What this family supports.
Defensive instruments for incident evidence, telemetry, resilience, threat hypotheses and blast-radius analysis.
Defensive instruments for incident evidence, telemetry, resilience, threat hypotheses and blast-radius analysis.
Defensive instruments for incident evidence, telemetry, resilience, threat hypotheses and blast-radius analysis.
Inputs are user-entered assumptions or evidence states. The tools do not verify live systems, datasets, vendors, clinical claims, vulnerabilities or scientific measurements.
Outputs are preliminary orientation artifacts for human review. They are not certification, legal advice, medical advice, engineering sign-off or compliance approval.
Builds an evidence source matrix and investigation sequence for a selected incident scenario.
Prioritizes review of a known-exploited vulnerability using user-entered exposure, asset criticality and compensating controls.
Maps a disruption scenario to controls, telemetry, recovery evidence and test cadence.
Maps where an AI system changes cyber dependencies, identities, data flows and incident-response paths.
Checks whether incident timestamps, evidence sources and time-zone assumptions are internally consistent.
Turns a defensive suspicion into a hunt hypothesis with telemetry, expected observations and falsification criteria.
Estimates likely blast-radius pressure from identity scope, lateral movement potential, data reach and dependency concentration.
Maps telemetry coverage across identity, endpoint, cloud, network, email, application and data layers.
Version policy: each instrument has a version, maturity state, assumptions, limitations, example input, example output and export formats. Method notes should be updated when scoring logic, input taxonomy or source families change.