Finance OAuth compromise
A finance employee approved a malicious OAuth app that accessed mail and payment files; the current endpoint snapshot contains no malware or persistence detection.
- The OAuth app holds delegated mail, file, and offline permissions.C-002 · E-002
- A payment-themed external forwarding rule exists in the mailbox.C-004 · E-004
- The active session accessed the Finance/Payments library.C-005 · E-003 · E-005
8 cited records → 3 classified exposure paths → 4 ranked responses → approval-ready receipt
Business assets within modeled reach
Evidence-linked business exposure—not a confirmed loss forecast.
- Exposure paths
- 3 1 evidence-derived · 2 hypothetical impact paths
- Risk posture
- 88.90 Critical
- Evidence quality
- 93% Very High evidence
Evidence-linked exposure model for Finance OAuth compromise. 10 nodes, 7 directed relationships, and 3 enumerated paths. P-001, Hypothesis path, open. The current endpoint snapshot has no malware detection; this bounded negative finding is shown as non-topological evidence with no causal edge.
External attacker → OAuth consent phishing → Malicious delegated OAuth grant → Active Microsoft 365 session → Finance mailbox → Payment instruction manipulationHypothesis path · modeled reachable
Finance mail and payment files is within modeled reach
A finance employee approved a malicious OAuth app that accessed mail and payment files; the current endpoint snapshot contains no malware or persistence detection.
Revoke OAuth sessions and malicious grant ranks first at 96.55/100 because it interrupts 3/3 enumerated paths while accounting for disruption, urgency, reversibility, and evidence strength.
Revoke OAuth sessions and malicious grant
Revoke OAuth sessions and malicious grant ranks first at 96.55/100 because it interrupts 3/3 enumerated paths while accounting for disruption, urgency, reversibility, and evidence strength.
Exact attack-path explorer
This SVG is drawn from the receipt's real from/to topology. Select a path or preview a response to see exactly which routes close and which remain.
Attack path topology for Finance OAuth compromise. 10 nodes, 7 directed relationships, and 3 enumerated paths. P-001, Hypothesis path, open. The current endpoint snapshot has no malware detection; this bounded negative finding is shown as non-topological evidence with no causal edge.
Eight bounded perspectives, one governed score
Identity, cloud, endpoint, network, business, and governance roles assess the same bounded evidence. Computed facts and policy scores remain locked.
The malicious grant is the common choke point
No material dissent in the specialist review.
Response ranking
Preview any option to project path closure in the receipt and graph. Flip the endpoint fact above to watch the ranking recompute.
New evidence changes the action—not the policy.
ARES recomputes the attack graph and response ranking when endpoint evidence confirms malware.
One receipt, three operating lenses
critical risk; identity-containment recommended
A finance employee approved a malicious OAuth app that accessed mail and payment files; the current endpoint snapshot contains no malware or persistence detection.
- 01
Authorize revoke oauth sessions and malicious grant.Now · 4 cited records
Human approval required
Machine-verifiable receipt
IntentDecision question and constraints classified.
✓PlanEvidence-first execution plan produced.
✓Evidence8 replay evidence items normalized.
✓ContextFusion10 cited claims fused without silent fact promotion.
✓Ontology10 typed entities and 7 relationships created.
✓DecisionGraph3 source-to-target paths enumerated.
✓Agents8 distinct specialist packets prepared for optional GPT-5.6 host narrative.
✓DebateDebate reducer selected A-IDENTITY-CONTAIN.
✓Ranking4 actions ranked with the published deterministic formula.
✓ReceiptEvidence receipt RECEIPT-00afcffb issued.
✓ProjectionsSOC, CISO, and Executive views projected from one decision bundle.
✓ExecutionMemoryApproval is pending; a replay memory record is prepared.
✓- Receipt
- RECEIPT-00afcffb
- Policy computation
- Deterministic
- External actions
- None
- Specialist review
- Not attached
Record prepared
Session onlyARES has prepared the case record and will mark it saved only after decision memory confirms the write.
- Prior records cited
- 0
- Selected action
- Pending
- Availability
- Available in this session
AI judgment where it helps. Determinism where trust demands it.
The reasoning layer supplies cited specialist analysis. ARES owns evidence normalization, topology, policy scores, governed state transitions, validation, and export.