AI 网络安全平台 Outtake 基于 Claude,使用 Claude Code 和 Agent SDK 构建了自主网络调查智能体 Recon Agent。
技巧观点Claude:Blog(网页)
今日 AI 情报摘要
AI 网络安全平台 Outtake 基于 Claude,使用 Claude Code 和 Agent SDK 构建了自主网络调查智能体 Recon Agent。
中文正文 · AI 翻译
Outtake 如何确保多小时的代理会话保持在正轨上,以揭示攻击网络操作
在我们的系列文章《创业公司如何使用 Claude 构建》中,我们重点介绍了创业公司如何利用 AI 改变其行业。在本文中,我们分享了 Outtake 如何构建一款自主网络调查员,该调查员能够检测、调查并拆除数字威胁,从克隆登录页面到整个对抗性网络。
即使有完善的防护措施和控制,恶意行为者仍可以将 AI 用于看似无害的目的,从而掩盖其恶意意图。代码生成平台可以创建逼真的登录门户,自动化的市场工具可以推动网络钓鱼攻击的传播,而图像生成能力可以伪造身份。传统的网络安全防御很难跟上。
AI 网络安全平台 Outtake 的创始人兼 CEO Alex Dhillon 说:“如果你站在攻击者的角度来看,现在确实是发动攻击的好时机。因为 AI,不仅平均攻击执行得更快,而且由于 AI 的帮助,还能获得更深层的访问。” https://www.outtake.ai/
Outtake 将完整的数字信任攻击链 https://www.outtake.ai/blog/2026-digital-trust-industry-pain-report 统一到单一防御中,利用大量 AI 代理自主检测、调查并拆除针对客户的威胁,其客户包括领先的 AI 实验室、主要对冲基金以及美国联邦机构。
以下是 Outtake 团队最近如何在 Claude 上使用 Claude Code https://code.claude.com/docs/en/quickstart 和 Agent SDK https://code.claude.com/docs/en/agent-sdk/overview 构建 Recon Agent(一款长期运行的自主网络调查员)的方式。
在针对一家公司时,攻击者通常会遵循相同的流程:利用公共数据进行武器化 → 构建诱饵伪装 → 利用内部系统。这个流程因 AI 的介入而加速。
在需要时,提示提供了灵活性,但在可能的情况下进行硬编码可以确保稳定性。“当你构建这些随时间变得复杂的长期运行代理时,提示只是建议,”Hayford 说。“当代理没有按照你的意图行动时,自然的反应是增加到代理中最容易改变的部分。在系统提示中加入‘当 X 发生时,确保你做 Y’可能起初有效,但随着代理运行时间的延长,该提示中的每一个字最终可能都会被忽略。”正确的方法是通过识别代理每次都应该执行的操作,并将其作为代理的护栏来构建系统。“把这些东西从提示中提取出来,放入框架中,”他说。“现在代理不必再去考虑它,它有更多的上下文空间和注意力去专注于真正可以发挥作用的领域。”
阅读更多关于指导 Claude 的最佳实践:https://claude.com/blog/steering-claude-code-skills-hooks-rules-subagents-and-more,以及每种方法的上下文成本和权威性。
Recon Agent 已上线并开始进行调查。如果你想深入了解 Outtake 如何使用 Claude 在大规模上映射对抗性基础设施:
探索更多关于使用 Claude 构建团队的产品新闻和最佳实践。
产品更新、操作指南、社区亮点等,每月发送到你的邮箱。
嗨 Claude!你能帮我为观众开发一个独特的声音吗?如果你需要更多信息,请立即向我提出 1-2 个关键问题。如果你认为我应该上传任何文档来帮助你更好地完成任务,请告诉我。你可以使用你能访问的工具——例如 Google Drive、网络搜索等——如果它们能帮助你更好地完成任务。请不要使用分析工具。请保持回答友好、简短和对话式。请尽快执行任务——如果制作一个成果会更好,如果制作成果,请考虑哪种类型的成果(交互式、视觉、清单等)对这个特定任务最有帮助。谢谢你的帮助!
嗨,Claude!你能帮我改善写作风格吗?如果你需要我提供更多信息,请立即问我1-2个关键问题。如果你认为我应该上传任何会帮助你做得更好的文档,请告诉我。你可以使用你可以访问的工具——比如 Google Drive、网页搜索等——如果它们能帮助你更好地完成任务。不要使用分析工具。请保持你的回答友好、简短并且富有交流感。请尽快执行任务——如果有合适的实物或工具会很好。使用实物时,请考虑哪种类型的实物(互动的、视觉的、清单等)对这个特定任务最有帮助。谢谢你的帮助!
嗨,Claude!你能帮我头脑风暴创意吗?如果你需要我提供更多信息,请立即问我1-2个关键问题。如果你认为我应该上传任何会帮助你做得更好的文档,请告诉我。你可以使用你可以访问的工具——比如 Google Drive、网页搜索等——如果它们能帮助你更好地完成任务。不要使用分析工具。请保持你的回答友好、简短并且富有交流感。请尽快执行任务——如果有合适的实物或工具会很好。使用实物时,请考虑哪种类型的实物(互动的、视觉的、清单等)对这个特定任务最有帮助。谢谢你的帮助!
嗨,Claude!你能用简单的方式解释复杂的话题吗?如果你需要我提供更多信息,请立即问我1-2个关键问题。如果你认为我应该上传任何会帮助你做得更好的文档,请告诉我。你可以使用你可以访问的工具——比如 Google Drive、网页搜索等——如果它们能帮助你更好地完成任务。不要使用分析工具。请保持你的回答友好、简短并且富有交流感。请尽快执行任务——如果有合适的实物或工具会很好。使用实物时,请考虑哪种类型的实物(互动的、视觉的、清单等)对这个特定任务最有帮助。谢谢你的帮助!
How Outtake ensures multi-hour agent sessions stay on track to uncover attack network operations
In our series, How startups build with Claude, we highlight how startups are transforming their industries with AI. In this article, we share how Outtake built an autonomous cyber investigator that detects, investigates, and dismantles digital threats, from cloned login pages to entire adversarial networks.
Even with strong safeguards and controls, bad actors can mask their use of AI in seemingly benign purposes that hide their malicious intent. Code generation platforms can create convincing login portals, agentic go-to-market tooling can power the distribution of phishing attacks, and image generation capabilities can spoof identity. Traditional cybersecurity defenses struggle to keep up.
“If you put on the bad actor's hat, it's actually a great time to be running attacks,” says Alex Dhillon, founder and CEO of AI cybersecurity platform Outtake:https://www.outtake.ai/. “The average attack is not only executed faster because of AI, but it also captures deeper access due to AI”
Outtake unifies the full digital trust attack chain:https://www.outtake.ai/blog/2026-digital-trust-industry-pain-report into a single defense, using fleets of AI agents to autonomously detect, investigate, and dismantle threats aimed at their customers, which include leading AI labs, major hedge funds, and US federal agencies.
Here’s how the Outtake team recently built the Recon Agent, a long-running autonomous cyber investigator, on Claude using Claude Code:https://code.claude.com/docs/en/quickstart and the Agent SDK:https://code.claude.com/docs/en/agent-sdk/overview.
When targeting a company, attackers typically move through the same process: weaponize public data → build impersonations as lures → exploit internal systems. This process has been accelerated by AI.
Before breaking into anything, they harvest publicly available information about an organization, and its executives and employees.
They then turn that intelligence into bait, like a fake website with a fraudulent login page, to trick victims into handing over credentials. The access gained from these lures help the attacker get inside the perimeter to reach an organization’s most valuable and sensitive assets.
This three-part sequence is predictable, but legacy security tooling guards only one slice at a time:
Outtake’s Recon Agent investigates the full network behind an impersonation. Instead of just taking down a cloned login page, for example, the agent gathers and classifies evidence from the impersonation event.
It follows those leads to connected infrastructure, like a fake Telegram account that presents itself as “Customer Support,” and maps this adversarial network in a graph. The agent’s final step produces a report explaining the investigation process, a profile of the threat actor, and a reconstructed timeline of what the attacker did.
To carry out this sophisticated workflow, the Recon Agent can read, write, and run code. It can even interact with malicious login pages directly to see where stolen credentials actually go.
These investigations can require agents to run autonomously for long periods of time. Agent sessions run a median of 16 minutes, but routinely stretch to an hour and beyond; the longest run thus far lasted two hours of agentic work before returning results.
Outtake built the Recon Agent in roughly four stages. Each stage was about understanding what a good investigation looked like, then progressively handing that judgment to the agent.
Before building any part of the agent, Outtake's engineers ran real cyber investigations themselves and pulled domain expertise from customers and design partners.
The goal was to define what "good" looks like. For these types of investigations, that meant identifying what evidence matters, how to organize it, and what separated an actionable conclusion from a guess. That standard became the fixed reference point they returned to at every later stage.
“The most important thing about building long running agents is that you really have to understand what does good look like? What is the agent supposed to be doing? ” said Jack Hayford, engineering lead for Outtake's agent platform. “Because ultimately you're ensuring that the agent can do that every single time.”
Initially, the Outtake team used traditional agent frameworks to progressively automate the investigations they were standardizing.
They quickly realized, however, that the Recon Agent couldn't just be a simple investigator. It needed to write, run code, build tools on the fly, and actually interact with malicious domains.
“Every investigation is different, and deeply technical,” Hayford said. “The agent needed coding muscle and capability, and Claude Code was a strong initial harness for us to actually validate those assumptions and start experimenting more and more.” It was by prototyping in Claude Code that they forged their core design principle: constrain the agent tightly at the orchestration level ( ‘always do X, Y, Z when investigating a domain’ ), but leave it free to improvise whenever judgement was required.
“We really liked the patterns that Claude Code had introduced, but we needed additional access to the lower level primitives, which we weren't trying to build ourselves,” Hayford said.
Using the Claude Agent SDK:https://code.claude.com/docs/en/agent-sdk/overview was a natural next step for taking the Recon Agent into production. Carrying over skills and patterns from Claude Code ensured that the team didn't drop any velocity while they gained tighter control over the Recon Agent’s memory, context, and file system without reinventing the wheel in terms of the agent loop and handling sessions.
The ability to iterate inexpensively and responsively is particularly crucial in cybersecurity, where attackers adapt the moment they learn a defensive tool exists. The team integrated agent evals from the very beginning, and arrived at a strong eval suite that runs many scenarios at once. This let them make sweeping changes, like model upgrades and full memory-system refactors, safely and with confidence.
It also let the team pull themselves out of the agentic loop. When, for example, the Recon Agent finishes an investigation and reports back that it could have done better with some tool it didn't have, a separate coding agent then reads those suggestions, writes the new tool, and builds a test scenario to try it out.
Only at the very end does a human step in to look at the result: did the agent do the investigation better with that tool, or not? “We are the bottleneck, and when you build these long, complex agents, it's very important that the feedback loop be automated. It's a lot faster and it's also a lot more satisfying as a developer,” said Hayford.
In the early days of agents, builders scripted agent behavior in advance with hardcoded, deterministic, step-by-step paths to keep it from going off the rails. Now, elaborate workflows are being replaced by a harness: a supportive environment of memory, tools, skills, and guardrails.
Here are some takeaways from the Outtake team’s experience in implementing the Recon Agents build.
Filesystem enables memory that survives compaction. Agents are typically given very specific and nuanced tools, but giving an agent a filesystem along with the ability to write, read, and run code helps the agent respond to obstacles.
“Handing those extremely powerful open-ended tools and capabilities to an agent is a huge step change. We’ve observed plenty of cases where an agent had a tool that was failing due to a network hiccup or whatever, and it would just find the right workaround and continue,” said Hayford. “Because the rest of the harness that we had built was strong enough, and because it left the agent with opportunity for improvisation with these powerful, open-ended tools, it was still able to get to a successful outcome.”
Prompts provide flexibility when needed, but hardcoding where possible ensures stability. “When you're building these long-running agents that get complicated over time, prompts are suggestions,” Hayford said. “When an agent didn't do what you wanted, the natural response is to add to the most plastic part of the agent. Slipping ‘when X happens, make sure you do Y’ into the system prompt may work initially, but as this agent runs longer, every single word in that prompt will probably be ignored eventually.” The correct approach is to build around that likelihood by identifying what the agent should always do every time and making it part of the agent guardrails. “Pull these things out of the prompt and put them into the harness,” he said. “Now the agent doesn't have to think about it anymore and it has more context space and attention to put towards areas where it can really thrive.”
Read more on best practices for directing Claude :https://claude.com/blog/steering-claude-code-skills-hooks-rules-subagents-and-more , and the context cost and authority of each method.
Use manual “reflections” as a roadmap to automated evals that tighten dev cycles. The conventional view is that evals are a quality gate for reliability. For long-running agents, though, the bigger payoff is speed.
Early on, every time the Recon Agent ran, the team did a manual review of its performance. But reading an agent’s 30-minute transcript of everything it did is brutal and doesn't scale.
“In modern agent development, evaluating the output is the most expensive step in the loop,” Jack said.
An eval is just a structured, graded, automatable version of that reflection. Once you've codified what good looks like into a repeatable check, you can put an agent in the judge's seat to read the 30-minute transcript and score the run.
“I think that some engineers feel apprehensive about building evals because it's like this idea of building a perfect case,” Jack said. “Building some version of evals from the very beginning will make you build that agent faster regardless of how official or ‘perfect' they are.”
Prompt injection:https://www.anthropic.com/research/prompt-injection-defenses is a real threat, so putting your agent in a sandbox or giving it armor is essential. The Outtake team chose Claude in part because of its strength against prompt injection.
“Security is a big note for us for building the Recon Agent,” Hayford said. “We gave it a file system and bash and we're sending it to adversarial environments, so the most important problem we had to solve was building a sort of blastbox where you could try to hide your agent from sensitive internals without actually hindering it.”
Their approach assumes the agent might get hijacked, so the surrounding system is engineered to contain the damage. Security looks different from agent to agent, however, depending on their purpose, and not all agents are blastbox candidates.
Outtake is now scoring the level of trust at the exact point where the agent reaches out to the internet, implementing a checkpoint that evaluates whatever the agent is about to touch: ‘Is this page an impersonation? Is it malware? Is it trying to prompt-inject the agent right now?’ This may be exactly the armor that agents need as they traverse an increasingly adversarial internet.
Recon Agent is live and running investigations today. If you want to go deeper on how Outtake uses Claude to map adversarial infrastructure at scale:
Explore more product news and best practices for teams building with Claude.
Product updates, how-tos, community spotlights, and more. Delivered monthly to your inbox.
Hi Claude! Could you help me develop a unique voice for an audience? If you need more information from me, ask me 1-2 key questions right away. If you think I should upload any documents that would help you do a better job, let me know. You can use the tools you have access to— like Google Drive, web search, etc.—if they’ll help you better accomplish this task. Do not use analysis tool. Please keep your responses friendly, brief and conversational. Please execute the task as soon as you can—an artifact would be great if it makes sense. If using an artifact, consider what kind of artifact (interactive, visual, checklist, etc.) might be most helpful for this specific task. Thanks for your help!
Hi Claude! Could you improve my writing style? If you need more information from me, ask me 1-2 key questions right away. If you think I should upload any documents that would help you do a better job, let me know. You can use the tools you have access to— like Google Drive, web search, etc.—if they’ll help you better accomplish this task. Do not use analysis tool. Please keep your responses friendly, brief and conversational. Please execute the task as soon as you can—an artifact would be great if it makes sense. If using an artifact, consider what kind of artifact (interactive, visual, checklist, etc.) might be most helpful for this specific task. Thanks for your help!
Hi Claude! Could you brainstorm creative ideas? If you need more information from me, ask me 1-2 key questions right away. If you think I should upload any documents that would help you do a better job, let me know. You can use the tools you have access to— like Google Drive, web search, etc.—if they’ll help you better accomplish this task. Do not use analysis tool. Please keep your responses friendly, brief and conversational. Please execute the task as soon as you can—an artifact would be great if it makes sense. If using an artifact, consider what kind of artifact (interactive, visual, checklist, etc.) might be most helpful for this specific task. Thanks for your help!
Hi Claude! Could you explain a complex topic simply? If you need more information from me, ask me 1-2 key questions right away. If you think I should upload any documents that would help you do a better job, let me know. You can use the tools you have access to— like Google Drive, web search, etc.—if they’ll help you better accomplish this task. Do not use analysis tool. Please keep your responses friendly, brief and conversational. Please execute the task as soon as you can—an artifact would be great if it makes sense. If using an artifact, consider what kind of artifact (interactive, visual, checklist, etc.) might be most helpful for this specific task. Thanks for your help!
Hi Claude! Could you help me make sense of these ideas? If you need more information from me, ask me 1-2 key questions right away. If you think I should upload any documents that would help you do a better job, let me know. You can use the tools you have access to— like Google Drive, web search, etc.—if they’ll help you better accomplish this task. Do not use analysis tool. Please keep your responses friendly, brief and conversational. Please execute the task as soon as you can—an artifact would be great if it makes sense. If using an artifact, consider what kind of artifact (interactive, visual, checklist, etc.) might be most helpful for this specific task. Thanks for your help!
Hi Claude! Could you prepare for an exam or interview? If you need more information from me, ask me 1-2 key questions right away. If you think I should upload any documents that would help you do a better job, let me know. You can use the tools you have access to— like Google Drive, web search, etc.—if they’ll help you better accomplish this task. Do not use analysis tool. Please keep your responses friendly, brief and conversational. Please execute the task as soon as you can—an artifact would be great if it makes sense. If using an artifact, consider what kind of artifact (interactive, visual, checklist, etc.) might be most helpful for this specific task. Thanks for your help!
Hi Claude! Could you explain a programming concept? If you need more information from me, ask me 1-2 key questions right away. If you think I should upload any documents that would help you do a better job, let me know. You can use the tools you have access to— like Google Drive, web search, etc.—if they’ll help you better accomplish this task. Do not use analysis tool. Please keep your responses friendly, brief and conversational. Please execute the task as soon as you can—an artifact would be great if it makes sense. If using an artifact, consider what kind of artifact (interactive, visual, checklist, etc.) might be most helpful for this specific task. Thanks for your help!
Hi Claude! Could you look over my code and give me tips? If you need more information from me, ask me 1-2 key questions right away. If you think I should upload any documents that would help you do a better job, let me know. You can use the tools you have access to— like Google Drive, web search, etc.—if they’ll help you better accomplish this task. Do not use analysis tool. Please keep your responses friendly, brief and conversational. Please execute the task as soon as you can—an artifact would be great if it makes sense. If using an artifact, consider what kind of artifact (interactive, visual, checklist, etc.) might be most helpful for this specific task. Thanks for your help!
Hi Claude! Could you vibe code with me? If you need more information from me, ask me 1-2 key questions right away. If you think I should upload any documents that would help you do a better job, let me know. You can use the tools you have access to— like Google Drive, web search, etc.—if they’ll help you better accomplish this task. Do not use analysis tool. Please keep your responses friendly, brief and conversational. Please execute the task as soon as you can—an artifact would be great if it makes sense. If using an artifact, consider what kind of artifact (interactive, visual, checklist, etc.) might be most helpful for this specific task. Thanks for your help!
Hi Claude! Could you write grant proposals? If you need more information from me, ask me 1-2 key questions right away. If you think I should upload any documents that would help you do a better job, let me know. You can use the tools you have access to — like Google Drive, web search, etc. — if they’ll help you better accomplish this task. Do not use analysis tool. Please keep your responses friendly, brief and conversational. Please execute the task as soon as you can - an artifact would be great if it makes sense. If using an artifact, consider what kind of artifact (interactive, visual, checklist, etc.) might be most helpful for this specific task. Thanks for your help!