ARESCISO Decision Cockpit
Simulation mode

Scenario replay · no production controls connected

GPT-5.6 packets readyEvidence as of 2026-07-18 08:50:00 UTC · 8 cited records · Decision record validatedLocal session
01 · DECISION CONTEXT
Business risk · 88.90Owner · Incident Commander2026-07-18 08:50:00 UTC

Finance OAuth compromise

A finance employee approved a malicious OAuth app that accessed mail and payment files; the current endpoint snapshot contains no malware or persistence detection.

Approval decisionApprove the recommended containment now, or accept continued exposure while the team gathers more evidence?
  • The OAuth app holds delegated mail, file, and offline permissions.C-002 · E-002
  • A payment-themed external forwarding rule exists in the mailbox.C-004 · E-004
  • The active session accessed the Finance/Payments library.C-005 · E-003 · E-005
Governed decision trace

8 cited records 3 classified exposure paths 4 ranked responses approval-ready receipt

02 · BUSINESS EXPOSURE

Business assets within modeled reach

Evidence-linked business exposure—not a confirmed loss forecast.

Exposure paths
3
1 evidence-derived · 2 hypothetical impact paths
Risk posture
88.90
Critical
Evidence quality
93%
Very High evidence
Business assets in scopeHypothesized impact — Payment instruction manipulationObserved access — Finance/Payments libraryHypothesized impact — Same-day payroll approval
Evidence-supported relationshipHypothesized impactModeled interruption
3modeled paths
Attack-path topology: External attacker → OAuth consent phishing → Malicious delegated OAuth grant → Active Microsoft 365 session → Finance mailbox → Payment instruction manipulation

Evidence-linked exposure model for Finance OAuth compromise. 10 nodes, 7 directed relationships, and 3 enumerated paths. P-001, Hypothesis path, open. The current endpoint snapshot has no malware detection; this bounded negative finding is shown as non-topological evidence with no causal edge.

Modeled attack surfaceG-006: AccessesAccessesG-007: Could DisruptCould DisruptG-001: InitiatesInitiatesG-002: CreatesCreatesG-003: AuthorizesAuthorizesG-004: AccessesAccessesG-005: EnablesEnablesFinance workstation · Endpoint · N-ENDPOINTEndpointFinanceworkstationExternal attacker · Threat Actor · N-THREATThreat ActorExternalattackerFinance employee · Identity · N-USERIdentityFinance employeeOAuth consent phishing · Attack Technique · N-PHISHAttack TechniqueOAuth consentphishingMalicious delegated OAuth grant · Cloud Grant · N-GRANTCloud GrantMaliciousdelegated OAuthActive Microsoft 365 session · Cloud Session · N-SESSIONCloud SessionActive Microsoft365 sessionFinance mailbox · Saas Asset · N-MAILBOXSaas AssetFinance mailboxSame-day payroll approval · Business Process · N-PAYROLLBusiness ProcessSame-day payrollapprovalFinance/Payments library · Data Asset · N-SHAREPOINTData AssetFinance/PaymentslibraryPayment instruction manipulation · Business Impact · N-FRAUDBusiness ImpactPaymentinstruction

External attacker → OAuth consent phishing → Malicious delegated OAuth grant → Active Microsoft 365 session → Finance mailbox → Payment instruction manipulationHypothesis path · modeled reachable

EXECUTIVE DECISION OVERVIEW

Finance mail and payment files is within modeled reach

A finance employee approved a malicious OAuth app that accessed mail and payment files; the current endpoint snapshot contains no malware or persistence detection.

Risk index88.90Critical
Modeled reachable paths33 require a decision
Decision confidence92.99Very High evidence confidence
Recommended action96.55Revoke OAuth sessions and malicious grant
Approval statePendingincident-commander
Decision requiredcritical risk; identity-containment recommended

Revoke OAuth sessions and malicious grant ranks first at 96.55/100 because it interrupts 3/3 enumerated paths while accounting for disruption, urgency, reversibility, and evidence strength.

Recommended responseRisk 88.90
THE DECISION

Revoke OAuth sessions and malicious grant

Revoke OAuth sessions and malicious grant ranks first at 96.55/100 because it interrupts 3/3 enumerated paths while accounting for disruption, urgency, reversibility, and evidence strength.

Decision score96.55Governed policy
Modeled path coverage0/3100% policy input
Continuity score92%Inverse-disruption input
Inspect causal evidence
RESPONSE PREVIEW · connected products remain unchanged
ME
ACTIVE INCIDENT

Finance OAuth compromise

A finance employee approved a malicious OAuth app that accessed mail and payment files; the current endpoint snapshot contains no malware or persistence detection.

Microsoft Entra IDMicrosoft Exchange OnlineMicrosoft SharePointMicrosoft Defender for EndpointServiceNow CMDB
1Ingest8 records2Correlate3 paths3Decide4 options4Governhuman gate5Verifyafter action
02 · CORRELATE · LAYER 6

Exact attack-path explorer

10 nodes7 edges3 paths

This SVG is drawn from the receipt's real from/to topology. Select a path or preview a response to see exactly which routes close and which remain.

Topology viewExternal attacker → OAuth consent phishing → Malicious delegated OAuth grant → Active Microsoft 365 session → Finance mailbox → Payment instruction manipulation
Base path+ Malware / endpoint

Attack path topology for Finance OAuth compromise. 10 nodes, 7 directed relationships, and 3 enumerated paths. P-001, Hypothesis path, open. The current endpoint snapshot has no malware detection; this bounded negative finding is shown as non-topological evidence with no causal edge.

Base attack surfaceEndpoint / malware causal laneNo endpoint malware detected in current snapshotThis bounded negative finding is non-topological evidence and has no connected graph edge.EVIDENCE ONLY · NOT TOPOLOGYNo endpoint malware detectedCurrent snapshot · not proof of clean stateG-006: AccessesAccessesG-007: Could DisruptCould DisruptG-001: InitiatesInitiatesG-002: CreatesCreatesG-003: AuthorizesAuthorizesG-004: AccessesAccessesG-005: EnablesEnablesFinance workstation · Endpoint · N-ENDPOINTEndpointFinance workstationN-ENDPOINTExternal attacker · Threat Actor · N-THREATThreat ActorExternal attackerN-THREATFinance employee · Identity · N-USERIdentityFinance employeeN-USEROAuth consent phishing · Attack Technique · N-PHISHAttack TechniqueOAuth consent phishingN-PHISHMalicious delegated OAuth grant · Cloud Grant · N-GRANTCloud GrantMalicious delegatedOAuth grantN-GRANTActive Microsoft 365 session · Cloud Session · N-SESSIONCloud SessionActive Microsoft 365sessionN-SESSIONFinance mailbox · Saas Asset · N-MAILBOXSaas AssetFinance mailboxN-MAILBOXSame-day payroll approval · Business Process · N-PAYROLLBusiness ProcessSame-day payrollapprovalN-PAYROLLFinance/Payments library · Data Asset · N-SHAREPOINTData AssetFinance/PaymentslibraryN-SHAREPOINTPayment instruction manipulation · Business Impact · N-FRAUDBusiness ImpactPayment instructionmanipulationN-FRAUD
P-001Hypothesis pathResidual open
External attacker → OAuth consent phishing → Malicious delegated OAuth grant → Active Microsoft 365 session → Finance mailbox → Payment instruction manipulation
External attackerN-THREATOAuth consent phishingN-PHISHMalicious delegated OAuth grantN-GRANTActive Microsoft 365 sessionN-SESSIONFinance mailboxN-MAILBOXPayment instruction manipulationN-FRAUD
5 evidence records · 5 causal edges
SPECIALIST COUNCIL

Eight bounded perspectives, one governed score

Review packets ready8 support · 0 dissent

Identity, cloud, endpoint, network, business, and governance roles assess the same bounded evidence. Computed facts and policy scores remain locked.

AEnumerate attacker goals, pivots, and choke pointsSupporting assessment

The malicious grant is the common choke point

4 evidence IDsSupports A-IDENTITY-CONTAINSource linked
Decision synthesisThe published deterministic action score is authoritative if the vote and score differ.

No material dissent in the specialist review.

03 · DECIDE · LAYER 9

Response ranking

40 coverage · 25 continuity · 15 urgency · 10 reversible · 10 evidence

Preview any option to project path closure in the receipt and graph. Flip the endpoint fact above to watch the ranking recompute.

RankAction / governed scoreCoverageContinuityGate
02
Isolate endpoint and revoke cloud accessCoordinate endpoint isolation with session, OAuth grant, and inbox-rule revocation.
79.81
100%42%
03
Continue enhanced monitoringPreserve access and increase identity, mail, cloud-data, and endpoint monitoring.
49.14
0%98%
04
Isolate the finance workstationSimulate network isolation of the endpoint while preserving EDR management traffic.
34.11
0%58%
DECISION SENSITIVITY

New evidence changes the action—not the policy.

ARES recomputes the attack graph and response ranking when endpoint evidence confirms malware.

No endpoint malware detectedRevoke OAuth sessions and malicious grant3 modeled paths · score 96.55
Endpoint compromisedIsolate endpoint and revoke cloud access7 paths · score 81.98
LAYER 11

One receipt, three operating lenses

CISO BRIEF

critical risk; identity-containment recommended

A finance employee approved a malicious OAuth app that accessed mail and payment files; the current endpoint snapshot contains no malware or persistence detection.

Risk88.9/100
Action score96.55/100
  1. 01

    Authorize revoke oauth sessions and malicious grant.Now · 4 cited records

04–05 · GOVERN & VERIFY

Human approval required

Pending
Modeled paths before3Canonical graph snapshot
Projected after top action0Not applied yet
Approval RequestedARES deterministic engine · 2026-07-18 08:50:00 UTC
DECISION TRACE

Machine-verifiable receipt

01

IntentDecision question and constraints classified.

02

PlanEvidence-first execution plan produced.

03

Evidence8 replay evidence items normalized.

04

ContextFusion10 cited claims fused without silent fact promotion.

05

Ontology10 typed entities and 7 relationships created.

06

DecisionGraph3 source-to-target paths enumerated.

07

Agents8 distinct specialist packets prepared for optional GPT-5.6 host narrative.

08

DebateDebate reducer selected A-IDENTITY-CONTAIN.

09

Ranking4 actions ranked with the published deterministic formula.

10

ReceiptEvidence receipt RECEIPT-00afcffb issued.

11

ProjectionsSOC, CISO, and Executive views projected from one decision bundle.

12

ExecutionMemoryApproval is pending; a replay memory record is prepared.

Receipt
RECEIPT-00afcffb
Policy computation
Deterministic
External actions
None
Specialist review
Not attached
CASE HISTORY

Record prepared

Session only

ARES has prepared the case record and will mark it saved only after decision memory confirms the write.

Prior records cited
0
Selected action
Pending
Availability
Available in this session
PLATFORM CONTROLS

AI judgment where it helps. Determinism where trust demands it.

The reasoning layer supplies cited specialist analysis. ARES owns evidence normalization, topology, policy scores, governed state transitions, validation, and export.

Reasoning layerSpecialist analysisInterpret · challenge · explain
Policy layerARES engineGraph · score · validate
Operator layerInvestigation receiptInspect · approve · export
✓ Evidence-linked claims✓ No live product credentials✓ Human approval required✓ Every transition receipted