Threat under simulation
Stale OAuth grant to ledger signing key
Generates 8 possible futures for this incident. No intervention is applied to the environment.
Simulated interventions · ranked by benefit vs disruption
Intervention catalogue
Dimmed actions are available in the catalogue but not modelled for this incident.
Before vs after · predicted
Do nothing — continue observing
Keep the grant live and continue collecting evidence. Baseline for every other option.
Outcome comparison · all modelled futures
| Option | Risk reduction | Disruption | Users | Confidence | Balance |
|---|---|---|---|---|---|
| A · Revoke OAuth token | High · −61% | Low | 1 | 91% | 39 |
| B · Rotate credential | High · −69% | Moderate | 0 | 79% | 22 |
| C · Disable identity | Very High · −78% | High | 1 | 86% | 21 |
| D · Revoke session | Low · −29% | Very Low | 1 | 90% | 19 |
| E · Remove specific permission | Moderate · −44% | Low | 0 | 83% | 18 |
| F · Quarantine resource | Very High · −84% | Very High | 18,400 | 74% | 12 |
| G · Block network connection | Moderate · −37% | High | 240 | 68% | -11 |
| H · Do nothing | Very Low · −0% | Very Low | 0 | 88% | -22 |
Balance = expected risk reduction minus weighted business disruption and recovery complexity, scaled by simulation confidence. Every term is shown so the ordering can be argued with.
Recommended intervention
Revoke OAuth grant oauth-grant-7f2c
Highest expected risk reduction (High, −61%) for the lowest modelled business disruption (Low), at 91% simulation confidence.
Expected outcome · predicted
Security outcome
Estimated risk reduction
−0%
Band Very Low · modelled, not guaranteed
Remaining attack paths
- Signing key → payments API → ledger writes
- Payments API → customer vault reads
- Service identity → east-west network → ledger database
Expected outcome · predicted
Business outcome
0
Users affected
0
Apps affected
0
Services affected
No change to production traffic or user access.
If the predicted path executes, recovery involves key re-signing, ledger reconciliation and regulatory notification.
Simulation
Confidence, evidence & assumptions
Simulation confidence
88%
Baseline needs no modelling of a control change.
Evidence used
- Grant refreshed from unrecognised ASN 08:57
- First AssumeRole in 214 days
- prod-secret-42 read 08:59
Important assumptions
- Attacker activity continues at the observed tempo
- No independent containment by the cloud provider
Simulation results are expected outcomes under the assumptions above. They are not guarantees, and no action is executed from this screen.
Policy & approval
No policy gate — observation only.
This simulator never executes an action, destructive or otherwise. Dispatch happens only in Autonomous Actions, under the policy gate shown above.