Cyber domain: the full analytical chain.
Synthetic port OT/IT network-flow picture (CIC-IDS2017-shaped): a SCADA gateway, PLCs, and corporate hosts of varying criticality run through a flow rule gate — C2 beaconing, exfiltration, port-scan, and a multi-stage campaign correlating hosts that converge on shared adversary infrastructure (the lateral-movement signal real critical-infrastructure intrusions leave) — then Models B/C/D (anomaly, risk, behaviour) with every score carrying a real Model G explanation. Non-geographic, rendered as a node/flow graph.
Synthetic network flows shaped like CIC-IDS2017. Not real traffic; hosts, IPs, and asset roles (SCADA gateway, PLCs, etc.) are a fabricated, illustrative port OT/IT topology, not a specific real facility.
Alerts
10 openHover or select an alert to trace the channel on the graph.
Cross-domain cueing · sent
1 cueRequests this domain has tasked to another — a high-confidence anomaly here tipping a look elsewhere. Human-in-the-loop: cues are queued, never auto-actioned.
full kill chain matched on campaign campaign-c0: recon → C2 → exfiltration across 3 hosts.