Authors here. Existing security-AI benchmarks measure knowledge, offensive capability, or workflow completion. SIR-Bench measures whether an agent discovers novel evidenceduring an investigation vs. reaching the right conclusion by restating the alert.
794 test cases derived from 129 real incident patterns, replayed in live cloud environments. Happy to answer questions on methodology, scoring, or failure modes we saw acrossfrontier models.
dan_l2•1h ago