← Unified IT/OT SOC

Cyber knowledge graph / Aster Chemical Works

Before the response.

Interrupt the attack path.
Understand what else stops.

An authored simulation of a specialist resin factory. All assets, intelligence, vulnerabilities and outcomes are synthetic. No live systems or response actions.

ASTER / CONNECTED ENVIRONMENT70 entities · 7 clusters
Preparing graph. All evidence is also available in the list below.
Reduced motion · orbit disabled
Graph legend

Size = authored connection count. Colour = community. Ring = scenario effect or selection. Drag to orbit; scroll to zoom; click to inspect.

IT / OT boundary: gateway → industrial DMZ → manufacturing. Positions show relationships, not network zones.

Network reachabilityAuthentication / accessPrivilegeSoftware applicabilityOperational dependencyRecovery capability
00:00 / 03:00 presentation
Compare a response—see what changes.Hypothetical comparison
Modelled route · BaselineConditionally feasible
Requires exposure, access and permission

The route depends on exposure, affected version, exploit conditions, maintenance access, a usable credential and staging permission. This is not observed compromise. Approval and integrity remain a separate barrier. Potential route, not observed compromise. Confirm the service version, credential state and prior access.

Current Line A productionContinues under local control**Local recipe and independent control assumed. No physical safety verdict.
Next-batch delay+0 minNo delay from this option

COMPARE BEFORE EXECUTION

What changes under each response?

Compare service availability, recovery and delay, then test the evidence that changes the recommendation.

Hypothetical intervention

SERVICE AVAILABILITY

Production dependencies

Recipe distributionAvailable
Production releaseAvailable
Remote supportAvailable

Continues under local-control assumptions. Continuing a batch is not a physical safety verdict.

CALCULATED SCHEDULE EFFECT

0minutes
next-batch start delay

No next-batch delay propagated from this option in the authored topology.

Illustrative timing, not guaranteed recovery or realised financial loss.

RECOVERY & RESIDUAL CONCERNS

What still needs checking

Verify session state, credential revocation and legitimate service behaviour.

Potential route, not observed compromise. Confirm the service version, credential state and prior access.

RECOMMENDATION UNDER CURRENT ASSUMPTIONS

Restrict and verify now; patch through a controlled change

Combine immediate supplier restriction and access verification with controlled patching. Check for prior internal access before reopening.

FEASIBILITY ≠ OBSERVED COMPROMISE

Test every step.

Satisfied / blocked / unknown

KEYBOARD & LIST EXPLORATION

Explore dependencies and evidence.

SYNTHETIC DECISION BRIEF / ASTER

Restrict and verify now; patch through a controlled change

Potential route; no observed compromise

SELECTED OPTION / SIMULATED OUTCOME

Unmodified environment
Modelled routeConditionally feasible
Current productionContinues*
Next-batch delay+0 min

*Continues under local-control assumptions. This does not establish physical safety.

Principal residual concern: Potential route, not observed compromise. Confirm the service version, credential state and prior access.

Compare the three response scopes

Isolate serverRoute interrupted · +45 minRestore and validate production dependencies
Restrict supplier accessRoute interrupted · +0 minNew access restricted; existing sessions need verification
Patch gatewayRoute still feasible · +0 minPlanned change; remediation not yet verified
Evidence, action sequence and assumptions

What intelligence changed

The fictional bulletin ASTER-SIM-GATEWAY-01 identifies an applicable pre-authentication service flaw. It changes our understanding of the route; it does not change the environment or prove exploitation.

Feasibility and barriers

The route to staging is satisfied under the selected option. It requires service exposure, affected version, exploit conditions, maintenance reachability, a usable credential and staging permission. Approval/integrity and direct PLC segmentation remain barriers.

Compared scope and business impact

Unmodified environment. Continues under local-control assumptions. Next-batch delay: 0 operational minutes. Internal production services stay available in this topology. Verify session state, credential revocation and legitimate service behaviour.

Recommended action sequence

  1. Apply a scoped supplier-ingress restriction and revoke affected access.
  2. Terminate or validate existing sessions and check for prior internal access. A new-connection block is not session eviction.
  3. Patch the affected gateway service under approved change and rollback arrangements; verify remediation.
  4. Check manufacturing services and supplier access before reopening. Escalate to targeted isolation and OT continuity review if internal evidence appears.

Evidence that changes the recommendation

Potential route, not observed compromise. Confirm the service version, credential state and prior access.

Reassess if the maintenance route, effective permissions, existing sessions, local recipe state or recovery estimate changes. Internal compromise requires targeted isolation and an OT continuity decision. Confirm process state and independent safety functions; a running batch does not demonstrate physical safety.

All facts and outcomes are synthetic. No exploit-success percentage or financial-loss estimate. This is not an operational instruction or evidence of production effectiveness.