Intelligence & Research

Insights

Threat analysis, tradecraft methodology, and operational field notes from the TCI team.

SITREPs

View all

Situation reports covering active conflicts, threat landscapes, and geopolitical developments.

Epic Fury Day 8: The Unconditional Mandate

Israel Security SITREP covering the Coalition's shift to strategic strangulation of the IRGC, the White House demand for unconditional surrender, and Kurdish shaping operations opening a second front.

David Greenhill
David Greenhill·

Threat Analysis

View all

Threat landscape assessments, adversary techniques, and risk analysis.

When LLMs Leak: Obfuscation Failures in AI-Assisted Redaction

LLM-powered redaction tools can fail in subtle, dangerous ways — reconstructing supposedly removed PII from context, leaking information through embeddings, or hallucinating redaction where none occurred.

David Greenhill
David Greenhill·

Prompt Injection as a Redaction Bypass

Documents processed through LLM redaction pipelines can contain adversarial text that manipulates the model into preserving sensitive information. This attack vector is unique to AI-powered redaction.

Michael Peterson
Michael Peterson·

Tradecraft

View all

Methodology, tools, and techniques for digital forensics and OSINT practitioners.

Agentic CLIs Are Redefining OSINT Collection Workflows

The command line is no longer a passive tool. Agentic CLI frameworks turn terminal sessions into autonomous investigation platforms — planning, executing, and iterating on OSINT collection without constant human steering.

David Greenhill
David Greenhill·

Air-Gapped AI: Running Local LLMs for Sensitive Evidence Processing

When evidence is too sensitive to leave the building, you need AI that runs entirely on-premises. Here's how TCI deploys local LLMs in air-gapped environments for entity extraction, analysis, and redaction.

David Greenhill
David Greenhill·

Building Trustworthy LLM Redaction Pipelines

LLMs offer powerful contextual PII detection, but only within a pipeline that compensates for their weaknesses. Here's how TCI architects redaction systems that combine LLM intelligence with deterministic guarantees.

David Greenhill
David Greenhill·

Research

View all

In-depth research papers, technical deep dives, and formal analysis.

Self-Hosted Agent Infrastructure: Architecture for Isolated Operations

Deploying autonomous AI agents on self-hosted infrastructure requires careful architecture — balancing agent autonomy with operational security, audit requirements, and physical isolation constraints.

Michael Peterson
Michael Peterson·

The Command Line as Investigation Platform

Modern agentic CLI tools are transforming the terminal from a simple command executor into a full investigation platform — with planning, tool orchestration, and autonomous decision-making built in.

Michael Peterson
Michael Peterson·

Field Notes

View all

Operational observations, tool reviews, and quick-reference technical notes.

Building an Autonomous Evidence Capture Agent with Claude Code

A practical walkthrough of designing an evidence capture agent inside Claude Code — from objective definition to WORM-compliant artifact storage, with chain-of-custody logging built into every step.

David Greenhill
David Greenhill·

Field Report: Deploying an Evidence Processing Agent on Isolated Infrastructure

Lessons from deploying an autonomous evidence processing agent on air-gapped hardware — what worked, what didn't, and what we'd change for the next deployment.

David Greenhill
David Greenhill·