Structural Application HostCasebook · Cybersecurity Edition
Knowledge in Use
Cybersecurity
security-agent · Agent A · v1.4
Runtime V3 · r44 · splunk-cim
Structural0
Neural0
Constitution v3

Runtime lifecycle

This screen explains the knowledge being applied — it is read-mostly. You can submit proposals here; deliberate engineering (authoring Books, Concept ladders, baseline schemas) happens in the IDE.

Activated Books

Authentication Threat Detection Set v3

Concept versions used

Normal Authentication Baselineauth_baseline · v1
Credential Compromisecredential_compromise · v1
Credential Abusecredential_abuse · v1

Baseline applied

Business-hours authentication baseline · v4

Known users + svc-backup service account, weekdays 07:00–19:00. Deviations above this baseline drive credential-abuse activation.

Vocabulary & field mappings

source_ip source_ip
timestamp observed_at
user user_identity
event_code event_code
host host
process process

Known Errors & expected behaviors

No Known Errors matched this session.

Expected behavior: svc-backup logging in hourly is baseline, not a finding.

Knowledge provenance

Customer overlayacme-corp · v7
Concept activations3
Atoms considered616
Author chainJulius Jenkins

Bounded actions

Proposals are evidence-linked and target Agent B — never live Agent A. Production editing is disabled in the Demonstration Edition.