Demo environment · simulated telemetry. Predictions and simulations are estimates with stated confidence, never guarantees.
Cybershield understands
a living model of identities, agents, data and permissions
Cybershield predicts
reachable paths and blast radius, with confidence
Cybershield simulates
defensive options before anything is executed
Cybershield governs
autonomous action inside explicit policy
Cybershield learns
from security decisions, never silently
Current threat level · High
Three active incidents, one of them reaching a Tier 0 data store through a privileged service identity.
Since 09:02 UTC · observed
Active incidents
03
Agents at risk
03
Blast radius now
76
INC-2471
Pending approvals
03
Autonomous actions 24h
05
Cybershield intelligence · intelligence layer, not a chatbot
What requires attention?
Evidence
- ·Grant consented 14 months ago, expiry removed by exception CS-EXC-118
- ·Token used from an ASN unseen for this identity in 90 days
- ·svc-ledger-prod assumed four minutes after first use (observed)
Predicted consequence
Recommended action
Expected security benefit
Expected business impact
Confidence · 91%
Approval requirement
Incidents
Active incidents
Stale OAuth grant to ledger signing key
Blast 76A 214-day-old OAuth grant belonging to Mira Chen was refreshed from an unfamiliar network and used to assume svc-ledger-prod, which then read the payments signing key. Three hops are confirmed by telemetry; everything past the key is modelled, not observed.
Predicted next · Forge a signed request to the payments API to confirm the key is still accepted (72% · next 3–6 minutes) · confidence 87%
Finance agent payment-redirection exposure
Blast 66The finance agent's payment ceiling was raised to $50k yesterday and a vendor bank account was edited within the same window. Three drafts now target that vendor. Both changes are individually legitimate; together they remove the control that would normally stop a redirection.
Predicted next · Drafts clear the approval queue and enter the next settlement batch (57% · next 5–15 minutes) · confidence 74%
Support agent scope creep toward customer data
Blast 62The support agent's retrieval and CRM query volume is nine times its median, and a knowledge-base document it consumes was edited by an unverified author. No exfiltration has been observed; this currently reads as scope creep or prompt influence rather than confirmed compromise.
Predicted next · Continue widening customer queries beyond assigned tickets (66% · next 5–10 minutes) · confidence 61%
AI agent control plane
AI agents at risk
Finance Assistant
agt_fin_4b19risk 77 · trust 61Purpose drift under review · payment ceiling elevated · unapproved tool in use
Purpose check · potential drift
Customer Support Agent
agt_sup_91c7risk 46 · trust 69Read-volume anomaly under monitoring · scope review scheduled
Purpose check · minor drift
People Ops Assistant
agt_hr_77d3risk 33 · trust 79One refused sensitive-data request logged for review
Purpose check · minor drift
Digital twin
Highest-risk identities
oauth-grant-7f2c
identitysvc-ledger-prod
identityMira Chen
humanPeter Konadu
humanMacBook Pro · MC-14
machineAttack-path engine
Critical and predicted paths
Confirmed segments
Predicted continuations
Predicted links are inferred from reachability in the twin, not observed activity.
Blast-radius prediction
Current exposure · INC-2471
Governed autonomy
Autonomous actions and approvals
Revoke OAuth token
ExecutedPetavora autonomy engine · CS-AUTO-01 · confidence 94%
Automated investigation
ExecutedPetavora autonomy engine · CS-AUTO-02 · confidence 99%
Rotate exposed credential
ExecutedPetavora autonomy engine · CS-AUTO-04 · confidence 91%
Restrict AI agent scope
ExecutedPetavora autonomy engine · CS-AUTO-03 · confidence 89%
Disable an employee account
Awaiting approvalPetavora autonomy engine · CS-AUTO-08 · confidence 86%
Security time machine
Recent security changes
Service-account session count returning to baseline
Identity collector · Observed · inc-2471
Human approval required for Finance Assistant
P. Konadu · Security Admin · Observed · inc-2473
OAuth grant revocation authorised
P. Konadu · Security Admin · Observed · inc-2471
Production signing key rotation staged
P. Konadu · Security Admin · Observed · inc-2471
East-west connection flagged between segments
Network collector · Inferred · inc-2473
Payroll database access attempted and denied
agt_fin_4b19 · Observed · inc-2473
Petavora Cybershield reduces and explains risk. It does not claim guaranteed prevention.