ATT&CK matrix tied to detectors.
Click a technique. See the detector that covers it. Pick a detection event, walk back to the receipt it produced.
MITRE ATT&CK v15.1 as the substrate
Every detector, every BAS scenario, every coverage assertion is keyed to ATT&CK v15.1 technique ids. Hover a cell to see the detectors that cover it, the BAS scenarios that exercise it, and the most recent witnessed detection receipt. The Navigator JSON layer is itself a signed artifact.
Anatomy — operational specs
Breach-and-attack simulation as IaC
Scenario WIRE-BEC-2026Q2 declared in OpenTofu HCL: emulator agents, isolated VPC, victim mailbox, spoofed sender infrastructure, OAuth consent lure. Re-applying the plan rebuilds the range from clean state. The playbook is the test, the plan hash is the version.
Anatomy — operational specs
Signed rules with ATT&CK coverage
R-DKIM-001 (RFC 6376), R-DMARC-014 (RFC 7489), R-AUTH-031 (T1078.004), R-BEC-227 (T1657 SimHash). Each rule is a code artifact with a version, a coverage assertion against ATT&CK, and a reproducible test vector from the BAS playbook. Detectors that lose coverage when ATT&CK is updated are flagged automatically.
Anatomy — operational specs
Offensive-capability playground as a service
Tenants spin up scenario environments from the BAS catalog. Each environment is one isolated VPC, one OpenTofu plan, one signed run archive. Re-running a scenario id reproduces the same coverage outcome — the range is a function, not a snowflake lab.
Anatomy — operational specs
The SIEM IS the receipt log
Every detector firing emits a cyber.detect.* receipt pinning the input artifact hash, the rule id and version, and the ATT&CK technique covered. ComplianceOS consumes the same receipt as evidence for NIST 800-53 SI-4 (System Monitoring) and AU-12 (Audit Record Generation). No separate SIEM table to reconcile.
Anatomy — operational specs
CyberSecurityOS, in one line
defense, made inspectable.
Click anything. The same primitives that compose the rest of the Transaction Science family — receipts, joules, signed transport — show up here too. The family is one system.