VANTREXIS Labs concept

SENTINEL

Turn fragmented security signals into a coherent attack story. SENTINEL connects identities, services, infrastructure, and evidence into a temporal incident model, so security teams can replay a synthetic attack, inspect how access moved across the environment, and test containment actions against the evolving attack path.

  • Cybersecurity
  • Graph Systems
  • Incident Response
  • Automation
Replay the incident Interactive concept · Synthetic data
Type
VANTREXIS Labs concept
Domain
Cybersecurity Incident Command
Format
Interactive system model
Interaction
Incident replay & containment

What the concept explores

Security events need to become a coherent investigation story.

Security incidents generate large volumes of disconnected signals, but responders need to understand what happened, what is affected, how access progressed, and where containment should begin. SENTINEL connects identities, infrastructure, evidence, and time into one evolving model.

Temporal attack graph

Entities and relationships appear as each deterministic incident event becomes known.

Evidence context

Every replay step connects the current event to synthetic signals, actors, targets, and investigation notes.

Controlled response

A containment playbook requires human review before sequential mock actions can block the active path.

System model

The interaction follows the system, not a generic dashboard pattern.

The demo runs entirely in the browser with typed, deterministic mock data. Each state transition is derived from relationships in the product model.

  1. 01

    Start with an anomaly

  2. 02

    Replay correlated events

  3. 03

    Inspect affected entities

  4. 04

    Review containment plan

  5. 05

    Execute and verify response

Engineering challenges

Complexity placed where it improves understanding.

The concept focuses on relationship modelling, consequential interaction, and operational clarity—not fabricated business outcomes.

  • Event-derived graph state at any selected time
  • Replay, pause, speed, reset, and timeline scrubbing
  • Evidence correlation without imitating real logs
  • Sequential containment with explicit human confirmation
  • Accessible structured alternatives to the graph
  • Timer cleanup and reduced-motion resilience

Engineering focus

Engineering coherent incident stories from fragmented security signals.

SENTINEL explores the systems behind temporal incident investigation: connecting identities, access, credentials, workloads and data into a correlated attack model that can be replayed, inspected and contained without losing the context behind each stage.

  1. 01

    Temporal incident modeling

    Represent an incident as a sequence of stateful security events so identity activity, privilege changes, credential access, workloads and data movement remain connected to when they occurred.

    Event sequence · Incident state · Time context

  2. 02

    Signal correlation & incident assembly

    Combine fragmented observations into one investigation context so individual anomalies can become meaningful when connected across identities, services and infrastructure.

    Correlated signals · Shared context · Incident assembly

  3. 03

    Attack-path modeling

    Model how access moves through identity, privilege, credentials, workloads and data while preserving both the active path and the supporting relationships discovered around it.

    Identity · Access · Credentials · Workloads · Data

  4. 04

    Deterministic incident replay

    Replay the same incident progression through a controlled state model so graph state, timeline position, selected entity and investigation context remain synchronized.

    Replay state · Timeline · Investigation context

  5. 05

    Contextual investigation

    Keep the selected entity, current event, evidence and incident state aligned so investigators can move through the attack story without losing why a component matters.

    Entity context · Evidence · Current event

  6. 06

    Human-controlled containment

    Translate investigation state into explicit response actions while keeping containment reviewable, staged and distinguishable from the active attack path.

    Response playbooks · Containment state · Human control

Incident model

From isolated signals to controlled containment.

  1. 01

    Security signals

    • Identity activity
    • Access events
    • Resource activity
  2. 02

    Incident correlation

    • Shared entities
    • Temporal relationships
    • Signal context
  3. 03

    Attack path

    • Privilege movement
    • Credential access
    • Workload progression
  4. 04

    Investigation context

    • Selected entity
    • Evidence
    • Incident state
  5. 05

    Containment response

    • Response actions
    • Neutralized path
    • Forensic context

Interactive product concept

Replay a 14-minute synthetic incident.

No account or external service is required. The demo is static-hostable and resets to a coherent first-run state.

Replay the incident

Have a similar challenge?

Have a complex product idea worth making tangible?