Hello, I'm
Ali Korsi
AI Security Researcher — Data & Observability
I research how autonomous agents fail under attack — memory poisoning, runtime compromise, governance gaps — and build the data and observability platforms that make those failures visible.
KOR IT
korit.org →My cybersecurity engineering and research firm.
Engineering Security for an Autonomous World
01
Engineering
SOC architecture, SIEM and detection engineering, security data platforms, secure cloud.
02
The LAB
A controlled environment for testing emerging architectures before they meet production.
03
Research & Products
What survives the lab becomes published research, open tooling, or a shipped product.
Memory poisoning · propagation
The bench →Memory poisoning is persistence, not exploitation. A false premise written into memory propagates through everything the agent decides next — and every action stays locally reasonable.
conceptual diagram · MISC 147
t0 · nominal — agent operating on trusted memory
•Signature detection
—
•Behavioural analysis
—
•Belief integrity
—
Experience
10+
years
Research
2
active projects
Labs
4
benches running
Writing
5
articles
Live telemetry
core web vitalsTTFB
—
FCP
—
LCP
—
CLS
—
INP
—
measured in your browser, right now — INP appears after your first interaction
Trace · page load
performance apicollecting trace…
Current focus
Commit history
GitHub →4 repos · snapshot Sep 21, 2026
Recent feed
View all →- publishedMemory poisoning: when the AI agent becomes the SOC's blind spotMISC Magazine n°1472026
- researchCryptagionKnow your cryptography before quantum does.2026
- researchContextMeshSee where your agent's tokens go.2026
- researchARGOSAutonomous Response & Governance Operations System.2026
- researchTyposentinelSupply chain attacks that scanners miss.2025
- writingWhat agentic AI actually changes in a SOCAI & Security2026
Domains
Cybersecurity Architecture
Designing and implementing enterprise-grade security architectures, zero-trust frameworks, and threat modeling across hybrid and cloud-native environments.
Data Security & Engineering
Building secure data pipelines, implementing data classification, encryption-at-rest and in-transit, DLP strategies, and compliance frameworks (GDPR, SOC2, ISO 27001).
Observability & Detection
Architecting SIEM/SOAR platforms, building detection engineering pipelines, crafting advanced correlation rules, and designing real-time security monitoring at scale.
Cloud & Infrastructure Security
Securing multi-cloud environments (AWS, Azure, GCP), container security, IaC security scanning, and designing resilient cloud-native security controls.