Temporal attack graph
Entities and relationships appear as each deterministic incident event becomes known.
VANTREXIS Labs concept
Turn fragmented security signals into a coherent attack story. SENTINEL connects identities, services, infrastructure, and evidence into a temporal incident model, so security teams can replay a synthetic attack, inspect how access moved across the environment, and test containment actions against the evolving attack path.
What the concept explores
Security incidents generate large volumes of disconnected signals, but responders need to understand what happened, what is affected, how access progressed, and where containment should begin. SENTINEL connects identities, infrastructure, evidence, and time into one evolving model.
Entities and relationships appear as each deterministic incident event becomes known.
Every replay step connects the current event to synthetic signals, actors, targets, and investigation notes.
A containment playbook requires human review before sequential mock actions can block the active path.
System model
The demo runs entirely in the browser with typed, deterministic mock data. Each state transition is derived from relationships in the product model.
Start with an anomaly
Replay correlated events
Inspect affected entities
Review containment plan
Execute and verify response
Engineering challenges
The concept focuses on relationship modelling, consequential interaction, and operational clarity—not fabricated business outcomes.
Engineering focus
SENTINEL explores the systems behind temporal incident investigation: connecting identities, access, credentials, workloads and data into a correlated attack model that can be replayed, inspected and contained without losing the context behind each stage.
Represent an incident as a sequence of stateful security events so identity activity, privilege changes, credential access, workloads and data movement remain connected to when they occurred.
Event sequence · Incident state · Time context
Combine fragmented observations into one investigation context so individual anomalies can become meaningful when connected across identities, services and infrastructure.
Correlated signals · Shared context · Incident assembly
Model how access moves through identity, privilege, credentials, workloads and data while preserving both the active path and the supporting relationships discovered around it.
Identity · Access · Credentials · Workloads · Data
Replay the same incident progression through a controlled state model so graph state, timeline position, selected entity and investigation context remain synchronized.
Replay state · Timeline · Investigation context
Keep the selected entity, current event, evidence and incident state aligned so investigators can move through the attack story without losing why a component matters.
Entity context · Evidence · Current event
Translate investigation state into explicit response actions while keeping containment reviewable, staged and distinguishable from the active attack path.
Response playbooks · Containment state · Human control
Incident model
Interactive product concept
No account or external service is required. The demo is static-hostable and resets to a coherent first-run state.
Replay the incidentHave a similar challenge?