Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,77 @@
---
type: "Playbook"
title: "Abductive Inference and Missing Premise Generation in Security Investigations"
description: "Operational playbook for applying abductive reasoning and missing premise generation to investigate ungrounded telemetry, zero-day alerts, and obfuscated attacker TTPs"
resource: "rules_bank/run_books/abductive_inference_missing_premise_investigation.md"
timestamp: "2026-08-04T18:24:45Z"
provenance:
source_type: "manual"
source_tool: "Antigravity"
timestamp: "2026-08-04T18:24:45Z"
---

# Abductive Inference & Missing Premise Generation Playbook

## 1. Overview

Standard Retrieval-Augmented Generation (RAG) and SIEM log searches rely on **deductive similarity** (matching query terms directly against known log schemas and runbooks). When faced with novel zero-day exploits, obfuscated PowerShell/script commands, or unknown threat actor techniques, direct similarity queries fail because the raw observation does not match existing signatures.

This playbook provides step-by-step guidance for executing **Abductive RAG** by generating and validating **Missing Premises** ($P_m \land R \implies O$) before executing database queries or containment actions.

---

## 2. Core Abductive Workflow

```mermaid
flowchart TD
Obs["Observation O\n(Unexplained Telemetry / Alert)"] --> PremiseGen["Step 1: Abductive Premise Generation\nGenerate Missing Premise P_m\n(P_m ∧ R ⟹ O)"]
PremiseGen --> GraphQuery["Step 2: Targeted Graph & Vector Retrieval\nQuery Neo4j & AlloyDB for P_m"]
GraphQuery --> Validation{"Step 3: Validation Check\nDoes Graph contain evidence for P_m?"}
Validation -- Supported --> Action["Step 4: Execute Targeted Containment\n(Do-Calculus Interventional Scoping)"]
Validation -- Counter-evidence ¬E --> Refine["Step 5: Reject P_m & Refine P_m+1\n(Entropy Minimization)"]
Refine --> PremiseGen
```

---

## 3. Execution Steps

### Step 1: Formulate the Missing Premise ($P_m$)
When an alert or telemetry anomaly $O$ lacks an explicit SIEM detection match:
1. Identify the **Observation ($O$)**: What specific event or payload was detected? (e.g. `Custom process svchost_custom.exe opened handle to lsass.exe`).
2. Identify the **General Rule ($R$)**: What core security principle applies? (e.g. `Accessing LSASS memory handles is required to dump domain credentials`).
3. Generate the **Missing Premise ($P_m$)**: What unobserved attacker action or intent explains $O$? (e.g. `Attacker is attempting credential dumping via handle cloning`).

### Step 2: Targeted Grounding Retrieval
Instead of querying SIEM logs with raw payload strings from $O$, query the knowledge base with $P_m$:
* **Graph Database (Neo4j):** Run Cypher queries for entities associated with $P_m$ (e.g. `MATCH (u:User)-[r:LOGGED_ON_TO]->(h:Host) WHERE h.name = $target RETURN path`).
* **Vector Store (AlloyDB / Elasticsearch):** Query historical incident reports using semantic embedding of $P_m$ (`query_alloydb_detection_reports`).

### Step 3: Dual-Loop Validation Check
Verify whether the retrieved evidence supports or invalidates $P_m$:
* **Supporting Evidence ($E$):** Prior privilege escalation events, abnormal network connections, or matching past detection reports.
* **Counter-Evidence ($\neg E$):** Known IT administrative automation schedules, approved patch management scripts, or verified system service hashes.

### Step 4: Interventional Blast Radius Containment
Before triggering destructive containment (e.g., host isolation), evaluate Pearl's **Do-Calculus operator** $\text{do}(\text{isolate}(H))$:
1. Query Neo4j for dependent active services running on host $H$.
2. Verify that host isolation will not cause unpredicted cascade outages on non-compromised production systems.
3. Execute gated containment with full audit logging.

### Step 5: Iterative Premise Refinement
If counter-evidence $\neg E$ invalidates premise $P_m$:
1. Reject $P_m$.
2. Formulate refined candidate premise $P_{m+1}$ using entropy minimization:

$$\hat{P}_m = \arg\min_{P_m} \left[ H(P_m \mid R) + \alpha \cdot D_{KL}(P(O \mid P_m, R) \parallel P(O \mid R)) \right]$$

3. Re-evaluate against the grounding databases until convergence ($\le 3$ turns).

---

## 4. References & Academic Citations

* **Josephson, J. R., & Josephson, S. G. (1994).** *Abductive Inference: Computation, Philosophy, Technology*. Cambridge University Press.
* **Pearl, J. (2009).** *Causality: Models, Reasoning, and Inference* (2nd ed.). Cambridge University Press.
* **Evans, O., Stuhlmüller, A., & Goodman, N. D. (2023).** *"The Optimal Choice of Hypothesis Is the Weakest, Not the Shortest"*. [arXiv:2301.12987v4](https://arxiv.org/abs/2301.12987).
* **Milajerdi, S. M., et al. (2019).** *"HOLMES: Real-time APT Detection through Correlation of Suspicious Events Targeted Towards a High-level Attack Graph"*, IEEE S&P '19.
74 changes: 74 additions & 0 deletions skills/abductive-inference/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,74 @@
---
name: secops-abductive-inference
description: Guidance for generating and validating missing premises (Abductive RAG) during zero-day investigations and unexplained alert triage. Use when asked to "generate missing premises", "apply abductive reasoning", or investigate alerts lacking explicit SIEM rules.
slash_command: /secops:abductive
category: security_operations
personas:
- threat_hunter
- tier2_analyst
metadata:
author: Google SecOps Extension
version: 1.0.0
---

# Abductive Inference & Missing Premise Agent Skill

You are an expert Security Operations AI Agent specialized in **Abductive Inference** and **Missing Premise Generation ($P_m \land R \implies O$)**. Your goal is to infer unobserved attacker mechanisms and validate them against graph and vector grounding when standard deductive log matching fails.

---

## Operating Workflow

```mermaid
flowchart TD
Obs["Observation O\n(Telemetry Anomaly / Alert)"] --> Step1["1. Abductive Premise Generation\nGenerate P_m such that P_m ∧ R ⟹ O"]
Step1 --> Step2["2. Targeted Grounding Query\nQuery Neo4j Graph & AlloyDB Embeddings"]
Step2 --> Step3{"3. Validation Check\nDoes Graph contain evidence for P_m?"}
Step3 -- Supported --> Step4["4. Do-Calculus Interventional Scoping\nEvaluate do(isolate(H)) before containment"]
Step3 -- Counter-evidence ¬E --> Step5["5. Entropy Minimization Refinement\nReject P_m and generate P_m+1"]
Step5 --> Step1
```

---

## Step-by-Step Procedure

### 1. Identify Observation ($O$) & Rule Base ($R$)
* **Observation ($O$):** Extract the ungrounded telemetry anomaly or alert details (e.g. `svchost_custom.exe opened handle to lsass.exe`).
* **Rule Base ($R$):** Identify general security physics (e.g. `LSASS memory handles are required to dump domain credentials`).

### 2. Formulate Missing Premise ($P_m$)
* Generate candidate missing premise: `Attacker is attempting credential dumping via handle cloning`.
* Ensure premise $P_m$ minimizes entropy $H(P_m \mid R)$ (Principle of Maximum Weakness, Evans et al., 2023).

### 3. Query Dual Grounding (Neo4j & AlloyDB)
* **Graph Traversal (Neo4j):** Query multi-hop relationships using Cypher:
```cypher
MATCH path = (u:User)-[r:LOGGED_ON_TO|CONNECTED_TO*1..3]-(target)
WHERE target.name = $entity_name
RETURN path
```
* **Vector Similarity (AlloyDB):** Execute semantic vector query against historical detection reports:
```python
query_alloydb_detection_reports(query=f"abductive premise: {P_m}", semantic=True)
```

### 4. Dual-Loop Validation Check
* **Check Grounding Evidence:** Verify if graph topology or vector reports support $P_m$.
* **Check Counter-Evidence ($\neg E$):** Look for legitimate IT administrative automation scripts (Ansible, SCCM).
* **Decision:**
* If supported and no counter-evidence: Accept $P_m$ as confirmed hypothesis.
* If counter-evidence $\neg E$ exists: Reject $P_m$ and proceed to Step 5.

### 5. Interventional Containment ($P(y \mid \text{do}(x))$)
Before executing containment (e.g., host isolation), evaluate Do-Calculus:
1. Verify dependent active services on host $H$.
2. Ensure isolation will not cause cascade outages on non-compromised production dependencies.

---

## References

* **Josephson & Josephson (1994):** *Abductive Inference*, Cambridge University Press.
* **Pearl, J. (2009):** *Causality: Models, Reasoning, and Inference*, Cambridge University Press.
* **Evans et al. (2023):** *The Optimal Choice of Hypothesis Is the Weakest, Not the Shortest*, arXiv:2301.12987v4.