What Frostbow Knows About Activity in the Network

Before Frostbow can reason about anything, it has to recognize patterns: which kinds of activity tend to be normal, which look like the early signs of an attack, which it has seen often enough to act on. The panels below are how the system tracks each pattern as it accumulates evidence, how it watches for patterns whose shape is drifting, and how it grades the reliability of every pattern it relies on.

Patterns Frostbow Has Learned to Recognize

Each entry below is a pattern of activity Frostbow has identified by watching signals repeat over time. The system gets sharper as more examples come in. The patterns it has seen most often, across the most hosts, get promoted to be shared across all customers.

Loading patterns...

Patterns That Are Changing Shape

Every pattern Frostbow knows has a typical “signature”: the signals that fit it, when they fire, which hosts they hit. If that signature starts to drift over time, the underlying activity may be changing. An attacker may be mutating their technique, or the network itself may be shifting. Patterns drifting fast enough to require attention are flagged below.

Loading drift data...

How Reliable Each Pattern Is

Each pattern Frostbow uses to score new signals has a quality score built from how strong the signal is, how stable its shape stays over time, and how often its calls have agreed with analyst rulings. Patterns that fall below the bar get flagged for review; patterns Frostbow has not seen in a long time get marked dormant.

Loading health data...
Concept Detail

How Frostbow Checks Its Own Work

Frostbow does not just act; it watches itself act. The panels below are how the system measures its own confidence, catches its own mistakes, and decides when to stop itself, holding a case open instead of closing it automatically. Each one is built from production data, not policy documents.

Loading metacognition data...

How Well Frostbow Knows Each Behavior It Recognizes

Rows are grouped by the learned concept Frostbow most associates with each signal — what it recognizes. For each, Frostbow tracks how often its calls have agreed with analyst rulings. The Self-Model needs roughly ten verified analyst decisions before it can speak with confidence about precision and recall. As Frostbow runs in more environments and analysts review more decisions, more classes cross that bar. The “uncertainty band” widens when sample size is small: narrow band means many samples and a confident read, wide band means few samples and a soft read. Caution rows () indicate low sample count (<10), wide uncertainty band (>30 pp), high miss rate (>20%), or data not updated in 7+ days.

Loading self-model data...
Signal Class Detail

How Frostbow Reasons About What It Sees

Recognizing a pattern is one thing; reasoning about it is another. The panels below are how Frostbow connects suspicious events into chains, learns how attack patterns relate to each other, predicts what an attacker is likely to do next, and tests competing theories about activity it has not yet fully understood.

How Frostbow Connects Suspicious Events Into Chains

When two or more suspicious events on the same host fit a known attack sequence (the kind of progression a real attacker would follow), Frostbow ties them together into a chain. Each chain below shows the steps in order and how confident Frostbow is that the sequence reflects real activity, not noise.

Loading chains...

Attack Recipes Frostbow Has Learned to Recognize

When the same chain of events plays out enough times across the network, Frostbow records the sequence as a template: a recipe of attack steps in a specific order. The next time it sees the first few steps of a known recipe play out, it can predict what comes next.

Loading templates...

Multi-Phase Activity Frostbow Has Stitched Together

A campaign is a sequence of suspicious activity on a single host that spans multiple attack phases over hours or days. Frostbow stitches campaign fragments together by linking the chains that share a host and timeline, then scores the stitched result against doctrine. The default view below shows the campaigns that warranted analyst engagement: cases resolved as a real threat and cases an analyst acknowledged. Most stitched candidates turn out to be benign workflows that incidentally crossed multiple kill-chain phases (admin tooling, scheduled tasks, software installs) and resolve without analyst action; use the All or Benign tabs to see those.

Loading campaigns...

What Frostbow Expects to See Next

When Frostbow recognizes the early steps of an attack pattern it has seen before, it predicts what the attacker is likely to do next: the technique, the target host, the time window. Each prediction has a confidence score and an outcome the system verifies or refutes against subsequent events.

Loading predictions...

Competing Theories Frostbow Is Testing

For each open chain, Frostbow generates two or three competing hypotheses about what the attacker is doing: “this looks like reconnaissance,” “this looks like lateral movement,” “this looks like persistence.” Each hypothesis has a short window during which a confirming event would prove it. Most hypotheses expire by design: they are short-lived guesses about the next step, not the system's overall view.

Loading hypotheses...

How Attack Patterns Relate to Each Other

Each node is an attack pattern Frostbow has observed; each arrow is a causal relationship learned from real activity. Stronger arrows indicate relationships seen more often. Drag nodes to rearrange the view; use the filter or search to focus on a tactic or pattern.

indicates
precedes
enables
requires
Loading causal graph...

Investigations Frostbow Has Queued for Itself

When Frostbow's predictions or hypotheses identify something worth a closer look (an attacker move it expects, a chain it wants to confirm), it generates an investigation plan: a hunt mission. The autonomous threat hunter picks these up and runs them.

Loading missions...

The Rules and Actions Frostbow Operates Under

Frostbow is allowed to act on its own only inside a set of rules: which kinds of activity it can act on, which it holds open for a person to decide instead of closing automatically, and which it must refuse to act on no matter how confident it is. The panels below are those rules, the recent actions taken under them, the open recommendations it has surfaced for a person to decide, and the hosts the system has placed under closer watch. Every autonomous action is reversible and time-bounded.

What Frostbow Is Recommending Right Now

Suggestions Frostbow has generated from its current view of activity but has not acted on autonomously. Each recommendation has a rationale, a target, and a confidence score; Frostbow does not act on it automatically — it stays open for a person to decide.

Loading recommendations...

What Frostbow Did on Its Own

Every low-disruption action Frostbow has taken without asking a human first. Each carries a rollback plan and a time-to-live, and is logged here for audit.

Loading actions...

Hosts Frostbow Is Watching Closely

After Frostbow takes an autonomous action on a host, or while a suspicious chain on that host is still being investigated, the system keeps the host on a closer-watch list. Each entry has a reason and a time-to-live; the host leaves the list when the watch period expires or the underlying chain resolves.

Loading watched hosts...

The Rules Frostbow Follows

Frostbow has codified rules about which kinds of activity it is allowed to act on autonomously, which it holds open for a person to decide instead of closing automatically, and which it must refuse to act on no matter how confident it is. The rules below are pulled from the live doctrine module; each one is enforced at decision time on every signal.

Loading doctrine policy...

Why Frostbow Did What It Did

When Frostbow's doctrine layer makes or holds a decision, this panel shows the evidence it relied on, the rule it applied, explained in plain English, and why that rule fit this alert.

This panel shows the decisions made by Frostbow's doctrine layer: the protected-asset holds and constraint checks that govern its most consequential calls. Coverage grows as more of Frostbow's decision paths route through that layer.

Loading provenance...
Foresight

A system reasoning about attacks that haven't happened yet.

  • What it doesPredicts where attacks are likely to land before they happen and marks those endpoints on the risk heat map. It generates likely attack variants from the structure it has already learned.
  • Why it mattersIt moves Frostbow from catching attacks as they happen to anticipating them ahead of time — a shift from reacting to what has occurred to reasoning about what has not occurred yet.
  • What makes it novelMost AI security recognizes only what it was trained on. Foresight reasons its way to attack patterns it was never shownnew combinations of components it has already seen — by understanding how attacks are assembled from their parts.
Advisory only — no automated action

What this is, stated plainly

  • Advisory only. Foresight surfaces risk and heightens monitoring. It takes no automated action — it blocks nothing and changes no live decision.
  • The bounded claim. Predictions are combinatorial: novel combinations of known attack components. On a fair held-out test the generator beat chance by 10.0×. It does not predict wholly new tools or techniques, and it is not a certainty — it is a high-signal early warning, not an oracle.
  • How we know. The held-out test, the chance baseline, and the committed, reproducible harness are open to inspection. See the evidence & methodology →
  • Coverage is partial. The map highlights a specific subset of the fleet where predicted patterns matched observed activity. Coverage grows as more fleet-relevant attack data is learned — this is not full-fleet coverage.
The living risk map

Where Frostbow is watching, right now

Each tile is an endpoint where observed activity matched one or more predicted attack patterns. Colour intensity is the match load — how many distinct predicted patterns lined up on that endpoint — so the few high-load endpoints stand out from the many that matched only once or twice. Click any tile for the receipts.

Loading the risk map…

How we know — check it yourself

This is measurement, not marketing.

The capability above rests on a held-out backtest: the system was shown one set of real attacks and correctly anticipated attack variants — new combinations of known components — from a completely separate set of recordings it was never given (a fair, by-recording holdout), beating a stated chance baseline. The test, the split, the baseline, and the harness that produced them are committed and reproducible. Open the full evidence view →