SCENARIO LIBRARY PREVIEW
Explore safe validation scenarios mapped to real security outcomes .
Public, non-weaponized descriptions of Hayrok validation scenarios. Understand what is validated, which assets are involved, what evidence is expected, and how each scenario supports a measurable outcome.
SCENARIO CATEGORIES
Nine domains, dozens of validated outcomes.
Each preview shows what the category validates and the scenarios inside.
EXPOSURE6 SCENARIOS
Internet Exposure
Whether internet-facing assets are active, exploitable, protected, detected, and connected to critical systems.
›Public Asset Exposure Validation
›Exposed Management Interface Validation
›Internet-Facing API Validation
›WAF Control Validation
›External-to-Internal Reachability
›Internet-to-Crown-Jewel Attack Path
RANSOMWARE8 SCENARIOS
Ransomware Readiness
Whether ransomware-like behaviors can progress, bypass controls, reach critical assets, or go undetected.
›Initial Access Exposure Validation
›Credential Abuse Path Validation
›Privilege Escalation Readiness
›Lateral Movement Control Validation
›Segmentation Validation
›Ransomware Detection Coverage
›Backup Isolation Validation
›Crown-Jewel Reachability
IDENTITY7 SCENARIOS
Identity Security
Whether identities, roles, permissions, tokens, and trust relationships create viable paths to sensitive resources.
›Privileged Access Validation
›Service Account Exposure
›Token Misuse Validation
›IAM Policy Escalation
›Conditional Access Validation
›Identity Detection Coverage
›Identity-to-Crown-Jewel Reachability
API7 SCENARIOS
API Security
API exposure, authentication, authorization, gateway behavior, sensitive data access, and downstream reachability.
›Public API Exposure Validation
›Authentication Control Validation
›Object-Level Authorization Validation
›Function-Level Authorization Validation
›API Gateway Control Validation
›API-to-Database Reachability
›API Detection Coverage
CLOUD8 SCENARIOS
Cloud Security
Cloud identities, storage, workloads, networks, controls, logging, and attack paths.
›Cloud IAM Privilege Validation
›Public Storage Exposure Validation
›Security Group Validation
›Workload Runtime Presence
›Cloud Network Reachability
›Cloud Logging Coverage
›Control Drift Validation
›Cloud-to-Crown-Jewel Attack Path
DETECTION8 SCENARIOS
Detection Coverage
Whether expected security events are generated, delivered, correlated, and surfaced as actionable detections.
›SIEM Rule Validation
›EDR Behavior Detection
›WAF Detection Coverage
›Identity Detection Validation
›Cloud Alert Validation
›Telemetry Pipeline Readiness
›Detection Latency Validation
›Attack-Path Detection Coverage
K8S8 SCENARIOS
Kubernetes Security
Cluster exposure, identities, workloads, network controls, runtime conditions, and audit visibility.
›Kubernetes Ingress Exposure
›RBAC Privilege Escalation
›Service Account Access Validation
›Pod-to-Service Reachability
›Runtime Workload Validation
›Network Policy Validation
›Kubernetes Audit Coverage
›Workload-to-Crown-Jewel Attack Path
SUPPLY8 SCENARIOS
Supply Chain
Whether dependency, secret, pipeline, container, and artifact risks are present and reachable in active environments.
›SCA-to-Runtime Correlation
›Vulnerable Dependency Presence
›Dependency Reachability
›Secret-to-Service Reachability
›CI/CD Control Validation
›Container Registry Access
›Artifact Integrity Validation
›Supply Chain Toxic Combination
AI8 SCENARIOS
AI Security
AI applications, LLM endpoints, agents, prompts, tools, data access, guardrails, and detections.
›Public AI Endpoint Exposure
›Prompt Injection Control Validation
›AI Agent Tool-Abuse Validation
›RAG Data Leakage Validation
›Model API Authorization
›AI Sensitive Data Reachability
›AI Detection Coverage
›AI Agent-to-Crown-Jewel Attack Path
SCENARIO LIBRARY AT A GLANCE
Curated, governed, and continuously growing.
420+
Governed scenarios
9
Domain categories
12
Framework mappings
Weekly
New scenario releases
EXAMPLE SCENARIO CARD
The public preview format. Non-weaponized. Framework-mapped.
API · SC-API-0142
Cross-Tenant Object Authorization Validation
Validates whether a B2B SaaS platform correctly enforces tenant boundaries on object-level API operations under realistic authentication contexts.
Security objectiveProve tenant isolation
Business questionCan Tenant A read Tenant B’s data?
Asset typesREST/GraphQL APIs · Multi-tenant DB
Safety classSafe · read-only · production-ready
VALIDATION METHODS
Cross-tenant probeObject ID enumerationRole-context replayBoundary decision replay
TELEMETRY REQUIRED
API gateway logsApplication auth eventsDB query auditIdentity provider events
EVIDENCE EXPECTED
Signed request/responseAuth contextBoundary decisionDB event correlation
FRAMEWORK MAPPINGS
OWASP API1:2023MITRE T1078NIST 800-53 AC-3ISO 27001 A.9.4PCI DSS 8.5
Ready to run these scenarios in your environment?
Every scenario ships with telemetry, safety controls, and evidence contracts — governed by Genesis and executed by validation agents.