01 · Sensing
Find
A synthetic sensor network detects an object inside a closed training environment.
Daily Break the Chain
A deterministic, evidence-led systems puzzle. The same synthetic scenario is available to everyone today: inspect what was observable, state your confidence, choose an interruption control, then compare the path not taken.
Daily Break the Chain · loading
Information is moving between connected nodes. One decision can change the path.
Synthetic scenario · no registration · no real target or external system
System view
Select a node to inspect its role without changing the authoritative state.
Briefing
The endpoint looks clean, but the identity trail does not.
Traditional cyber intrusion defense challenge
A fictional enterprise account begins accessing resources from two incompatible session contexts. Endpoint telemetry shows no malware alert, while identity and application logs indicate token reuse.
Correlate identity and endpoint evidence, distinguish a session compromise from a device infection, and contain the account without destroying forensic evidence.
Inspect evidence before committing to a hypothesis. High model confidence does not establish source integrity or authority.
Watch the chain form. Select a node in the spatial view or continue when you are ready to inspect the evidence objects.
Open the records that matter. Accurate evidence can still be irrelevant.
Choose the causal account best supported by what was observable at the time.
Select the narrowest control that constrains authority while preserving legitimate function.
Immediate consequence
Ground truth
Main insight
This result does not predict real combat outcomes, real infrastructure behavior, or the performance of any actual organization or system.
Counterfactual replay
Phantom timeline
Return without compulsion
Past daily scenarios remain available for review. Progress is stored only in this browser, missed days do not erase earlier work, and no account or behavioral profile is required.
Open analysis sandbox
Move freely through military F2T2EA, the traditional cyber intrusion sequence, or an attack chain against an AI system. Enable stage-specific controls and inspect nodes without changing the authoritative stage.
Analysis model
Preparing the synthetic event stream.
Authoritative state
Interface-state metrics only—not predictions of operational effectiveness, legality, or harm.
Stage
Loading synthetic state.
Observable
Human question
Break the chain
Enable controls, then advance. A matching control interrupts progression for review; continuing is allowed only for comparative learning.
01 · Sensing
A synthetic sensor network detects an object inside a closed training environment.
02 · Identity & location confidence
Independent synthetic sources are correlated to refine identity and position uncertainty.
03 · Continuity
The synthetic system maintains custody while displaying uncertainty growth during sensor loss.
04 · Decision support
Humans review mission purpose, evidence, alternatives, constraints, and legal requirements.
05 · Authorized simulated effect
A human-authorized, non-destructive simulated effect is applied inside the training environment.
06 · Effects & accountability
Post-action evidence is compared with the intended outcome without automatically generating a repeat action.
Guided · Challenge · Analysis
Guided mode explains each decision. Challenge mode adds a visible three-minute clock and rewards calibrated confidence. Analysis mode removes urgency and foregrounds provenance, the event sequence, ground truth, and alternative paths.
Guided
Prompts, contextual hints, clear evidence states, and recovery from a poor first decision make the first session understandable without prior training.
Challenge
A visible timer increases pressure, but speed is only one dimension. Unsupported confidence and disproportionate controls lower the assessment.
Analysis
Review the append-only event trail, reveal ground truth after resolution, rewind the decision point, and load a phantom alternative without erasing the first path.
Assessment without a destruction score
The action report does not count simulated casualties, targets, or damage. It evaluates evidence discipline, confidence calibration, intervention timing, authority containment, functional preservation, and whether the selected control actually interrupted the causal chain.
Did the user inspect relevant records, recognize provenance problems, and avoid mistaking accurate but irrelevant data for causal evidence?
A Brier-style dimension rewards confidence that matches the correctness of the selected hypothesis and penalizes unsupported certainty.
Did the intervention place a deterministic control at the point where a model, identity, sensor, or process could change external state?
Could the control stop the unsafe path without unnecessarily disabling trusted monitoring, approved models, legitimate users, or unrelated services?
One phrase, three distinct models
“Kill chain” can describe a military decision-and-engagement sequence, an intrusion lifecycle, or a staged attack against an AI-enabled application. The site keeps those meanings separate while showing their shared logic: linked dependencies and interruption points.
Military targeting doctrine
AI may assist sensing, fusion, classification, prioritization, guidance, or assessment. That does not by itself establish autonomous authority to use force.
Trace the functional chainCyber intrusion model
The classic Cyber Kill Chain presents an ordered campaign narrative. Modern adversary behavior can loop, overlap, or skip stages, so ATT&CK annotations add needed granularity.
Compare cyber stagesAttacks against AI systems
Here the AI system is the target or compromised intermediary. The trust boundary includes models, prompts, retrieval data, memory, tools, identities, and downstream actions.
Explore the AI security chainExpansion horizon
Version 1.2.0 adds the first public Evidence Atlas on top of the deterministic challenge, evidence, scoring, replay, and sharing primitives. Cooperative and authoring systems remain explicitly marked as future releases.
Filter country, doctrine, system, human-control, deployment, evidence, timeline, governance, and source layers using country-level abstraction rather than tactical deployment coordinates.
Two-to-six-person cooperative sessions with asymmetric evidence, role-specific authority, structured recommendations, facilitator controls, and a deterministic team debrief.
A constrained, declarative scenario editor with synthetic-data enforcement, reviewed components, publishing states, remix lineage, and no arbitrary scripts or external actions.
Trust and publication boundary
Every challenge is labeled synthetic. Result cards preserve the challenge code and methodological limitation. The friend link hides the sender’s solution until the recipient completes the same deterministic seed. No identity, raw headset pose, gaze, voice, exact location, or private note is included in the challenge state or result card.
The site remains an instructional environment: it does not execute attacks, contact external systems, accept real target data, model casualty outcomes, or provide weapon-design or operational targeting instructions.
Read the evidence and publication methodology, review the privacy design, or open the curated source library.