What I built

Zion is a defensive-security ("Blue Team") AI workspace — a structured environment that loads consistent doctrine, methodology, and skills into an AI coding assistant so it operates like a senior defensive practitioner instead of a generic chatbot. The context persists across sessions and runs the same way across different AI runtimes.

  • Trigger-activated security skills — security review, threat modeling (STRIDE, attack trees, kill-chain), incident response (triage to containment to eradication to recovery to lessons learned, with a written incident record), and CIS Controls mapping.
  • Oriented around real Blue Team workstreams — detection engineering, threat hunting, incident response and DFIR, hardening, and security review.
  • A compounding knowledge base — verified defensive patterns and documented anti-patterns with provenance, CIS Controls v8.1 reference material, and an append-only incident log.
  • Runtime-agnostic — the same workspace runs under multiple AI assistants because the skills are plain, portable markdown with no vendor lock-in.
  • Scoped to sanctioned, authorized defensive use only.

Why it matters

An AI assistant is only as good as the context it works from. Zion is my attempt to make that context a discipline: give the assistant the methodology, standards, and institutional memory a senior defender would carry, so its output stays consistent, auditable, and grounded in an actual framework (CIS v8.1, STRIDE, kill-chain). Its controls skill maps evidence to controls rather than claiming compliance — an honest posture that matters in security. And because the knowledge base is append-only, lessons from one incident compound into the next instead of evaporating when the session ends.