Causal threat correlation

From scattered events to an explainable incident.

The Causality Engine connects qualifying security observations into evidence-backed timelines while keeping confidence, severity, impact and evidence grade separate.

Causality EngineCausality MatrixThreat GenomeTimeline replay
THREAT CONTINUUMOBSERVING
ReconnaissanceEndpoint probes linked
PursuitIdentity pressure follows
ContainmentExploit attempt blocked

Causality Matrix

Visualize which observations support the incident and how they are connected.

Timeline Replay

Review the sequence chronologically instead of reading disconnected log rows.

Threat Genome

Generate stable local fingerprints for recurring behavior sequences.

Observation Mode

Correlation without pretending omniscience.

Nexus explains why events were linked, which identifiers support the connection and which limitations reduced certainty. Timing alone does not become proof.

  • Separate correlation confidence, threat severity and observed impact
  • Evidence grades for direct, source-based and temporal links
  • Incident lifecycle for review, confirmation, containment and resolution
  • Retained supporting events and human-readable rationale
Capability map

The anatomy of an explainable incident.

The feature combines deterministic correlation rules with explicit evidence and limitations.

Causality Engine

Evaluate event type, source, identity, endpoint, timing and persistence context to form qualifying chains.

  • Deterministic rules
  • Repeated-source tolerance
  • Bounded decay windows

Causality Matrix

Map the supporting observations and the strength of each relationship around the protected site.

  • Evidence nodes
  • Connection reasons
  • Bounded visual complexity

Threat Genome

Create a stable local fingerprint for the event sequence so recurring patterns can be recognized.

  • Behavior sequence identity
  • No personal-content fingerprinting
  • Reusable investigation context

Event Inspector

Open the exact activity records behind a timeline and understand why Nexus included them.

  • Full retained chain
  • Readable rationale
  • Impact and limitation notes
Operational flow

A chain is built only when the evidence supports it.

The engine moves from eligible observations to an inspectable timeline without rewriting the source evidence.

01

Collect

Eligible security events remain in local activity history.

02

Compare

Source, identity, endpoint, timing and event-class relationships are evaluated.

03

Connect

A qualifying chain receives confidence, severity, impact and evidence grading.

04

Review

The administrator opens the timeline, Matrix and supporting events to confirm or dismiss it.

What Nexus does

Connect evidence and expose the reasoning.

  • Keep confidence distinct from severity
  • Report when no impact was detected
  • Retain full supporting chains
  • Allow timelines to be reviewed and dismissed
What Nexus avoids

Manufacture an attack story.

  • Use timing alone as certainty
  • Call every suspicious event a compromise
  • Hide weak links from the administrator
  • Delete source evidence after correlation
Feature questions

What buyers usually want to know.

Is Threat Continuum an AI system?

The current engine uses deterministic local correlation and explicit evidence rules. Marketing does not need to label it as AI to explain its value.

Does a completed timeline mean the site was compromised?

No. A timeline may describe reconnaissance, pursuit or a blocked campaign with no measurable impact. Impact is reported separately.

What is a Threat Genome?

It is a stable local fingerprint for a qualifying behavior sequence, helping recognize recurring incident patterns without replacing the underlying evidence.

What happens if the licence becomes inactive?

New licensed correlation processing stops while existing local timelines, settings and evidence are preserved for later review or reactivation.

Lumiverse Nexus PRO

Stop reviewing security events as isolated dots.

Threat Continuum runs locally in Observation Mode with an active Nexus PRO licence.