This is a small attack graph — the same structure security teams build during threat modeling (STRIDE / PASTA / attack-tree analysis). Each node is an asset, each directed edge is a possible attack step tagged with a STRIDE-style category (credential theft, injection, lateral network movement, privilege escalation). Every edge carries a numeric exploit cost:
credential edge: cost = base × (MFA on ? 2.5 : 1)
injection edge: cost = base × (1 + patch/100 × 2)
network edge: cost = base × (1 + segmentation/100 × 2)
privilege edge: cost = base × (1 + patch/100 × 1.5)
The simulator runs Dijkstra's shortest-path algorithm from the chosen entry point to the crown-jewel database, treating "shortest" as "cheapest for the attacker" — exactly how automated attack-graph tools (e.g. MulVAL) rank the most likely breach route among many possible ones. Total path cost is converted into two attacker-relevant numbers: an estimated time to compromise and a breach-risk score, both of which fall as your controls raise the cost of every edge on the current best path.
- Entry point — where the attacker starts (a phished user, a public web app, or a VPN gateway).
- Patch level — raises the cost of injection and privilege-escalation edges (unpatched CVEs are cheap to exploit).
- Segmentation — raises the cost of lateral, network-crossing edges (flat networks make lateral movement cheap).
- MFA — raises the cost of every credential-based edge (phishing, VPN, and stolen admin credentials).
- Weakest link — the single cheapest edge on the current best path; in real threat modeling this is the control a defender should fix first, since it does the most to raise the attacker's total cost.
The glowing pulse animates the attacker's actual traversal of the current cheapest path, one edge at a time, looping continuously.