Entry 005
AI in offensive security, minus the marketing
Where language models genuinely change offensive work, where they are theatre, and which parts of the workflow are actually worth automating right now.
What actually helps
Reading unfamiliar code, summarising a large scope, and drafting the report section nobody wants to write. All three are recall problems, which is what these models are good at.
What does not
Judgement about whether a finding matters. That requires knowing what the business loses, and no amount of context window supplies it.
The honest position
Treat it as a fast, confident junior. Useful, and never the last reviewer.