Research focus
Example task
Network incident response
Conceptual example
Suspicious network activity
An unexpected pattern appears
Isolate affected host
Limit the host’s network access
Verify service availability
Check that required services respond
Illustrative task record. It does not represent a published evaluation result.
What the task measures.
Score whether the threat was contained and legitimate services remained available. Connect the model's investigation and containment actions to the resulting network state.
Blocking suspicious activity can also interrupt legitimate work. Checking both containment and service availability tests whether the model resolved the incident without unnecessary disruption.
Discuss cybersecurity evaluation.
Evaluation engagements are custom. We agree on the task, inputs, outcomes, and scoring before a run begins.