SecRespond: 23 Frontier LLMs Tested on Post-Compromise Forensics, None Completes Detection and Remediation on a Single Range
SecRespond (arXiv 2607.26791, 2026-07-29) is the first benchmark for the post-compromise incident-response workflow — agents get a forensic disk snapshot of a breached host plus alerts, vuln scans, and baseline checks, and must produce intrusion, baseline-risk, and vulnerability-risk reports with a remediation plan. It spans 10 cyber ranges built from distinct compromised cloud hosts, 4 entry-point types, 21 ATT&CK techniques, and 5 operating systems, evaluated across 23 frontier LLMs on the OpenCode harness. Agents reliably chase down what the alerts already surfaced but fail to proactively investigate the disk for silent intrusions, and no model achieves complete detection and remediation on any single range.
↳ Follow the thread