A quick article showing how the Jev OPSEC ranker works, and looking at how Jev can be used for identifying potentially sensitive file paths and content at speed.
Article

Experimenting with Jev for Offensive Security

A few days ago I published a quick demo of using the new Jev model to measure OPSEC strength of a command being typed into Mythic: Since posting the video I have had a few questions about just how

Sep 23, 2026 · 6:40 PM UTC

2
76
448
26,483
Sort replies: Relevant Recent Liked
Replying to @_xpn_
Very interesting idea. But sending your commands over to TypeSafe's API can be quite un-OPSEC depending on your operation right? Eventually though, I believe it will be easy to self-host a jev-like classifier model anyway.
1
3
765
Well... yes, of course don't do that! But experiment for sure, the tech is new, it's our job to figure out what works/doesn't work, and how it is likely going to be applied.
1
1
550
Replying to @_xpn_
Does it have context of how each command is implemented and what is does under the hood? E.g shell might be a spawn cmd.exe /c with named pipe to get the output. So in this case would it be assessing and scoring the fact you have cmd.exe as a child process?
2
1
309
If you look at the state I had to pass to get it to do anything, the "notes" field is LLM generated summary of the Apollo functionality (it didn't do a great job, but better than nothing). When I get a sec I want to run the extracted EDR rules I have into a Jev like model and see if we can improve suggestions based on certain EDR's.. because Jev is good at picking up different parameter types.
1
143