Command Center

Global production environment · demo data

Threat level · High

Demo environment · simulated telemetry. Predictions and simulations are estimates with stated confidence, never guarantees.

Cybershield understands

a living model of identities, agents, data and permissions

Cybershield predicts

reachable paths and blast radius, with confidence

Cybershield simulates

defensive options before anything is executed

Cybershield governs

autonomous action inside explicit policy

Cybershield learns

from security decisions, never silently

Current threat level · High

Three active incidents, one of them reaching a Tier 0 data store through a privileged service identity.

Since 09:02 UTC · observed

Active incidents

03

Agents at risk

03

Blast radius now

76

INC-2471

Pending approvals

03

Autonomous actions 24h

05

Cybershield intelligence · intelligence layer, not a chatbot

What requires attention?

Open simulator ↗

Evidence

  • ·Grant consented 14 months ago, expiry removed by exception CS-EXC-118
  • ·Token used from an ASN unseen for this identity in 90 days
  • ·svc-ledger-prod assumed four minutes after first use (observed)

Predicted consequence

Predicted: signing-key read within 6 minutes, then impersonation of the payments API. 2.4M records become reachable.

Recommended action

Rotate the ledger signing key and remove the never-expiring grant exception.

Expected security benefit

Estimated −54 blast-radius points · 3 of 5 predicted paths removed

Expected business impact

Low · one scheduled ledger job re-authenticates; no user is signed out.

Confidence · 91%

Three corroborating observed signals plus two prior confirmed token-theft patterns.

Approval requirement

Named approval required · CS-AUTO-04 · credential rotation on production secrets

Incidents

Active incidents

All incidents ↗

AI agent control plane

AI agents at risk

All agents ↗

Digital twin

Highest-risk identities

Open twin ↗

oauth-grant-7f2c

identity
91

svc-ledger-prod

identity
86

Mira Chen

human
58

Peter Konadu

human
34

MacBook Pro · MC-14

machine
22

Attack-path engine

Critical and predicted paths

Open paths ↗

Confirmed segments

Mira Chenoauth-grant-7f2cObserved
oauth-grant-7f2csvc-ledger-prodObserved
Finance AgentAccounting SystemObserved
Accounting SystemVendor DatabaseObserved

Predicted continuations

svc-ledger-prodprod-vpc-eastpossible
prod-vpc-eastledger-primarypossible
Finance AgentVendor Payment APIpossible
Vendor DatabaseVendor Payment APIpredicted

Predicted links are inferred from reachability in the twin, not observed activity.

Blast-radius prediction

Current exposure · INC-2471

Explain score ↗
76ElevatedWeighted · factors shown
Privilege level
×0.1892
Data sensitivity
×0.1796
Reachable systems
×0.1378
Identity trust
×0.1231
Network position
×0.1270
Credential exposure
×0.1394
AI-agent permissions
×0.0522
Attack-path length
×0.1074

Governed autonomy

Autonomous actions and approvals

Autonomy Center ↗
09:04:37

Revoke OAuth token

Executed

Petavora autonomy engine · CS-AUTO-01 · confidence 94%

09:03:02

Automated investigation

Executed

Petavora autonomy engine · CS-AUTO-02 · confidence 99%

09:05:11

Rotate exposed credential

Executed

Petavora autonomy engine · CS-AUTO-04 · confidence 91%

08:58:20

Restrict AI agent scope

Executed

Petavora autonomy engine · CS-AUTO-03 · confidence 89%

09:06:45

Disable an employee account

Awaiting approval

Petavora autonomy engine · CS-AUTO-08 · confidence 86%

3 actions awaiting a named approver

Security time machine

Recent security changes

Open timeline ↗
10:27:00Zinfo

Service-account session count returning to baseline

Identity collector · Observed · inc-2471

10:19:00Zinfo

Human approval required for Finance Assistant

P. Konadu · Security Admin · Observed · inc-2473

10:11:00Zinfo

OAuth grant revocation authorised

P. Konadu · Security Admin · Observed · inc-2471

10:02:00Zinfo

Production signing key rotation staged

P. Konadu · Security Admin · Observed · inc-2471

09:49:00Znotable

East-west connection flagged between segments

Network collector · Inferred · inc-2473

09:36:00Znotable

Payroll database access attempted and denied

agt_fin_4b19 · Observed · inc-2473

Run the 60-second attack simulation

Petavora Cybershield reduces and explains risk. It does not claim guaranteed prevention.