Initializing Architecture
Case Study / Sprint entry, 3-person team

Apocalypse

The July 2026 frontier-model sandbox escape had no public standard you could test a lab against. And the evidence is thin: there is no 17,600-action corpus, only 8 phase totals, 5 day counts, and 14 example commands in the public record.

Apocalypse project screenshot
Approach

For the Apart x CeSIA AI Incident Response Sprint (Track 1), three of us wrote a 9-rule containment standard where every rule maps to one documented step of the real attack, then built what proves it: a broken lab with the real misconfiguration, a fixed lab, and checks anyone can run on a laptop in seconds.

Model / System

A fail-closed scorecard runner (a hostile config fails one rule, never crashes the suite), an attack replay of the 13 boundary-testing steps, detection simulators that run harmless local event generators through independent matchers, and an Ed25519 capability token for rule 9. Offline, no API keys, no cluster.

Result

Fixed lab 9 of 9, broken lab 0 of 9, all 13 attack steps blocked on replay, detection at 18 true positives, 0 false negatives, 0 false positives and 18 true negatives, and 118 tests passing. I owned rules 4, 5 and 9, the scorecard runner, and the architecture.

Technical highlights

What to inspect.

01

Every rule cites a specific line of a curated public-record file, and curating that record was part of the work.

02

Broken-vs-fixed labs make the standard verifiable by a third party without lab network access, which was the track's literal success bar.

03

Red-team labs (exploit and adversarial configs) were used to attack the checkers themselves, and every bypass found is written up with its fix.