Structural Application HostCasebook · Cybersecurity Edition
Books
Cybersecurity
security-agent · Agent A · v1.4
Runtime V3 · r44 · splunk-cim
Structural0
Neural0
Constitution v3

Runtime lifecycle

Demonstration data. Books & recognition authoring (Grow mode) renders curated demo state shaped like the future Runtime API responses. The live V3 Reflection & Governance engine connects here post-first-customer — one config flip, no rewrite.

Grow mode. Teach the Agent how meaning appears in your World — build Customer Books on top of the protected standard, add source vocabulary, and teach recognition profiles. Agent A is never edited directly; every change is proven on Agent B before it can go live.

Book library · library · v12

Credential Threats — Standard

The protected standard for credential-abuse and brute-force recognition. Read-only; extend it with a Customer Book below.

Protected standard

Concepts in this Book

Brute forceCredential stuffingPassword sprayImpossible travel

Recognition profiles

Brute forceTemporal aggregation Protected

≥ 50 correlated authentication failures for one user inside one episode

Impossible travelEntity relationships Protected

Two successful logins from geographically incompatible locations within the travel window

The protected standard is never edited directly. Clone it to build a Customer Book on top.

Terminology overlays

Map an internal system label to a human-readable term. Presentation only — the agent's canonical identifiers and logic never change.

No terminology overlays yet. Add your first mapping above.