Automation kill switch
Immediately stop or resume all automated and approved execution
Released: automation runs under the approval matrix below.
Human-approval matrix
Policy rules, not model judgement
Monitor, enrich, close predefined benign
Human optional
Enrich, ticket, recommend
Human review
Recommend containment
SOC approval required
Immediate escalation + recommendation
Authorized approver required
Approval queue
High and Critical actions held at the gate — nothing destructive executes without an authorized human
A targeted phishing message harvested credentials for an elevated Grid Operations account. The account authenticated from an unfamiliar ASN, and encoded PowerShell then executed on the SCADA historian with LSASS access attempts.
T1566.002T1078.002T1059.001T1003.001risk 64Isolate endpointA field-services workstation performed internal port sweeps across three subnets shortly after a VPN reconnection. Under investigation; scoped monitoring increased.
T1046T1133risk 32Block external IP at perimeterA distributed spray attempted 4,180 authentications across 612 accounts over 9 hours, followed by repeated MFA push prompts against three targeted users. No successful compromise observed.
T1110.003T1621risk 28Revoke active sessionsAutomated actions
Low and Medium work the agent performs without a human
INC-2041 · 3 indicator matches, 1 actor, 1 campaign returned.
INC-2041 · 24h extended telemetry pulled for nwu-scada-hist-01.
INC-2041 · Case CASE-8814 opened with evidence package attached.
INC-2044 · nwu-bkp-vault-01 network-quarantined; management channel retained.
INC-2044 · svc-etl-runner credentials rotated and disabled.
INC-2042 · Edge deny rule for 192.0.2.219 applied, 24h TTL.
INC-2043 · Monitoring level raised for 3 targeted identities.
INC-2045 · Case CASE-7781 opened; user verification requested.
INC-2046 · Monitoring raised on nwu-field-ws-061 and the VPN edge.
Playbooks
Scenario playbooks the orchestrator follows
Phishing-led credential compromise · floor High
- Enrich sender, URL and file indicators
- Correlate identity sign-in anomalies
- Collect endpoint telemetry for affected hosts
- Recommend session revocation
- Hold containment for approval
- Generate audience-scoped reports
Suspected implant / beaconing · floor High
- Confirm periodicity and rarity
- Match destination against TI
- Check vulnerability timeline on the asset
- Recommend perimeter block
- Rebuild affected workload
- Capture lessons learned
Credential spray / MFA fatigue · floor Medium
- Quantify spray breadth and success
- Identify targeted identities
- Enrich source infrastructure
- Recommend session revocation
- Raise monitoring
- Propose MFA policy change
Ransomware precursor · floor Critical
- Detect recovery inhibition
- Hash-match staged artefacts
- Identify lateral delivery path
- Request isolation approval
- Disable abused credentials
- Verify recovery estate
Benign verification & closure · floor Low
- Check identity and device posture
- Check documented exceptions
- Request user verification
- Close with rationale retained
Allowlisted action catalogue
Agent → approved API → restricted service account → specific allowed action (all simulated)
Enrich with threat intelligence
Query the simulated TI platform for indicator, malware, actor and campaign context.
Scope: Read-only TI lookup · non-destructive · None
Create investigation ticket
Open a case in the simulated ticketing system with evidence attached.
Scope: SOAR case queue · non-destructive · None
Collect extended host logs
Pull extended endpoint telemetry for the affected asset.
Scope: Named asset, 24h window · non-destructive · None
Notify asset owner
Send a notification to the asset owner with the incident summary.
Scope: Owner of record from CMDB · non-destructive · None
Increase monitoring level
Raise telemetry verbosity and detection sensitivity for the entity.
Scope: Named asset / identity · non-destructive · None
Isolate endpoint
Network-quarantine the host through the EDR platform, management channel retained.
Scope: Single asset, EDR network quarantine · destructive · Authorized Approver
Disable user account
Disable the account in the identity provider.
Scope: Single non-break-glass identity · destructive · Authorized Approver
Revoke active sessions
Invalidate refresh tokens and active sessions for the identity.
Scope: Single identity, all tokens · destructive · SOC Approval
Block external IP at perimeter
Add a time-boxed deny rule at the edge firewall.
Scope: Single external address, 24h TTL · destructive · SOC Approval
Quarantine email message
Remove the message from all mailboxes in the tenant.
Scope: Named message, tenant-wide purge · destructive · SOC Approval
Apply firewall policy change
Push a scoped firewall policy change through the approved API.
Scope: Named rule set, change-window bound · destructive · Authorized Approver
Disable service credentials
Rotate and disable credentials for a service account.
Scope: Single service principal · destructive · Authorized Approver