Counterfactual Defense Simulator

8 modelled interventions · simulated demo telemetry

01Threat detected
02Understand attack path
03Generate defenses
04Simulate each
05Compare outcomes
06Recommend
07Request approval
08Execute per policy

Threat under simulation

Stale OAuth grant to ledger signing key

INC-2471

Generates 8 possible futures for this incident. No intervention is applied to the environment.

Simulated interventions · ranked by benefit vs disruption

Intervention catalogue

Do nothingRevoke sessionDisable identityRevoke API keyRevoke OAuth tokenIsolate endpointRestrict AI agentRemove specific permissionBlock network connectionDisable application integrationRotate credentialQuarantine resource

Dimmed actions are available in the catalogue but not modelled for this incident.

Before vs after · predicted

Do nothing — continue observing

Pre-authorised
Current modelled state
Mira Chenoauth-grant-7f2csvc-ledger-prodprod-vpc-eastAWS · prod-9921prod-secret-42Production API · paymentsledger-primarycustomer-vault
Expected after · simulation
Mira Chenoauth-grant-7f2csvc-ledger-prodprod-vpc-eastAWS · prod-9921prod-secret-42Production API · paymentsledger-primarycustomer-vault

Keep the grant live and continue collecting evidence. Baseline for every other option.

Outcome comparison · all modelled futures

OptionRisk reductionDisruptionUsersConfidenceBalance
A · Revoke OAuth tokenHigh · −61%Low191%39
B · Rotate credentialHigh · −69%Moderate079%22
C · Disable identityVery High · −78%High186%21
D · Revoke sessionLow · −29%Very Low190%19
E · Remove specific permissionModerate · −44%Low083%18
F · Quarantine resourceVery High · −84%Very High18,40074%12
G · Block network connectionModerate · −37%High24068%-11
H · Do nothingVery Low · −0%Very Low088%-22

Balance = expected risk reduction minus weighted business disruption and recovery complexity, scaled by simulation confidence. Every term is shown so the ordering can be argued with.

Recommended intervention

Revoke OAuth grant oauth-grant-7f2c

Highest expected risk reduction (High, −61%) for the lowest modelled business disruption (Low), at 91% simulation confidence.

Execution handled in Autonomous Actions

Expected outcome · predicted

Security outcome

Estimated risk reduction

−0%

Band Very Low · modelled, not guaranteed

Attack paths removed0 of 10
Assets protected0 entities
Data exposure reduced0%

Remaining attack paths

  • Signing key → payments API → ledger writes
  • Payments API → customer vault reads
  • Service identity → east-west network → ledger database

Expected outcome · predicted

Business outcome

0

Users affected

0

Apps affected

0

Services affected

Estimated disruptionVery Low
Recovery complexityVery High

No change to production traffic or user access.

If the predicted path executes, recovery involves key re-signing, ledger reconciliation and regulatory notification.

Simulation

Confidence, evidence & assumptions

Simulation confidence

88%

Baseline needs no modelling of a control change.

Evidence used

  • Grant refreshed from unrecognised ASN 08:57
  • First AssumeRole in 214 days
  • prod-secret-42 read 08:59

Important assumptions

  • Attacker activity continues at the observed tempo
  • No independent containment by the cloud provider

Simulation results are expected outcomes under the assumptions above. They are not guarantees, and no action is executed from this screen.

Policy & approval

No policy gate — observation only.

Pre-authorised by policy · still requires operator dispatch

This simulator never executes an action, destructive or otherwise. Dispatch happens only in Autonomous Actions, under the policy gate shown above.