CyberHalluciNet CHN

Agentic platform

Core engine architecture

One deception engine, three deployment usages: inside your network, on the internet for CTI, and an isolated AI-automated cyber range lab. Fail-closed — models never own the wire.

How you run it

Three deployment usages

Same sensor fabric and fail-closed rules. Pick the posture that matches the job — internal defense, open-internet CTI collection, or an isolated cyber range lab.

01 Internal

Inside the network

Decoys beside real assets

Plant forbidden scenarios next to production identity, OT, and AI surfaces. When an adversary — human or AI — touches a decoy, you get graded campaign evidence and a human Propose→Approve→Execute path to Soft/Hard — not another SIEM flood.

  • Enterprise internal planting
  • Detection off until you enable observe
  • Loopback / private bind by default
02 CTI

On the internet

Public decoys → intel

Opt-in internet-facing research decoys collect scanner, bot, and operator activity. Graded evidence exports to SIEM and CTI feeds under operator-controlled admission — not an always-on Internet claim by default.

  • CTI collection posture
  • Fleet / sticky per-source admission
  • SIEM & CTI export sinks
03 Range

Cloud cyber range

AI-automated explosion lab

Spin up an isolated cloud range of decoys for purple-team and malware behaviour runs. Ack-gated disposable guests record every move, block attacker egress, and send behaviour evidence to Ops — no production path, no phone-home entitlement check.

  • Isolated range boundary
  • Ack-gated Live guests
  • Egress denied · guests recycled

Authority matrix

The 4 specialized agent roles

Who may touch what. Wire authority stays in the sensor; AI stays suggestion-only.

01 Wire plane

Sensor

Deterministic wire-level execution. Policy, personas, and synthetic responses: score-independent, fail-closed.

  • Owns attacker-visible bytes
  • No model chooses egress / OS exec
02 Suggestion plane

Content Agent

Bounded, schema-validated AI fills over UDS. Fail-closed when the broker is unavailable.

  • ValidateSlotFill gate
  • Static / template fallback
03 Control plane

Fabric Planner & Scenario Director

Operator-approved deception change management with a signed audit ledger.

  • Propose → Approve → Deploy
  • Never on the attacker wire
04 Analyze plane

Read-Only CTI Investigator

Cited evidence assembly without mid-session risk or auto-containment.

  • Closed read-only tools
  • No wire morph from scores

Attacker path

Attacker Sensor Content Agent
UDS · slot fills

Operator path

Operator Fabric Planner CTI Investigator
read-only · cited

Planes stay separated. Scores never grant wire authority.

Deception fabric

The 3-surface deception fabric

Purpose-built coverage for enterprise identity, cyber-physical plants, and AI agent infrastructure.

Identity & host defense

Identity lures (ITDR-style)

ITDR = Identity Threat Detection and Response. Agentless host and directory-oriented tripwires that end at honeypot surfaces : without a heavyweight endpoint agent as the default path.

  • Registry / SSH config lure packs (GPO / Intune / Jamf-oriented)
  • Monitored AD / Entra-style honey account patterns
  • Self-cleaning TTL lifecycle to cut orphaned debt

Built for · CISO & IT SecOps

Safety interlocks

Closed-loop containment

Human-gated, decoy-touch scoped. No score-driven IPS. No silent cloud mutation.

Pre-flight blast-radius

Simulate exposure before permissive binds or Live/ack-gated paths. Sign-off before the blast radius grows.

Rate-limit circuit breakers

Admission and sticky per-source controls keep CTI / Internet postures from runaway scanner floods.

Immutable exclusion matrices

Hard exclusions keep protected ranges, production IAM, and non-decoy assets off the auto path.

Phase A wired (defaults off) · Phase C Beta (LocalState + BYO webhook)

Agentic attack defense

Deterministic decoy-touch evidence for compromised AI agents. Complements guardrails; does not replace them. Soft/Hard are Beta via LocalState and optional customer webhook, native vendor EDR/IdP SDKs remain GA-train. Canonical wording lives in the docs positioning page: this section must not exceed it.

Install in a lab: Install Phase A · Install Phase C Beta · All agentic tutorials (make agentic-lab-install).

Graded evidence

observed_anomaly → verified_decoy_touch / canary_egress / credential_use. Scores never promote a grade.

Do-no-harm retrieval

Node-local shadow index for canary memory, production top-k stays clean.

Bounded containment (Phase C Beta)

Separate Enforcement Plane; session-first ladder; rung 3 never autonomous. Soft/Hard via LocalState + BYO webhook. Native vendor APIs are GA-train only.

Non-claim: third-party canary benchmarks describe those studies, not CHN performance. Internal use remains free under PSL-1.0; no online entitlement check for enforcement.

What is CyberHalluciNet agentic attack defense?

Deception that fires when a tool-calling agent or operator touches honeytools, shadow canaries, or other bait. Phase A is advisory with defaults off. Phase C Beta Soft/Hard runs on a separate Enforcement Plane via LocalState and optional BYO webhook; native vendor EDR/IdP SDKs remain GA-train only.

Why keep containment off the sensor?

The sensor notify path is evaluate-only. Ops holds the execute token and connector credentials stay on the Enforcement Plane, so a compromised sensor identity cannot Soft/Hard by itself.

How do I install the Phase A and Phase C Beta lab?

Run make agentic-lab-install from a repo checkout, then follow the Install Phase A and Install Phase C Beta tutorials. Confirm /healthz reports maturity beta before Soft/Hard pilots.

Industry verticals

Example deployment profiles

Pre-configured decoy and sensor profiles for specialized environments.

Plant kinematics without operational interruption

  • Optional passive SPAN/TAP profiling → signed Zero-Collision Certificate before active OT (gates default off)
  • Rockwell MicroLogix, Siemens S7 Contained face, water/wastewater ScenarioPlans
  • No real PLC on the sensor — Contained kinematics fiction

Ecosystem

Connects to your security stack

Ops Plugins sit on the private management plane so connector credentials stay with Ops. Labels below match docs/reference/integrations-plugins.md.

SIEM / CTI export

  • Splunk
  • Microsoft Sentinel
  • Elastic
  • Datadog
  • Wazuh
  • CEF
  • LEEF
  • MISP

Notify / SOAR

  • Slack
  • Teams
  • PagerDuty
  • SOAR webhook

Containment (Beta)

  • BYO webhook
  • LocalState

Native CrowdStrike, Defender, SentinelOne, and Palo Alto SDKs remain GA-train.

Deploy

  • Docker Compose
  • Helm (deploy/helm/chn-sensor)

Default research bind stays loopback.

Containment stays fail-closed / dry-run by default. Soft/Hard on LocalState + BYO webhook after observe pilot (Beta). OCSF export is an Ops helper with execute_containment: false.

Next step

Ready to test?

Run the agentic lab on loopback. Detection stays off until you enable observe.