Warden
3 awaiting decision
Data as of 21 Aug 2026 16:40 UTC

Automation kill switch

Immediately stop or resume all automated and approved execution

Released: automation runs under the approval matrix below.

Human-approval matrix

Policy rules, not model judgement

Low

Monitor, enrich, close predefined benign

Human optional

Medium

Enrich, ticket, recommend

Human review

High

Recommend containment

SOC approval required

Critical

Immediate escalation + recommendation

Authorized approver required

Approval queue

High and Critical actions held at the gate — nothing destructive executes without an authorized human

Critical INC-2041Credential phishing to hands-on-keyboard activity on grid historian

A targeted phishing message harvested credentials for an elevated Grid Operations account. The account authenticated from an unfamiliar ASN, and encoded PowerShell then executed on the SCADA historian with LSASS access attempts.

T1566.002T1078.002T1059.001T1003.001risk 64Isolate endpoint
High INC-2046East-west service discovery from field workstation

A field-services workstation performed internal port sweeps across three subnets shortly after a VPN reconnection. Under investigation; scoped monitoring increased.

T1046T1133risk 32Block external IP at perimeter
Medium INC-2043Password spraying with MFA fatigue against cloud tenant

A distributed spray attempted 4,180 authentications across 612 accounts over 9 hours, followed by repeated MFA push prompts against three targeted users. No successful compromise observed.

T1110.003T1621risk 28Revoke active sessions

Automated actions

Low and Medium work the agent performs without a human

Enrich with threat intelligenceAutomated

INC-2041 · 3 indicator matches, 1 actor, 1 campaign returned.

Collect extended host logsAutomated

INC-2041 · 24h extended telemetry pulled for nwu-scada-hist-01.

Create investigation ticketAutomated

INC-2041 · Case CASE-8814 opened with evidence package attached.

Isolate endpointApproved

INC-2044 · nwu-bkp-vault-01 network-quarantined; management channel retained.

Disable service credentialsApproved

INC-2044 · svc-etl-runner credentials rotated and disabled.

Block external IP at perimeterApproved

INC-2042 · Edge deny rule for 192.0.2.219 applied, 24h TTL.

Increase monitoring levelAutomated

INC-2043 · Monitoring level raised for 3 targeted identities.

Create investigation ticketAutomated

INC-2045 · Case CASE-7781 opened; user verification requested.

Increase monitoring levelAutomated

INC-2046 · Monitoring raised on nwu-field-ws-061 and the VPN edge.

Playbooks

Scenario playbooks the orchestrator follows

Phishing-led credential compromise · floor High
  1. Enrich sender, URL and file indicators
  2. Correlate identity sign-in anomalies
  3. Collect endpoint telemetry for affected hosts
  4. Recommend session revocation
  5. Hold containment for approval
  6. Generate audience-scoped reports
Suspected implant / beaconing · floor High
  1. Confirm periodicity and rarity
  2. Match destination against TI
  3. Check vulnerability timeline on the asset
  4. Recommend perimeter block
  5. Rebuild affected workload
  6. Capture lessons learned
Credential spray / MFA fatigue · floor Medium
  1. Quantify spray breadth and success
  2. Identify targeted identities
  3. Enrich source infrastructure
  4. Recommend session revocation
  5. Raise monitoring
  6. Propose MFA policy change
Ransomware precursor · floor Critical
  1. Detect recovery inhibition
  2. Hash-match staged artefacts
  3. Identify lateral delivery path
  4. Request isolation approval
  5. Disable abused credentials
  6. Verify recovery estate
Benign verification & closure · floor Low
  1. Check identity and device posture
  2. Check documented exceptions
  3. Request user verification
  4. Close with rationale retained

Allowlisted action catalogue

Agent → approved API → restricted service account → specific allowed action (all simulated)

Enrich with threat intelligence

Query the simulated TI platform for indicator, malware, actor and campaign context.

Scope: Read-only TI lookup · non-destructive · None

Create investigation ticket

Open a case in the simulated ticketing system with evidence attached.

Scope: SOAR case queue · non-destructive · None

Collect extended host logs

Pull extended endpoint telemetry for the affected asset.

Scope: Named asset, 24h window · non-destructive · None

Notify asset owner

Send a notification to the asset owner with the incident summary.

Scope: Owner of record from CMDB · non-destructive · None

Increase monitoring level

Raise telemetry verbosity and detection sensitivity for the entity.

Scope: Named asset / identity · non-destructive · None

Isolate endpoint

Network-quarantine the host through the EDR platform, management channel retained.

Scope: Single asset, EDR network quarantine · destructive · Authorized Approver

Disable user account

Disable the account in the identity provider.

Scope: Single non-break-glass identity · destructive · Authorized Approver

Revoke active sessions

Invalidate refresh tokens and active sessions for the identity.

Scope: Single identity, all tokens · destructive · SOC Approval

Block external IP at perimeter

Add a time-boxed deny rule at the edge firewall.

Scope: Single external address, 24h TTL · destructive · SOC Approval

Quarantine email message

Remove the message from all mailboxes in the tenant.

Scope: Named message, tenant-wide purge · destructive · SOC Approval

Apply firewall policy change

Push a scoped firewall policy change through the approved API.

Scope: Named rule set, change-window bound · destructive · Authorized Approver

Disable service credentials

Rotate and disable credentials for a service account.

Scope: Single service principal · destructive · Authorized Approver