SecRespond introduces a benchmark for evaluating LLM agents in post-compromise incident response, rather than in clean pre-attack environments. Agents receive a forensic disk snapshot from a compromised host alongside security-product alerts, vulnerability scans, and baseline checks. They must produce forensic reports covering intrusions, baseline risks, and vulnerability risks, plus a remediation plan. The benchmark contains 10 cyber ranges spanning four entry-point types, 21 ATT&CK techniques, and five operating systems. Across 23 frontier models evaluated with the OpenCode harness, agents reliably found alert-exposed issues but struggled with proactive disk investigation and comprehensive, verified remediation; no model fully detected and remediated any range.
No heat snapshots are available in the last 24 hours.