A PREDICTIVE ADVERSARY EMULATION CHAINING SIMULATOR

CHAIN is purpose-driven to do one job. It takes a confirmed adversary action — a single observed TTP, a log signal, an analyst finding — and traverses the Unified Kill Chain forward from that point, predicting the most probable next moves with MITRE ATT&CK alignment and ranked confidence scoring, so defenders stop waiting and start preempting.
FORM FACTOR
Web-based simulation interface. No install, no client software. Feed CHAIN an observed action and receive a structured prediction report in seconds — accessible to analysts, threat hunters, and IR leadership from any modern browser.
TRAVERSAL MODEL
CHAIN maps the input action to its position within the 18-phase Unified Kill Chain and projects forward across In, Through, and Out phases — modeling adversary momentum, objective convergence, and likely branching paths from that point in the intrusion lifecycle.
INPUTS
A single observed adversary action described in natural language, a MITRE ATT&CK technique ID, or a structured TTP from an active investigation. Optional context — threat actor profile, targeted asset class, sector — sharpens prediction fidelity.
OUTPUTS
A ranked list of predicted next adversary steps with associated ATT&CK technique mappings, confidence tiers (High / Medium / Low), and recommended defensive countermeasures for each projected move. Exportable for briefing, ticketing, or playbook activation.
INTEGRATIONS
Native output compatible with SCOUT, TheHive, and MITRE ATT&CK Navigator. Prediction exports available in structured JSON for SIEM ingestion and case management enrichment.


Every CHAIN projection is built on three components working in sequence. The observed action anchors the analysis to reality. The traversal engine maps the adversary's probable trajectory across the kill chain. The prediction output hands defenders a prioritized list of what to block before it happens.

PIL. 01
CHAIN starts with a single confirmed signal from the field — a MITRE ATT&CK technique, a natural language description of analyst findings, or a structured TTP pulled from an active investigation. No hypotheticals. The input anchors the entire projection to something real that already happened.

PIL. 02
CHAIN locates the observed action within the 18-phase Unified Kill Chain and projects forward — modeling adversary momentum across the In, Through, and Out phases. The AI evaluates objective convergence, historical actor behavior, and technique adjacency to surface the most probable continuation paths, not just adjacent techniques.

PIL. 03
Every projection is a ranked report — High, Medium, and Low confidence next steps, each tagged with the ATT&CK technique, the UKC phase it falls in, and a recommended defensive action. Defenders don’t get a list of possibilities. They get a prioritized ops order for what to cover first.
The traversal engine resolves the observed action to its position in the Unified Kill Chain, then models forward momentum across all remaining phases — weighting continuation paths by technique adjacency, objective proximity, and actor behavioral patterns. Each phase transition produces a ranked prediction with ATT&CK alignment and a paired defensive action.
Reconnaissance
Phase 1 of 18 → adversary profiling & target selection
Weaponization & Delivery
Phases 2–3 → payload staging & initial vector
Exploitation & Persistence
Phases 4–5 → foothold establishment & survival
Defense Evasion & C2
Phases 6–9 → dwell extension & remote control
Pivoting & Discovery
Phases 10–12 → lateral movement & asset enumeration
Collection & Exfiltration
Phases 13–15 → data staging & exfil channel selection
Impact & Objectives
Phases 16–18 → mission execution & final effect
The confidence score isn't a black box. Every ranked prediction CHAIN produces is the result of documented signals — technique adjacency, phase proximity, actor behavioral alignment, asset exposure, and objective convergence — each contributing a weighted value to the final High / Medium / Low tier. Analysts can audit exactly why a prediction ranked where it did.
| // SIGNAL | DESCRIPTION | WEIGHT |
|---|---|---|
| 01 PER-STEP SCORE: What you see on each tree node | ||
| LLM likelihood | Claude's predicted probability that this specific action is the actor's next move, given the full path so far and any environment context. | 65% |
| Deterministic ATT&CK Prior | A rule-based score, independent of the LLM: kill-chain position blended with known technique-to-technique pivot strength. | 35% |
| 02 DETERMINISTIC PRIOR, EXPANDED: What makes up the 35% | ||
| Kill-Chain Position | How far the candidate's Unified Kill Chain tactic sits past the furthest progressed tactic observed so far (the "Frontier") | Produces the starting value, 5–98, before any bonus is applied. |
| Known ATT&CK Chain | Applies when the current technique has a curated, documented pivot to the candidate(e.g. Spearphishing Attachment → User Execution), scaled by that pivot's authored strength. | +0–25 bonus and a 0–95 score floor, both scaled by edge strength (0–1). |
| 03 FULL-CHAIN CONFIDENCE — REPORT ONLY | ||
| Computed Path Confidence | Likelihood-weighted mean of every predicted step's blended score, weighted by 0.9 so near-term steps count more than the peculative tail. | 60% |
| Model Self-Assessed Confidence | Claude's own 0-100 confidence in the whole analysis, explicitly instructed to calibrate down for long, speculative chains or thin evidence. | 40% |
Most threat analysis ends with a long list of possibilities and a team that doesn't know where to start. CHAIN collapses the cycle into a single workflow — an observed action goes in, a ranked and mapped prediction comes out, and every output is wired for immediate defensive action or case management enrichment.
Provide a single observed adversary action — a MITRE ATT&CK technique ID, a natural language analyst finding, or a structured TTP from a live case. Optionally add actor profile, target sector, or asset class to sharpen fidelity. No template to fill out. No session to configure.
CHAIN resolves the action to its position in the 18-phase Unified Kill Chain and traverses forward — modeling phase momentum, technique adjacency, and objective convergence across the In, Through, and Out phases. Every continuation path is weighted by the confidence scoring model in real time.
A ranked prediction report is generated — High, Medium, and Low confidence next steps, each with an ATT&CK technique tag, the UKC phase it falls in, a confidence score breakdown, and a paired defensive countermeasure. The model shows its work. Every score is traceable to its signals.
Export the prediction as a structured JSON feed, an ATT&CK Navigator layer, or a formatted report for briefing and ticketing. Pipe directly into SCOUT, TheHive, or your SIEM. The high-confidence predictions become the next items on the containment checklist — not the next hour of analyst triage.