Security operations
Cyber Tracker
Status: DemonstrationDemonstration systemInternal system, not a customer deployment
Forty-five assets across seven tiers joined by 113 links, each carrying fifteen telemetry channels, with five attack scenarios that play out end to end and respond to the operator. Every number on screen comes from a model that runs, and can be tested, without a renderer in the scene.
- Modelled assets
- 45
- Network links
- 113
- Telemetry channels per asset
- 15
- Attack scenarios
- 5
Properties of the model
These describe this model. None is a benchmark, a customer result, or a claim about a real facility.
Problem
Detection coverage is usually asserted rather than demonstrated. Whether a set of controls would actually catch a given adversary depends on the estate's topology, on what telemetry each asset produces, on how that telemetry behaves normally, and on which of it an analyst is in a position to act upon. Those are systems questions, and answering them by argument is how organisations arrive at confidence they have not earned.
This system reproduces the estate, the telemetry and the adversary so that the question can be examined. It is an internal system built and published by Alsadaany Industries. It is not a customer deployment, and the operation it models is illustrative. It is a simulation and cyber-physical modelling demonstration, not a deployed security product.
System
An enterprise estate of 45 assets across seven tiers: internet, firewall and VPN, DMZ and load balancers, web and application servers, databases, directory and file servers, endpoints, and an operational technology segment of cameras, printers and controllers. The tiers are honoured as the visual layering, while the 113 links are wired the way a real network is, branching and partially meshed, with the OT segment behind its own boundary.
That distinction is deliberate. A straight descending chain would be easier to draw and would not survive thirty seconds of scrutiny from a network architect.
Model
Fifteen telemetry channels per asset covering CPU, memory, disk, bandwidth, connections, sessions, processes, logins, DNS, HTTP, HTTPS, SMTP, SSH, RDP and VPN, plus throughput, latency and packet loss per link.
Each channel is composed rather than randomised: a baseline, organic drift, a working-hours envelope, and whatever the current attack is doing to it, smoothed. There is no per-frame randomness anywhere in the model, which is what makes an anomaly in it mean something.
Simulation
Five scenarios are modelled: phishing, ransomware, insider threat, distributed denial of service, and a zero-day. Each is authored as a sequence of beats the attack manager interprets. It selects targets, ramps risk and compromise, applies resource pressure, lights the links the attacker traverses, fires detections and drives the analyst view.
Because the sequences are data rather than code, adding a scenario is an authoring job. That is what makes the system usable for examining coverage against a technique sequence rather than only for watching the five that ship with it.
Engineering
The model runs, and can be tested, with no renderer in the scene. The build can also photograph itself unattended at specified simulation times, from the same seed, so demonstration material is regenerated after a change rather than re-shot by hand.
The browser build trims itself deliberately rather than degrading unpredictably: post-processing effects are dropped, the packet cap falls from 1,400 to 550, shadow distance is reduced, and frame pacing is handed back to the browser.
Demonstrated capability
The system demonstrates modelling a heterogeneous estate including an OT segment, generating plausible telemetry with the statistical structure real telemetry has, driving an adversary through it as a sequence of techniques, and observing detection and response as consequences of the model.
The transferable capability is the modelling of coupled cyber-physical infrastructure. The same structure of assets, links, states, telemetry and propagating events is what an industrial estate looks like when its network and control layers are represented alongside its machinery.
Technology
Unity 6 with the universal render pipeline. A headless simulation core, attack sequences as authored data, a real-time telemetry model, a live network graph, and desktop and browser builds with an explicit performance budget for each.
Limitations
This is not a security product. It does not monitor, detect or defend anything, it has no connection to a real network, and it must not be read as evidence that Alsadaany Industries operates a security service.
The estate and its telemetry are illustrative and have not been calibrated against a real network's recorded behaviour.
Attack scenarios follow authored technique sequences. They are a model of an adversary, not an emulation of one, and they are not a substitute for adversary emulation testing against real controls.
Status
Demonstration. Built and published to show complex systems modelling. Presented here as evidence of modelling capability rather than as a security offering.
What it demonstrates
The transferable capability, separated from the domain it happens to be shown in.
- A topology modelled as an engineer would build it rather than as a diagram would draw it
- Telemetry composed from baseline, drift, working-hours envelope and adversary effect
- Scenarios as authored data rather than as code
More work
The other systems
Next step
Bring us the system you cannot test
Discovery establishes what a model of your operation would contain, what it would be built from, and whether it is the right instrument for the decision.
Prefer email? sales@alsadaany.com