Causality Matrix
Visualize which observations support the incident and how they are connected.
The Causality Engine connects qualifying security observations into evidence-backed timelines while keeping confidence, severity, impact and evidence grade separate.
Visualize which observations support the incident and how they are connected.
Review the sequence chronologically instead of reading disconnected log rows.
Generate stable local fingerprints for recurring behavior sequences.
Nexus explains why events were linked, which identifiers support the connection and which limitations reduced certainty. Timing alone does not become proof.
The feature combines deterministic correlation rules with explicit evidence and limitations.
Evaluate event type, source, identity, endpoint, timing and persistence context to form qualifying chains.
Map the supporting observations and the strength of each relationship around the protected site.
Create a stable local fingerprint for the event sequence so recurring patterns can be recognized.
Open the exact activity records behind a timeline and understand why Nexus included them.
The engine moves from eligible observations to an inspectable timeline without rewriting the source evidence.
Eligible security events remain in local activity history.
Source, identity, endpoint, timing and event-class relationships are evaluated.
A qualifying chain receives confidence, severity, impact and evidence grading.
The administrator opens the timeline, Matrix and supporting events to confirm or dismiss it.
The current engine uses deterministic local correlation and explicit evidence rules. Marketing does not need to label it as AI to explain its value.
No. A timeline may describe reconnaissance, pursuit or a blocked campaign with no measurable impact. Impact is reported separately.
It is a stable local fingerprint for a qualifying behavior sequence, helping recognize recurring incident patterns without replacing the underlying evidence.
New licensed correlation processing stops while existing local timelines, settings and evidence are preserved for later review or reactivation.
Threat Continuum runs locally in Observation Mode with an active Nexus PRO licence.