I’m Noah Potti. I’ve spent the last dozen years in offensive security, red teaming, and adversarial engineering. These days I work mostly on how to test and bring systemic improvements at scale across identity, system boundaries, and the security of AI systems and agents.

I’m a co-founder of Adversis and Puck. A lot of my work is simply around this: if this credential, identity, or endpoint is compromised, what can it actually reach and do?

I also build security tools and co-wrote The Effective Red Team, forthcoming from No Starch Press.

Nothing new here

Most of the serious compromises I have been a part of didn’t need a zero-day. Something already in the environment, a token, a service account, a browser extension, a forgotten permission, had more access than anyone remembered giving it. We noticed before the attackers or defenders.

So much of the work is finding the gap between what a system is supposed to be able to reach and do and what it can actually reach, and then closing it.

Agents are making this more interesting. The software holding the credential now also reads untrusted text and decides what to do with it. The desktop agent is the new browser, except we’re skipping thirty years of hardening and shipping it with prompt injection unresolved. Agents need broad latitude, but must be task-constrained.

Questions I’m thinking about now: whether constraining an agent’s output to a fixed grammar makes it safe to act on, how to grant access based on what a user asked for, and what happens once attackers and defenders both run fleets of agents.

The other problem is measurement. Security has little reliable evidence about which controls work. Papers that convinced me of that are on the resources page.

Tools

All the tools →

Writing

More →

Now

Fractional CISO for a handful of companies through Adversis. AI security assessments for a few more. Building Puck, which is mostly about answering “are we affected?” from the endpoints instead of from a meeting.

Email noah at this domain. Haikus get read first. Everything else gets read eventually.

Elsewhere

GitHub (@thesubtlety, and @noahpotti) · LinkedIn · Adversis · Puck Security