Last 24 hours · Aug 06, 2026 16:54 – Aug 07, 2026 16:54 UTCDemonstration Mode (synthetic data)Generated: 2026-08-07 16:54:46 UTC
OCCAM Detection Overview
OCCAM has two stages. The classifier scores each 15-minute asset window into one of 13 ATT&CK tactics (Benign + 12 attack stages). The predictor runs a Hidden Markov Model over the resulting token sequence, predicts Benign by default, and treats prediction failure as the pre-intrusion signal.
Total Detections
4,821
Pre-Intrusion Alerts
23
Suppressed (FP)
3,947
Assets Observed
847
Avg Surprisal (bits)
1.42
Max Surprisal (bits)
8.73
Predictor Status
Self-commissioning state machine: Accumulating → Activating → Active. The predictor self-deactivates to Degraded if its confirmation rate drops below threshold.
High-surprisal observations in progressive attack sequences. Each row is an assessed-probable intrusion in progress — acted on before the attacker achieves objective.
−Pre-Intrusion Alerts8 rows
Window
Source
Segment
Observed
Surprisal (bits)
Anomaly
P(Benign)
Predicted Next
Viterbi Path
2026-08-07T14:54:46
10.0.12.45
datacenter
CommandAndControl
8.73
0.92
0.080
Benign
B→R→S→L
2026-08-07T12:54:46
10.0.3.118
corporate
LateralMovement
7.21
0.87
0.130
Benign
B→R→L
2026-08-07T10:54:46
10.0.12.201
datacenter
DataExfiltration
6.84
0.84
0.160
Benign
B→S→C→E
2026-08-07T08:54:46
172.16.0.89
dmz
CommandAndControl
6.42
0.81
0.190
Reconnaissance
B→R→L
2026-08-07T06:54:46
10.0.8.77
corporate
Persistence
5.92
0.78
0.220
Benign
B→S→L
2026-08-07T05:54:46
10.0.12.45
datacenter
CommandAndControl
5.87
0.76
0.240
Benign
B→R→S→L
2026-08-07T03:54:46
10.0.5.212
corporate
PrivilegeEscalation
5.47
0.73
0.270
Benign
B→S→I
2026-08-07T01:54:46
10.0.12.45
datacenter
CommandAndControl
5.31
0.71
0.290
Benign
B→R→S→L
Viterbi State Paths
The most-likely hidden-state paths decoded from observed token sequences. This is the explainable-AI output that satisfies DoD XAI requirements — every prediction can be traced back to the specific ATT&CK tactic progression that drove it.
Decoded Path
Occurrences
Avg Surprisal
Elevated
B→R→S→L→C→E
12
6.84
8
B→R→S→L
8
5.92
5
B→S→C→E
6
6.21
4
B→S→L
4
4.87
2
B→R→S→I
3
5.12
2
B→R→I
2
4.42
2
Detection Timeline
Detections by ATT&CK Tactic
Tactic
Detections
Avg Surprisal
Avg Anomaly Score
Elevated
Benign
3,284
0.38
0.02
0
Reconnaissance
487
2.84
0.31
3
LateralMovement
312
3.17
0.42
5
CommandAndControl
198
4.92
0.67
8
DataExfiltration
147
5.31
0.71
4
PrivilegeEscalation
89
3.84
0.48
2
Persistence
67
4.12
0.53
1
InitialAccess
42
5.87
0.78
0
Collection
38
3.41
0.39
0
Impact
157
2.18
0.22
0
Dispositions Breakdown
Each token observation is classified into one of four dispositions based on the surprisal score and the surrounding sequence context.
Disposition
Count
%
suppress
3,947
81.9
investigate
412
8.5
present
284
5.9
downgrade_infrastructure_change
155
3.2
elevate_to_preintrusion
23
0.5
Detections by Segment
Segment
Detections
Assets
Elevated
corporate
2,847
512
8
datacenter
1,284
187
11
dmz
421
34
3
iot
189
78
1
guest
80
36
0
Most Anomalous Assets
−Most Anomalous Assets8 rows
Source IP
Segment
Detections
Elevated
Max Surprisal
Avg Anomaly
Last Tactic
10.0.12.45
datacenter
87
4
8.73
0.82
CommandAndControl
10.0.3.118
corporate
64
3
7.21
0.71
LateralMovement
10.0.12.201
datacenter
52
2
6.84
0.68
DataExfiltration
172.16.0.89
dmz
41
2
5.92
0.59
Reconnaissance
10.0.8.77
corporate
38
1
5.47
0.54
Persistence
10.0.5.212
corporate
31
1
4.83
0.47
PrivilegeEscalation
10.0.12.15
datacenter
28
0
4.21
0.41
Collection
192.168.1.44
iot
24
1
3.97
0.38
CommandAndControl
False Positive Suppression
Recurring patterns the predictor has classified as legitimate. If a suppressed pattern deviates from expected resolution, it escalates to a high-priority alert.