Real security-operations triage does not sort an incoming event into a single bucket — it scores the event along several independent axes (how covert it is, whether it originates inside or outside the perimeter, and what it is ultimately trying to achieve) and assigns it to whichever known attack class it statistically resembles most. This simulator makes that process visible: six attack classes — DDoS/flooding, ransomware, phishing & social engineering, advanced persistent threat espionage, insider data exfiltration and insider sabotage — sit at fixed centroids in a 3D stealth/origin/objective feature cube. Every spawned event is a noisy sample of one true class, and a real nearest-centroid classifier with a softmax confidence score assigns it to the class it is closest to, flying it toward that centroid and marking whether the prediction was correct. Raise the noise slider to watch classification accuracy degrade exactly as it does when real attacks blend their traffic patterns to evade detection.