Bounded simulation: no real targets, coordinates, casualty models, weapon-performance parameters, executable payloads, or operational attack instructions.

Daily Break the Chain

Inspect the signal.Change the outcome.

A deterministic, evidence-led systems puzzle. The same synthetic scenario is available to everyone today: inspect what was observable, state your confidence, choose an interruption control, then compare the path not taken.

No registration Synthetic only Desktop + WebXR Local progress
Initializing immersive renderer…

Daily Break the Chain · loading

A chain is forming.

Information is moving between connected nodes. One decision can change the path.

Synthetic scenario · no registration · no real target or external system

Daily challenge

KC-2026-08-01-562798

System view

Loading the chain…

Select a node to inspect its role without changing the authoritative state.

observed unverified human gate interrupted

Briefing

The Opaque Package

Coordinator

A high-performing model package cannot prove where it came from.

AI supply-chain provenance challenge

Situation

A fictional analytics team receives a model package from an unverified mirror. It passes a basic benchmark and promises better accuracy, but its manifest, build lineage and serialization policy are incomplete.

Your mission

Decide whether the package is merely poorly documented or unsafe to promote, then choose a control that protects the production boundary without blocking approved releases.

Guided mode

Inspect evidence before committing to a hypothesis. High model confidence does not establish source integrity or authority.

Open analysis sandbox

Trace three different meanings of “kill chain.”

Move freely through military F2T2EA, the traditional cyber intrusion sequence, or an attack chain against an AI system. Enable stage-specific controls and inspect nodes without changing the authoritative stage.

Initializing visual renderer…

Analysis model

Loading simulation…

Preparing the synthetic event stream.

Active Traversed Future

Authoritative state

ActiveChain status
0Event sequence
0/0Controls active
0%Progress

Interface-state metrics only—not predictions of operational effectiveness, legality, or harm.

Stage

Initializing

00 / 00

Loading synthetic state.

Observable

Human question

Break the chain

Defensive and governance controls

Enable controls, then advance. A matching control interrupts progression for review; continuing is allowed only for comparative learning.

01 · Sensing

Find

A synthetic sensor network detects an object inside a closed training environment.

02 · Identity & location confidence

Fix

Independent synthetic sources are correlated to refine identity and position uncertainty.

03 · Continuity

Track

The synthetic system maintains custody while displaying uncertainty growth during sensor loss.

04 · Decision support

Target

Humans review mission purpose, evidence, alternatives, constraints, and legal requirements.

05 · Authorized simulated effect

Engage

A human-authorized, non-destructive simulated effect is applied inside the training environment.

06 · Effects & accountability

Assess

Post-action evidence is compared with the intended outcome without automatically generating a repeat action.

Guided · Challenge · Analysis

One event model, three ways to learn.

Guided mode explains each decision. Challenge mode adds a visible three-minute clock and rewards calibrated confidence. Analysis mode removes urgency and foregrounds provenance, the event sequence, ground truth, and alternative paths.

Guided

Learn the visual language

Prompts, contextual hints, clear evidence states, and recovery from a poor first decision make the first session understandable without prior training.

Challenge

Commit under uncertainty

A visible timer increases pressure, but speed is only one dimension. Unsupported confidence and disproportionate controls lower the assessment.

Analysis

Freeze, inspect, and compare

Review the append-only event trail, reveal ground truth after resolution, rewind the decision point, and load a phantom alternative without erasing the first path.

Assessment without a destruction score

Measure reasoning, authority, and preservation.

The action report does not count simulated casualties, targets, or damage. It evaluates evidence discipline, confidence calibration, intervention timing, authority containment, functional preservation, and whether the selected control actually interrupted the causal chain.

01

Evidence discipline

Did the user inspect relevant records, recognize provenance problems, and avoid mistaking accurate but irrelevant data for causal evidence?

02

Confidence calibration

A Brier-style dimension rewards confidence that matches the correctness of the selected hypothesis and penalizes unsupported certainty.

03

Authority containment

Did the intervention place a deterministic control at the point where a model, identity, sensor, or process could change external state?

04

Functional preservation

Could the control stop the unsafe path without unnecessarily disabling trusted monitoring, approved models, legitimate users, or unrelated services?

One phrase, three distinct models

Do not collapse them into one definition.

“Kill chain” can describe a military decision-and-engagement sequence, an intrusion lifecycle, or a staged attack against an AI-enabled application. The site keeps those meanings separate while showing their shared logic: linked dependencies and interruption points.

Military targeting doctrine

Find → Fix → Track → Target → Engage → Assess

AI may assist sensing, fusion, classification, prioritization, guidance, or assessment. That does not by itself establish autonomous authority to use force.

Trace the functional chain

Cyber intrusion model

Reconnaissance → Actions on Objectives

The classic Cyber Kill Chain presents an ordered campaign narrative. Modern adversary behavior can loop, overlap, or skip stages, so ATT&CK annotations add needed granularity.

Compare cyber stages

Attacks against AI systems

Recon → Poison → Hijack → Persist → Impact

Here the AI system is the target or compromised intermediary. The trust boundary includes models, prompts, retrieval data, memory, tools, identities, and downstream actions.

Explore the AI security chain

Expansion horizon

The event model now supports the next immersive layers.

Version 1.2.0 adds the first public Evidence Atlas on top of the deterministic challenge, evidence, scoring, replay, and sharing primitives. Cooperative and authoring systems remain explicitly marked as future releases.

Available · v1.2

Global Evidence Atlas

Filter country, doctrine, system, human-control, deployment, evidence, timeline, governance, and source layers using country-level abstraction rather than tactical deployment coordinates.

Open the Evidence Atlas

Planned · Multiplayer

Kill Chains War Room

Two-to-six-person cooperative sessions with asymmetric evidence, role-specific authority, structured recommendations, facilitator controls, and a deterministic team debrief.

Planned · Authoring

Creator Studio

A constrained, declarative scenario editor with synthetic-data enforcement, reviewed components, publishing states, remix lineage, and no arbitrary scripts or external actions.

Trust and publication boundary

Exciting does not mean context-free.

Every challenge is labeled synthetic. Result cards preserve the challenge code and methodological limitation. The friend link hides the sender’s solution until the recipient completes the same deterministic seed. No identity, raw headset pose, gaze, voice, exact location, or private note is included in the challenge state or result card.

The site remains an instructional environment: it does not execute attacks, contact external systems, accept real target data, model casualty outcomes, or provide weapon-design or operational targeting instructions.

Read the evidence and publication methodology, review the privacy design, or open the curated source library.