Dallas, Texas, USA
0
Follow on

CHAIN

A PREDICTIVE ADVERSARY EMULATION CHAINING SIMULATOR

CHAIN traverses the Unified Kill Chain to transform a single observed adversary action into a forward-looking attack projection — mapping likely next steps across all 18 UKC phases so your team can act not react.
HOW IT WORKS
Image link
18
UKC Phases
ATT&CK
MITRE Aligned
Attack Paths
AI
Predictive Engine
THE INSTRUMENT

An AI-driven kill chain engine that tells you where the adversary is going before they get there.

CHAIN is purpose-driven to do one job. It takes a confirmed adversary action — a single observed TTP, a log signal, an analyst finding — and traverses the Unified Kill Chain forward from that point, predicting the most probable next moves with MITRE ATT&CK alignment and ranked confidence scoring, so defenders stop waiting and start preempting.

FORM FACTOR

Web-based simulation interface. No install, no client software. Feed CHAIN an observed action and receive a structured prediction report in seconds — accessible to analysts, threat hunters, and IR leadership from any modern browser.

TRAVERSAL MODEL

CHAIN maps the input action to its position within the 18-phase Unified Kill Chain and projects forward across In, Through, and Out phases — modeling adversary momentum, objective convergence, and likely branching paths from that point in the intrusion lifecycle.

INPUTS

A single observed adversary action described in natural language, a MITRE ATT&CK technique ID, or a structured TTP from an active investigation. Optional context — threat actor profile, targeted asset class, sector — sharpens prediction fidelity.

OUTPUTS

A ranked list of predicted next adversary steps with associated ATT&CK technique mappings, confidence tiers (High / Medium / Low), and recommended defensive countermeasures for each projected move. Exportable for briefing, ticketing, or playbook activation.

INTEGRATIONS

Native output compatible with SCOUT, TheHive, and MITRE ATT&CK Navigator. Prediction exports available in structured JSON for SIEM ingestion and case management enrichment.

THREE PILLARS OF PREDICTION

An action, a traversal, and a ranked forecast. The same three steps every effective defender needs — executed in seconds.

Every CHAIN projection is built on three components working in sequence. The observed action anchors the analysis to reality. The traversal engine maps the adversary's probable trajectory across the kill chain. The prediction output hands defenders a prioritized list of what to block before it happens.

Image link

PIL. 01

The Observed Action

CHAIN starts with a single confirmed signal from the field — a MITRE ATT&CK technique, a natural language description of analyst findings, or a structured TTP pulled from an active investigation. No hypotheticals. The input anchors the entire projection to something real that already happened.

 


INPUT FORMATSATT&CK ID, Natural Language, TTP
OPTIONAL CONTEXTActor Profile, sector, asset
SOURCEAnalyst, SIEM, case file
Image link

PIL. 02

The Traversal Engine

CHAIN locates the observed action within the 18-phase Unified Kill Chain and projects forward — modeling adversary momentum across the In, Through, and Out phases. The AI evaluates objective convergence, historical actor behavior, and technique adjacency to surface the most probable continuation paths, not just adjacent techniques.

 


FRAMEWORKUnified Kill Chain (18 Phases)
MAPPED TOMITRE ATT&CK
PATH MODELINGAI — branching + weighted
Image link

PIL. 03

The Prediction

Every projection is a ranked report — High, Medium, and Low confidence next steps, each tagged with the ATT&CK technique, the UKC phase it falls in, and a recommended defensive action. Defenders don’t get a list of possibilities. They get a prioritized ops order for what to cover first.

 

 


CONFIDENCE TIERSHigh / Medium / Low
PER PREDICTIONATT&CK tag + countermeasure
EXPORTJSON, report, Navigator layer
THE TRAVERSAL ENGINE

Eighteen phases. Every move an adversary makes after initial access, mapped and predicted before it lands.

The traversal engine resolves the observed action to its position in the Unified Kill Chain, then models forward momentum across all remaining phases — weighting continuation paths by technique adjacency, objective proximity, and actor behavioral patterns. Each phase transition produces a ranked prediction with ATT&CK alignment and a paired defensive action.

Reconnaissance

Phase 1 of 18 → adversary profiling & target selection

Weaponization & Delivery

Phases 2–3 → payload staging & initial vector

Exploitation & Persistence

Phases 4–5 → foothold establishment & survival

Defense Evasion & C2

Phases 6–9 → dwell extension & remote control

Pivoting & Discovery

Phases 10–12 → lateral movement & asset enumeration

Collection & Exfiltration

Phases 13–15 → data staging & exfil channel selection

Impact & Objectives

Phases 16–18 → mission execution & final effect

CONFIDENCE SCORING

Every prediction ends with a confidence tier. The model is open. You can read every signal that produced it.

The confidence score isn't a black box. Every ranked prediction CHAIN produces is the result of documented signals — technique adjacency, phase proximity, actor behavioral alignment, asset exposure, and objective convergence — each contributing a weighted value to the final High / Medium / Low tier. Analysts can audit exactly why a prediction ranked where it did.

// SIGNAL DESCRIPTION WEIGHT
01 PER-STEP SCORE: What you see on each tree node
LLM likelihood Claude's predicted probability that this specific action is the actor's next move, given the full path so far and any environment context. 65%
Deterministic ATT&CK Prior A rule-based score, independent of the LLM: kill-chain position blended with known technique-to-technique pivot strength. 35%
02 DETERMINISTIC PRIOR, EXPANDED: What makes up the 35%
Kill-Chain Position How far the candidate's Unified Kill Chain tactic sits past the furthest progressed tactic observed so far (the "Frontier") Produces the starting value, 5–98, before any bonus is applied.
Known ATT&CK Chain Applies when the current technique has a curated, documented pivot to the candidate(e.g. Spearphishing Attachment → User Execution), scaled by that pivot's authored strength. +0–25 bonus and a 0–95 score floor, both scaled by edge strength (0–1).
03 FULL-CHAIN CONFIDENCE — REPORT ONLY
Computed Path Confidence Likelihood-weighted mean of every predicted step's blended score, weighted by 0.9 so near-term steps count more than the peculative tail. 60%
Model Self-Assessed Confidence Claude's own 0-100 confidence in the whole analysis, explicitly instructed to calibrate down for long, speculative chains or thin evidence. 40%
END TO END

Input, traverse, predict, act. One tool, four stages, no analyst guesswork.

Most threat analysis ends with a long list of possibilities and a team that doesn't know where to start. CHAIN collapses the cycle into a single workflow — an observed action goes in, a ranked and mapped prediction comes out, and every output is wired for immediate defensive action or case management enrichment.

STAGE 01

Input

Provide a single observed adversary action — a MITRE ATT&CK technique ID, a natural language analyst finding, or a structured TTP from a live case. Optionally add actor profile, target sector, or asset class to sharpen fidelity. No template to fill out. No session to configure.

STAGE 02

Traverse

CHAIN resolves the action to its position in the 18-phase Unified Kill Chain and traverses forward — modeling phase momentum, technique adjacency, and objective convergence across the In, Through, and Out phases. Every continuation path is weighted by the confidence scoring model in real time.

STAGE 03

Predict

A ranked prediction report is generated — High, Medium, and Low confidence next steps, each with an ATT&CK technique tag, the UKC phase it falls in, a confidence score breakdown, and a paired defensive countermeasure. The model shows its work. Every score is traceable to its signals.

STAGE 04

Act

Export the prediction as a structured JSON feed, an ATT&CK Navigator layer, or a formatted report for briefing and ticketing. Pipe directly into SCOUT, TheHive, or your SIEM. The high-confidence predictions become the next items on the containment checklist — not the next hour of analyst triage.