Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

Cyber Operations

Adjudicate the Incident, Not the Alert Queue

ArtOfTheHack consolidates detections from every security platform in the environment, resolves the entities behind them, tests competing explanations, and returns a governed decision with the authority required to act.

Operating problem

Detection Capacity Has Outgrown Adjudication Capacity

Security operations centers rarely fail because a detection was missing. They fail because the combined evidence was never adjudicated as a single question.

  • Security systems operate in isolation and cannot evaluate each other
  • Duplicate alerts describe the same event with different identifiers
  • Detections reach conflicting conclusions about the same identity or host
  • Risk models are incompatible across identity, endpoint, cloud, and data
  • Business consequence is absent from most technical severity scores
  • Escalation volume exceeds the adjudication capacity of the analyst team
  • Automation executes without complete cross-system context

Governance rail

  • Human in the loop
  • Approval thresholds
  • Separation of duties
  • Policy constraints
  • Reversibility checks
  • Blast-radius limits
  • Audit logging
  • Compliance mapping
  • Kill switch
  • Native fallback

Intelligence does not equal authority. KRYOS-XS Hypercube may analyze. Policy determines authority. Approved systems execute.

Analyst workflow

One Queue of Decisions Instead of Many Queues of Alerts

Each case arrives with the evidence that supports it, the evidence that contradicts it, the response options that were compared, and the authority required for execution.

Cyber decision queue

Illustrative platform visualization

CaseSubjectRiskConfidenceState
INC-8841Token replay, finance tenantHigh0.78Awaiting authority
INC-8836Cloud key exposure, build pipelineHigh0.91Approved, executed
INC-8829Beaconing host, contradicted by NDRMedium0.42Advisory, evidence gap
INC-8814Privilege escalation attemptCritical0.88Blocked by policy

Decision record

Every Recommendation Is a Structured Record

Analysts can read the reasoning, question the alternatives, and reconstruct the decision months later.

Governed Decision Object

Illustrative platform visualization

Decision ID
DEC-4417-IDENT
Status
Awaiting authority
Risk
High
Confidence
0.78
Uncertainty
Device telemetry gap, 14 minutes
Identity provider
Impossible travel, two regions, 41 minutes apart
Endpoint platform
No malicious process observed on the registered device
Network
Session originated from a residential proxy range
Data platform
Access to a regulated dataset attempted twice
Evidence quality
Three independent sources, one derived source excluded

Response modes

Automation Should Scale With Certainty and Consequence

Level 1

Advisory

ArtOfTheHack analyzes evidence and recommends an action to a named analyst.

No write capability is required. Recommendations are compared against current practice.

Level 2

Approval-Gated

ArtOfTheHack prepares the action. An authorized human approves execution.

Authority is resolved from policy, and the request expires if evidence goes stale.

Level 3

Bounded Automatic

Only predefined, reversible, policy-approved actions execute automatically.

Every automatic class requires a validated rollback path and a blast-radius ceiling.

ArtOfTheHack does not replace SIEM, XDR, EDR, NDR, SOAR, IAM, PAM, ZTNA, CNAPP, DLP, or cloud control planes. It operates above them as a non-intrusive API overlay and returns governed decisions to those systems.