We converted publicly documented OpenAI-Hugging Face activity into realistic AI sessions, including prompts, available reasoning, tool calls, and tool results, then replayed those sessions through Milgram’s current production engine.
Where the forensic reports published a command, payload, reasoning excerpt, request shape, or observed output, the reconstruction preserves that material in redacted form. Where exact wire details were not public, we used faithful redacted reconstructions and defender-authored simulated results to represent the reported event.
In this bounded replay, Milgram flagged text associated with task drift, unauthorized agent coordination, credential abuse, exploitation attempts, command-and-control activity, data staging, Kubernetes privilege escalation, and source-control or CI abuse. Most findings came from explainable deterministic rules, with additional neural-classifier signals.
The current replay includes incident-specific rule work informed by the published artifacts. It demonstrates coverage of this reconstruction, not contemporaneous or zero-shot detection, and it does not measure recall across the complete original incident or across all possible agent attacks.