Skip to main content
Alsadaany

Search this site

Search projects, services, pricing and frequently asked questions.

Site navigation

Security operations

Cyber Tracker

Status: DemonstrationDemonstration systemInternal system, not a customer deployment

Forty-five assets across seven tiers joined by 113 links, each carrying fifteen telemetry channels, with five attack scenarios that play out end to end and respond to the operator. Every number on screen comes from a model that runs, and can be tested, without a renderer in the scene.

Properties of the model

Modelled assets
45
Network links
113
Telemetry channels per asset
15
Attack scenarios
5

These describe this model. None is a benchmark, a customer result, or a claim about a real facility.

Problem

Detection coverage is usually asserted rather than demonstrated. Whether a set of controls would actually catch a given adversary depends on the estate's topology, on what telemetry each asset produces, on how that telemetry behaves normally, and on which of it an analyst is in a position to act upon. Those are systems questions, and answering them by argument is how organisations arrive at confidence they have not earned.

This system reproduces the estate, the telemetry and the adversary so that the question can be examined. It is an internal system built and published by Alsadaany Industries. It is not a customer deployment, and the operation it models is illustrative. It is a simulation and cyber-physical modelling demonstration, not a deployed security product.

System

An enterprise estate of 45 assets across seven tiers: internet, firewall and VPN, DMZ and load balancers, web and application servers, databases, directory and file servers, endpoints, and an operational technology segment of cameras, printers and controllers. The tiers are honoured as the visual layering, while the 113 links are wired the way a real network is, branching and partially meshed, with the OT segment behind its own boundary.

That distinction is deliberate. A straight descending chain would be easier to draw and would not survive thirty seconds of scrutiny from a network architect.

Model

Fifteen telemetry channels per asset covering CPU, memory, disk, bandwidth, connections, sessions, processes, logins, DNS, HTTP, HTTPS, SMTP, SSH, RDP and VPN, plus throughput, latency and packet loss per link.

Each channel is composed rather than randomised: a baseline, organic drift, a working-hours envelope, and whatever the current attack is doing to it, smoothed. There is no per-frame randomness anywhere in the model, which is what makes an anomaly in it mean something.

Simulation

Five scenarios are modelled: phishing, ransomware, insider threat, distributed denial of service, and a zero-day. Each is authored as a sequence of beats the attack manager interprets. It selects targets, ramps risk and compromise, applies resource pressure, lights the links the attacker traverses, fires detections and drives the analyst view.

Because the sequences are data rather than code, adding a scenario is an authoring job. That is what makes the system usable for examining coverage against a technique sequence rather than only for watching the five that ship with it.

Engineering

The model runs, and can be tested, with no renderer in the scene. The build can also photograph itself unattended at specified simulation times, from the same seed, so demonstration material is regenerated after a change rather than re-shot by hand.

The browser build trims itself deliberately rather than degrading unpredictably: post-processing effects are dropped, the packet cap falls from 1,400 to 550, shadow distance is reduced, and frame pacing is handed back to the browser.

Demonstrated capability

The system demonstrates modelling a heterogeneous estate including an OT segment, generating plausible telemetry with the statistical structure real telemetry has, driving an adversary through it as a sequence of techniques, and observing detection and response as consequences of the model.

The transferable capability is the modelling of coupled cyber-physical infrastructure. The same structure of assets, links, states, telemetry and propagating events is what an industrial estate looks like when its network and control layers are represented alongside its machinery.

Technology

Unity 6 with the universal render pipeline. A headless simulation core, attack sequences as authored data, a real-time telemetry model, a live network graph, and desktop and browser builds with an explicit performance budget for each.

Limitations

This is not a security product. It does not monitor, detect or defend anything, it has no connection to a real network, and it must not be read as evidence that Alsadaany Industries operates a security service.

The estate and its telemetry are illustrative and have not been calibrated against a real network's recorded behaviour.

Attack scenarios follow authored technique sequences. They are a model of an adversary, not an emulation of one, and they are not a substitute for adversary emulation testing against real controls.

Status

Demonstration. Built and published to show complex systems modelling. Presented here as evidence of modelling capability rather than as a security offering.

What it demonstrates

The transferable capability, separated from the domain it happens to be shown in.

  • A topology modelled as an engineer would build it rather than as a diagram would draw it
  • Telemetry composed from baseline, drift, working-hours envelope and adversary effect
  • Scenarios as authored data rather than as code

Next step

Bring us the system you cannot test

Discovery establishes what a model of your operation would contain, what it would be built from, and whether it is the right instrument for the decision.

Prefer email? sales@alsadaany.com