Codex

Every defence and every threat, with the stats the simulation actually runs on. Threat numbers are the wave-one baseline; health and bounty scale up as a run progresses.

Every threat and defence here is real

Threats map to MITRE ATT&CK techniques and defences to MITRE D3FEND countermeasures, using the same dataset that powers MITRE ATT&CK Adventure. Nothing here is invented: if a threat has no D3FEND coverage, this page says so rather than guessing.

PLAY THE ADVENTURE →

Same seven D3FEND tactics the Adventure’s Defender seat uses: Model, Harden, Detect, Isolate, Deceive, Evict, Restore. A firewall here is Isolate there; a honeypot is Deceive in both.

Doctrine

Defence in depth

A threat that has already been engaged by several different kinds of control takes more damage from the next one. Ten firewalls are one layer. A firewall, an IDS and an encryption field are three.

+9% per extra layer, up to ×1.36 at 5 layers

The small marks above a threat’s health bar count the layers it has taken so far. This is the main reason a varied board beats a bigger uniform one.

Alert fatigue

More sensors means more alerts, and past a point less attention paid to any one of them. Detectors past the 3rd dilute the strength of every flag on the board. Detection itself never fails; only the damage bonus weakens.

3 detectors
100% flag strength
5 detectors
78% flag strength
8 detectors
59% flag strength
12 detectors
44% flag strength

Three upgraded sensors beat ten cheap ones, which is the right answer here and in a real detection programme.

Defences

Firewall

Rapid single-targetLVL 1

Stateful packet filtering. Cheap, fast, and always the first thing you stand up. Struggles against hardened payloads.

Cost
120
Damage
8 → 24
Range
112 → 144
Rate
2.2/s
D3FENDIsolate
  • D3-NTF Network Traffic Filtering
  • D3-ITF Inbound Traffic Filtering
  1. MK1Baseline packet filtering.
  2. MK2Tighter rule set: +damage, +range.
  3. MK3Application-aware filtering: faster and harder hitting.
  4. MK4Deep packet inspection burns targets over time.

Antivirus

Splash damageLVL 1

Signature-based scanning with a quarantine burst. Clears clustered, low-health swarms faster than anything else.

Cost
210
Damage
14 → 44
Range
104 → 130
Rate
1/s
D3FENDDetect
  1. MK1Quarantine burst on impact.
  2. MK2Wider quarantine radius.
  3. MK3Heuristics: larger blast, less falloff.
  4. MK4Residual scan burns everything caught in the blast.

IDS / IPS

Detection & markingLVL 2

Intrusion detection. Reveals stealthed threats in range and flags what it hits so every other tower hurts more.

Cost
180
Damage
9 → 26
Range
144 → 192
Rate
1.4/s
D3FENDDetect
  1. MK1Reveals stealth. Flagged threats take +15% damage.
  2. MK2Better signatures: +22% damage taken.
  3. MK3Correlation engine: +32% damage taken.
  4. MK4Inline prevention. Sees encrypted tunnels; +45% damage taken.

Encryption Node

Area slowLVL 3

Forces every packet through a crypto handshake. Low damage, but the throughput penalty stacks up across a whole lane.

Cost
240
Damage
5 → 18
Range
98 → 132
Rate
1/s
D3FENDHarden
  1. MK1Pulses the field. Slows everything inside by 25%.
  2. MK2Stronger cipher suite: 33% slow.
  3. MK3Perfect forward secrecy: 42% slow.
  4. MK4Post-quantum handshake: 52% slow, faster pulses.

Honeypot

Lure & forensicsLVL 4

A deliberately soft target. Pulls threats toward it, poisons them slowly, and turns every kill nearby into extra budget.

Cost
150
Damage
4 → 17
Range
112 → 148
Rate
1.5/s
D3FENDDeceive
  1. MK1Lures threats; +2 credits per kill in range.
  2. MK2Deeper decoy: stronger pull, +3 credits.
  3. MK3Tarpit: threats take damage over time, +5 credits.
  4. MK4Full deception grid: heavy tarpit, +9 credits per kill.

EDR Mesh

Chain damageLVL 4

Endpoint agents sharing telemetry. A detection on one host propagates to its neighbours, arcing between clustered threats.

Cost
300
Damage
16 → 48
Range
132 → 166
Rate
1.1/s
D3FENDIsolate
  • D3-ABPI Application-based Process Isolation
  • D3-SCF System Call Filtering
  1. MK1Arcs to 2 additional threats.
  2. MK2Wider mesh: arcs to 3.
  3. MK3Arcs to 4 with less damage loss.
  4. MK4Host isolation: arcs to 6, 25% chance to freeze a threat.

SOC Uplink

Support auraLVL 5

Analysts feeding targeting data to everything around them. Deals no damage itself, and makes every neighbour hit harder and faster.

Cost
390
Damage
0 → 0
Range
124 → 178
Rate
0/s
D3FENDModel
  1. MK1+12% damage and fire rate to towers in range.
  2. MK2Tier-2 analysts: +19% to both.
  3. MK3Threat intel feed: +27% to both.
  4. MK4Fusion centre: +38% to both, and grants stealth detection.

AI Sentinel

Long-range sniperLVL 6

A model that learns the target it is shooting at. Slow, expensive, enormous range, and it ramps up the longer it stays locked on. The answer to anything with too much health to burst down.

Cost
360
Damage
55 → 200
Range
244 → 324
Rate
1/s
D3FENDDetect
  1. MK1Ramps +8% damage per consecutive hit, up to +100%.
  2. MK2Larger model: more damage and reach.
  3. MK3Faster convergence: ramps to +150%.
  4. MK4Autonomous response: ramps to +220%, punches through one extra target, and sees tunnelled traffic.

Threats

ThreatHealthSpeedArmourCore dmgBountyFrom waveATT&CK
Virus

Self-replicating code riding a host file. The baseline nuisance: no armour, no tricks.

551.50191T1204.002
User Execution: Malicious File
Runs because somebody opened it.
Worm

Propagates on its own across the network. Fast and fragile, and it never comes alone.

382.60172T1091
Replication Through Removable Media
Spreads on its own, without anyone opening anything.
Phishing Payload

A convincing lure clicked by a real user. Almost no health, but it sprints for the core.

263.20163T1566.002
Phishing: Spearphishing Link
A convincing lure, clicked by a real person.
Trojan

Hides inside something you asked for. Lightly armoured, so chip damage bounces off it.

1101.222144T1027.002
Obfuscated Files or Information: Software Packing
Packed so the thing you scan is not the thing that runs.
Ransomware

Encrypts everything it touches. Slow, heavily armoured, and devastating if it reaches the core. Needs burst damage, not chip damage.

2600.8563325T1486
Data Encrypted for Impact
Encrypts what it reaches and asks to be paid.
Cryptominer

Does not want to break anything. It wants your compute, and it drains budget every second it survives.

1301.311206T1496
Resource Hijacking
Wants your compute, not your data.
DDoS Packet

Volumetric flood traffic. Individually trivial, collectively overwhelming. Bring splash damage.

202.20127T1498.001
Network Denial of Service: Direct Network Flood
Volume as the weapon.
Botnet Node

A command-and-control hub. Killing it scatters the bots it was coordinating.

190132248T1583.005
Acquire Infrastructure: Botnet
A rented crowd of compromised hosts.
Zombie Host

An orphaned bot with no controller left. Only appears when a botnet node is destroyed.

301.9013—T1105
Ingress Tool Transfer
The payload pulled down onto each conscripted host.
Rootkit

Operates below the OS. Completely invisible, and untargetable, until a detector lights it up.

1501.15422810T1014
Rootkit
Sits below the layer doing the looking.
Encrypted Tunnel

Exfiltration over TLS. Ignores your network topology entirely and flies straight at the core.

1201.4222612T1572
Protocol Tunneling
Exfiltration wrapped in traffic you already allow.
Logic Bomb

Dormant until its trigger fires. Hits the core hard, and accelerates the closer it gets to dying.

1801.6253014T1053
Scheduled Task/Job
Dormant until its trigger condition fires.
APT Implant

A funded, patient adversary. Shielded, self-healing, and it will outlast anything that cannot burst it down.

4201.05845816T1078
Valid Accounts
Not breaking in. Logging in, and staying.
Zero-Day Exploit

No signature exists. No patch exists. It is immune to throttling and it does not care about your rule sets.

17000.75915420—T1068
Exploitation for Privilege Escalation
No signature exists yet, because nobody has seen it.