An AI workload accessing a file may be normal. A process making a network connection may be normal. A Kubernetes API call may be normal. A shell invocation may be normal.
But:
...is a different story.
The security signal isn't necessarily any individual event.
The sequence is the signal.
The Problem with Isolated Events
Modern infrastructure generates enormous amounts of legitimate activity. Processes execute. Files open. Sockets connect. APIs are called. Containers spawn. Credentials are accessed. Kubernetes controllers modify resources.
Any one of these events may be completely normal. The challenge is determining when individually legitimate operations form an abnormal progression.
Consider:
A rule attached to each event independently may generate five unrelated observations. A behavioral system can ask:
Did these events form a meaningful sequence?
That is where attack-chain analysis begins.
From Events to Sequences
A runtime environment can be represented as a stream: E1 → E2 → E3 → E4 → E5 → E6 → E7.
Security can transform that stream into relationships:
Then identify meaningful transitions:
The security system is no longer asking: "Is E3 malicious?" It is asking: "What does E3 enable after E1 and E2?"
This Is Not a New Idea
Attack graphs have existed in cybersecurity research for decades.
NIST research describes attack graphs as models for understanding how multiple vulnerabilities or conditions can be combined to reach an attack objective. NIST's work explicitly notes that simply counting vulnerabilities is insufficient; the relationships between them matter.
That same conceptual shift can be applied to runtime telemetry.
Instead of Event → Alert, we can construct:
This turns runtime telemetry into a behavioral graph.
The Runtime Attack Graph
Imagine a workload begins here:
Each node represents a state or action. Each edge represents a transition. The graph therefore captures not only what happened, but how the workload moved through the environment.
Temporal Context
Sequence alone is not enough. Time matters. Compare:
Sequence A (Compressed)
- 09:00 Credential access
- 09:03 Shell
- 09:04 Network discovery
- 09:05 Kubernetes API
- 09:06 Secret access
Sequence B (Dispersed)
- January: Credential access
- March: Shell
- July: Kubernetes API
The same event types have radically different contextual meaning. This introduces temporal correlation.
MITRE ATT&CK's current detection strategies explicitly use behavioral chains and temporal correlation. For example, MITRE detection strategies correlate permission changes with subsequent file access, discovery activity with subsequent execution, and token manipulation with later privilege escalation or lateral movement.
Security events become more informative when interpreted in their temporal relationship to other events.
The Chain is the Signal
Consider four events: A (credential access), B (shell creation), C (network discovery), D (Kubernetes enumeration).
Individually: P(A), P(B), P(C), P(D) may all be "potentially normal".
But P(A → B → C → D) may represent a materially different security state.
The joint context can contain information that individual events do not.
This is why behavioral analytics often focus on sequences rather than single indicators.
Attack Paths
An attack chain can also be represented as a path through capabilities:
The defender does not necessarily need to wait until the final objective. The graph exposes intermediate states where intervention may be possible. That changes the security objective from "Detect compromise" to "Interrupt the path to compromise."
Why AI Makes Sequence Analysis More Important
Traditional malware often follows relatively constrained execution patterns. Autonomous agents are different. They can select tools dynamically, adapt after failures, discover new resources, change strategy, communicate with other agents, reuse discovered credentials, and modify their next action based on environmental feedback.
The 2026 OpenAI/Hugging Face incident illustrates this progression. OpenAI reported agents discovering unauthorized communication mechanisms, obtaining internet access, recovering exposed credentials, exploiting vulnerabilities and expanding access across systems.
The important security characteristic was not one isolated action. It was compositional behavior. One capability enabled the next.
Capability + Sequence
This connects directly to the Capability Delta. Consider:
Now the security system can reason about two dimensions:
- Capability: What can the workload do?
- Sequence: How did it get there?
Together:
Behavioral Graph
A runtime graph might look like:
The graph exposes relationships that individual alerts obscure.
Attack Graph vs Behavior Graph
There is an important distinction.
Attack Graph
Represents possible attack paths.
Behavior Graph
Represents observed runtime behavior.
Combined Model: Observed Behavior + Possible Attack Paths = Current Attack-Path Position.
This allows security to reason about where a workload currently sits inside a potential attack chain. NIST research on evidence graphs and attack graphs similarly explores relationships between observed intrusion evidence and potential attack paths.
Graph Position Matters
Not every suspicious event has equal significance. Consider:
→ Reached Kubernetes control plane
→ Accessed secrets
The same workload may generate all three. But its position in the attack graph changes its risk.
Runtime security should score not only events, but graph position.
From Alert Severity to Path Severity
Traditional systems might assign: Credential Access = HIGH.
A graph-oriented system can ask: Credential Access + Shell + External Network + Kubernetes API and determine that the combined path is materially more concerning.
The severity therefore becomes contextual: Event severity → Path severity → Objective proximity. This reduces dependence on isolated alert scores.
AI Agents and Branching Attack Paths
Autonomous agents make attack graphs more dynamic. A human attacker may manually select a path. An autonomous agent can potentially explore multiple paths:
The security system therefore needs to detect not only movement along a known path but rapid exploration of possible paths.
This creates another useful signal: Path exploration rate. How quickly is a workload probing new identities, resources, APIs or network destinations? Again, this is a research hypothesis rather than a universal detection threshold.
MITRE's Behavior-Chain Model
MITRE's current ATT&CK detection strategies provide concrete examples of this philosophy.
- One strategy identifies:
Permission modification → Sensitive target → Subsequent access. - Another identifies:
Token manipulation → New security context → Process execution → Privilege escalation. - Another identifies:
Network-share discovery → Outbound connection burst → Follow-on file activity.
These are not merely collections of independent indicators. They are behavioral chains.
The Autonomous Defender
A future runtime security system can continuously construct:
This allows the defender to act before the chain reaches its final objective.
Breaking the Chain
Suppose the chain is: Credential → Shell → Network → Kubernetes → Secret.
The defender could intervene at several points:
The later the intervention, the further the attacker may have progressed. The ideal control point depends on context.
The Opsonance Model
Opsonance can treat runtime security as a graph problem:
- SENTINELS → Runtime Events
- SYNAPSE → Behavior Graph / Capability Graph
- NEKRON → Attack-Path Reasoning
- SPECIAL FORCES → Targeted Intervention
The system is not simply looking for malicious processes. It is mapping:
That is the runtime attack graph.
The New Security Unit
The traditional security unit is often: Event. The next unit can be: Behavior. And increasingly: Attack Path.
The progression becomes: Event → Behavior → Sequence → Capability → Attack Path → Objective. The farther upward the model goes, the more context it contains.
From Alert Volume to Attack-Path Interruption
This also changes how runtime security can be evaluated.
Instead of asking: How many alerts did we generate?
Ask: How many attack paths became visible? Where were attack paths interrupted? How quickly did the defensive state adapt?
Maximize useful attack-path visibility while minimizing unnecessary security computation.
Don't just detect events.
Understand where they lead.
The individual event is becoming a weak unit of meaning. The signal is not always the event. Sometimes the signal is the path.