Live demo · synthetic

Cyber domain: the full analytical chain.

Synthetic port OT/IT network-flow picture (CIC-IDS2017-shaped): a SCADA gateway, PLCs, and corporate hosts of varying criticality run through a flow rule gate — C2 beaconing, exfiltration, port-scan, and a multi-stage campaign correlating hosts that converge on shared adversary infrastructure (the lateral-movement signal real critical-infrastructure intrusions leave) — then Models B/C/D (anomaly, risk, behaviour) with every score carrying a real Model G explanation. Non-geographic, rendered as a node/flow graph.

Synthetic

Synthetic network flows shaped like CIC-IDS2017. Not real traffic; hosts, IPs, and asset roles (SCADA gateway, PLCs, etc.) are a fabricated, illustrative port OT/IT topology, not a specific real facility.

INTERNALEXTERNALOT / CRITICALCORPORATE10.0.0.4 · port-scada-gw10.0.0.7 · scada-plc-0410.0.0.14 · energy-rtu-0210.0.0.68 · gate-cctv-nvr10.0.0.18 · corp-dc-0110.0.0.22 · corp-vpn-gw10.0.0.31 · corp-ws-0510.0.0.36 · corp-ws-1110.0.0.42 · corp-ws-1410.0.0.47 · corp-ws-1910.0.0.53 · corp-ws-2310.0.0.61 · corp-ws-27111.178.235.206117.45.42.209122.23.82.180145.254.102.148147.202.101.68150.19.210.61154.211.51.128158.100.3.18183.247.47.79198.118.69.125202.112.49.45204.207.159.86207.41.70.224208.58.1.154215.81.75.4725.131.198.2240.188.151.12744.186.224.18549.220.74.6561.102.4.14166.116.56.15194.145.221.13598.109.85.98Benign trafficC2 beaconingData exfiltrationPort scan
Synthetic network-flow graph · internal hosts (left) → external (right) · edge weight = risk · CIC-IDS2017-shaped, not real traffic

Alerts

10 open

Hover or select an alert to trace the channel on the graph.

Cross-domain cueing · sent

1 cue

Requests this domain has tasked to another — a high-confidence anomaly here tipping a look elsewhere. Human-in-the-loop: cues are queued, never auto-actioned.

to Maritimehigh

full kill chain matched on campaign campaign-c0: recon → C2 → exfiltration across 3 hosts.

c0exfil·pending