The cheapest way to the goal, and the smallest defence that stops it
Paste one attack tree for one attacker goal, as an indented outline with AND and OR gates.
Your browser rolls cost, difficulty, detection and time up the gates, lists every attack
scenario, finds the cheapest, easiest, stealthiest and fastest, and works out the
minimal cut sets: the smallest sets of steps whose defence blocks every
scenario. All free, before you sign in. No tree yet? Describe the system and the desk drafts
one. Then a review checks the gates and the estimates, adds the branches the tree is missing
and picks the defence that buys the most. Everything it writes is checked against the tree.
Every example comes with a saved model reply, one per lane and outcome, so you can see the
whole page without signing in or spending a credit. The systems in them are invented.
Reviewing
Drafted tree
steps
scenarios
notes
disagreements
The tree
Why each step is there
Assumptions
Left out on purpose
Questions the description leaves open
Checked against the analyzer
The drafted tree was read by the same engine a pasted tree goes through, and every note and in-place control was checked against your description.
flags answered
gates checked
estimates challenged
branches added
disagreements
The defence that buys the most
Flags
Gates
Estimates to change
Branches the tree is missing
Adding a branch writes its lines under its parent in the tree above and re-runs the free analysis, so you can see what it changes before you review again.
For stakeholders
Reconciliation with the analysis
Every flag the review answered, every gate and estimate it quoted, every branch it proposed, the cut it recommends, its verdict, and every id and share it wrote were checked against the analysis your browser computed. A disagreement means the review, not your tree, is wrong.
Summary
Raw model reply
The reply did not parse as the structured result, so it is shown as it arrived.
Your recent runs
If that did not work
Check that each node is on its own line with its children indented under it, that you are
signed in, and that your balance covers the amount reserved next to the button. The four
examples always work and cost nothing, so they are the quickest way to tell whether the
problem is your tree or the service.
How the numbers are worked out
An OR gate is reached by any one child; an AND gate needs
every child. A scenario is one set of steps that reaches the goal. Its
difficulty and detection are those of its hardest and loudest step; its cost and time are the
sums over its steps. Difficulty is scored 1 to 5 and cost and detection 0 to 4, following the
scales in the attack-tree-construction skill. A minimal cut set is a smallest
set of steps that appears in every scenario's way: defend all of them and the goal is out of
reach, as the tree is written. A control marked in place only counts if it works; the
desk never assumes it does.
The scenario and cut-set counts are exact even when a tree has too many to list. The review is
sent the analysis, never asked to redo it, and every number it writes is checked against it.