Watchlines and Muster: Executable Counterfactuals for Cyber Defense
Bobby Faber · Team Bobby Faber with a little help
Submitted to AI Incident Response Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.
Concepts for reasoning about Cyber Defense: Watchlines
And a modest harness for testing counterfactuals against them: Muster.
Reviews
I liked the focus on what remains compromised after a control works. The example where isolation interrupts the evidence needed for later revocation makes that point well.
It is also good that the report acknowledges when a simple dependency graph gives the same answer. I would align the README with the implemented scenario and test a few alternative attack paths. That would help show how much the conclusions depend on the chosen reconstruction, which the report already recognizes as a limitation.
High clarity tool for testing "if defense is placed here, how does it change attacker capabilities". At this time it only replays attack paths.
Couple of recommendations/extensions:
1) Turn into an interactive website for rapid demonstration of the incidents and what controls help with
2) Potentially enrich the story with failed attempts, denied actions, rejected tool calls, blocked network requests (alternate branches/negative evidence). Informs what is not available.
3) Leverage same failed attempts (even if synthetic) to also create counterfactual branches, then add plausible alternative branches to see if Watchline still holds
Nice work!
I think this project makes a useful distinction between stopping an attacker’s next action and removing access they already gained. It replays incident records with proposed defenses to explore how the outcome might change. One example shows how isolating a system early could leave investigators without information needed to remove that access later.
I would treat this as a useful way to examine response decisions, rather than evidence that early isolation generally makes incidents worse. The result depends on assumptions about when defenses act and what information remains available afterward. Those assumptions need to be clear and consistent, particularly where the paper and repository describe access differently. The example raises a worthwhile question, but broader recommendations need evidence beyond this particular replay.
Cite this project
@misc{faber2026watchlines,
title = {{Watchlines and Muster: Executable Counterfactuals for Cyber Defense}},
author = {Bobby Faber},
year = {2026},
month = sep,
note = {Submitted to AI Incident Response Sprint, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/watchlines-and-muster-executable-counterfactuals-for-cyber-defense-uf3j}},
url = {https://apartresearch.com/sprints/projects/watchlines-and-muster-executable-counterfactuals-for-cyber-defense-uf3j}
}More from AI Incident Response Sprint
- View project: Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Saarlanders
The study evaluates whether an incident-history-reasoning defender outperforms a fixed response policy against an autonomous LLM attacker changing paths after containment. Using a minimal, isolated Docker cyber range …
- View project: When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
Arathi
AI incident-reporting regimes are being introduced in fast succession to address the concerns that exist in the public sphere and government on the risks associated with frontier AI systems, yet we have limited insight …
- View project: A Recomputable Containment Record for Evaluation Sandboxes
A Recomputable Containment Record for Evaluation Sandboxes
Shadow
In this paper, I address the critical issue of AI agents escaping evaluation sandboxes (as seen in the July 2026 incidents where monitors failed) by proposing an externally audit-able containment layer that doesn't rely …