Runtime interception replay · the same IR-2026-07 timeline · ~17,600 actions
The same intrusion, with Cerberus in the loop
This is the exact frontier-lab agent intrusion — the same ~17,600 machine-speed actions — replayed through a runtime that guards the agent's tool calls and its egress. The unguarded attack ran for five days and pivoted from a sandbox into the internal network. Press play and watch where it ends instead.
2026-07-09 → 07-13 UTC~17,600 actions replayedContained · Day 1 · 14:11 UTC0 records left the perimeter
2026-07-09 02:28
Day 1 / 5 · UTC
Attacker actions before interception
0
of 17,613 the attack would have taken
Cerberus verdict
observing
building provenance on every tool call
Blast radius
contained
agent boxed at the first outbound
Attack chain across trust boundaries
Cerberus severs the chain at egress
Phase activity
what the attack never got to do
Live action stream
tool calls + Cerberus verdicts
Volume per day
what never happened
Day 1 (07-09) - Initial access, foothold, C2 established.
Companion to the July 2026 incident disclosure. The unguarded timeline mirrors the public reconstruction; the guarded lane shows where the Cerberus gateway (fail-closed egress guard + Lethal-Trifecta detection) refuses the agent's first outbound. Cerberus guards the agent's tool-call and egress boundary inside your own environment — it does not claim to prevent the upstream model/sandbox foothold; it stops the exfiltration and every downstream pivot that needs egress. Illustrative reconstruction; indicators genericized.See Cerberus →