{"id":2176,"date":"2026-03-15T12:55:00","date_gmt":"2026-03-15T12:55:00","guid":{"rendered":"https:\/\/abstractionslab.com\/?p=2176"},"modified":"2026-03-17T10:08:43","modified_gmt":"2026-03-17T10:08:43","slug":"idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine","status":"publish","type":"post","link":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/","title":{"rendered":"IDPS-ESCAPE (V0.7 + V0.8): SONAR, DECIPHER CTI, RADAR risk engine"},"content":{"rendered":"\n<p>March 15, 2026 \u2014 Abstractions Lab announces the joint release of IDPS-ESCAPE v0.7 and v0.8. Together, these two releases represent the most significant functional leap in the project since RADAR was introduced in v0.4.<\/p>\n\n\n\n<div class=\"wp-block-uagb-image aligncenter uagb-block-bb22f969 wp-block-uagb-image--layout-default wp-block-uagb-image--effect-static wp-block-uagb-image--align-center\"><figure class=\"wp-block-uagb-image__figure\"><a class=\"\" href=\"https:\/\/abstractionslab.github.io\/idps-escape\/website\/product-presentation.html\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" srcset=\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2024\/09\/1D1B2_LOG_IDPS-ESCAPE_v1.0-1-150x150.png ,https:\/\/abstractionslab.com\/wp-content\/uploads\/2024\/09\/1D1B2_LOG_IDPS-ESCAPE_v1.0-1.png 780w, https:\/\/abstractionslab.com\/wp-content\/uploads\/2024\/09\/1D1B2_LOG_IDPS-ESCAPE_v1.0-1.png 360w\" sizes=\"auto, (max-width: 480px) 150px\" src=\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2024\/09\/1D1B2_LOG_IDPS-ESCAPE_v1.0-1-150x150.png\" alt=\"\" class=\"uag-image-1615\" width=\"100\" height=\"100\" title=\"1D1B2_LOG_IDPS-ESCAPE_v1.0\" loading=\"lazy\" role=\"img\"\/><\/a><figcaption class=\"uagb-image-caption\"><a href=\"https:\/\/abstractionslab.github.io\/idps-escape\/website\/product-presentation.html\" target=\"_blank\" rel=\"noreferrer noopener\">IDPS-ESCAPE<\/a><\/figcaption><\/figure><\/div>\n\n\n\n<p>For a visual user-oriented tour of IDPS-ESCAPE, visit the <a href=\"https:\/\/abstractionslab.github.io\/idps-escape\/website\/product-presentation.html\"><strong>product presentation page<\/strong><\/a>. The release is now <a href=\"https:\/\/github.com\/AbstractionsLab\/idps-escape\">available on GitHub<\/a>.<\/p>\n\n\n\n<div class=\"wp-block-uagb-image aligncenter uagb-block-ce7d0bb9 wp-block-uagb-image--layout-default wp-block-uagb-image--effect-zoomin wp-block-uagb-image--align-center\"><figure class=\"wp-block-uagb-image__figure\"><a class=\"\" href=\"https:\/\/abstractionslab.github.io\/idps-escape\/website\/product-presentation.html\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" srcset=\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/IDPS-ESCAPE-product-website-1024x480.png ,https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/IDPS-ESCAPE-product-website.png 780w, https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/IDPS-ESCAPE-product-website.png 360w\" sizes=\"auto, (max-width: 480px) 150px\" src=\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/IDPS-ESCAPE-product-website-1024x480.png\" alt=\"\" class=\"uag-image-2178\" width=\"687\" height=\"397\" title=\"IDPS-ESCAPE-product-website\" loading=\"lazy\" role=\"img\"\/><\/a><\/figure><\/div>\n\n\n\n<p>v0.7 delivers SONAR \u2014 a production-grade multivariate anomaly detection engine \u2014 a risk computation model for RADAR, and the first structural integration of <strong><a href=\"https:\/\/abstractionslab.github.io\/satrap-dl\/website\/product-presentation.html\" target=\"_blank\" rel=\"noreferrer noopener\">SATRAP-DL<\/a><\/strong>&#8216;s <a href=\"https:\/\/github.com\/AbstractionsLab\/satrap-dl\/tree\/main\/decipher\" target=\"_blank\" rel=\"noreferrer noopener\">DECIPHER<\/a> subsystem. v0.8 completes that integration with a fully operational <code>DecipherClient<\/code>, adds health check and attack simulation tooling, and upgrades the SpecEngine and traceability layer to <strong><a href=\"https:\/\/abstractionslab.github.io\/c5dec\/website\/product-presentation.html\" target=\"_blank\" rel=\"noreferrer noopener\">C5-DEC v1.2<\/a><\/strong>. Together, they close the loop on IDPS-ESCAPE&#8217;s MAPE-K (Monitor, Analyze, Plan, Execute, Knowledge) architecture: detection signals flow into a mathematically grounded risk engine, trigger risk-scaled automated responses enriched by live CTI, and generate Flowintel incident cases automatically \u2014 all within a fully traceable, specification-driven environment.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Key Highlights Of V0.7 And V0.8<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">SONAR: A Production-Grade Multivariate Anomaly Detection Engine<\/h3>\n\n\n\n<p>SONAR (SIEM-Oriented Neural Anomaly Recognition), the headline feature of v0.7, is a complete redesign of ADBox as a production-ready anomaly detection subsystem for Wazuh. Powered by Microsoft&#8217;s MTAD-GAT deep learning library, it operates directly on Wazuh alert streams through a YAML-based scenario system that makes detection workflows fully repeatable and version-controllable without touching Python code. Four pre-built scenario templates ship out of the box; a debug mode enables full offline train-detect cycles without a live Wazuh instance. With SONAR reaching production status, ADBox has been formally designated as a legacy research engine.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">A Risk Engine And Three-Tier Automated Response For RADAR<\/h3>\n\n\n\n<p>v0.7 replaces RADAR&#8217;s ad-hoc per-scenario decision logic with a principled weighted fusion model: the normalized risk score <\/p>\n\n\n\n<div class=\"wp-block-math\"><math display=\"block\"><semantics><mrow><mi>R<\/mi><mo>\u2208<\/mo><mo form=\"prefix\" stretchy=\"false\">[<\/mo><mn>0,1<\/mn><mo form=\"postfix\" stretchy=\"false\">]<\/mo><mo>=<\/mo><msub><mi>w<\/mi><mi>a<\/mi><\/msub><mo>\u22c5<\/mo><mi>A<\/mi><mo>+<\/mo><msub><mi>w<\/mi><mi>s<\/mi><\/msub><mo>\u22c5<\/mo><mi>S<\/mi><mo>+<\/mo><msub><mi>w<\/mi><mi>t<\/mi><\/msub><mo>\u22c5<\/mo><mi>T<\/mi><\/mrow><annotation encoding=\"application\/x-tex\">R \\in [0,1] = w_a \\cdot A + w_s \\cdot S + w_t \\cdot T<\/annotation><\/semantics><\/math><\/div>\n\n\n\n<p>combines anomaly detection signal A, signature-based risk S, and DECIPHER CTI score T. The score drives a three-tier response system \u2014 notification, remediation with case creation, and full host isolation \u2014 implemented in a single consolidated active response script (<code>radar_ar.py<\/code>) that replaces the previous fragmented per-scenario implementations. v0.8 refines the tier boundaries and separates per-tier mitigation configuration for finer operational control.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">DECIPHER Integration: From Stub To Full Production Client<\/h3>\n\n\n\n<p>v0.7 introduced a <code>SatrapClientMock<\/code> stub establishing the DECIPHER interface contract; v0.8 replaces it with a fully operational <code>DecipherClient<\/code> communicating with DECIPHER&#8217;s REST API. When RADAR fires a medium- or high-risk response, <code>DecipherClient<\/code> queries DECIPHER for MISP-backed IOC assessments, receives a CTI score, fuses it into the overall risk score, and opens a structured Flowintel case \u2014 all without manual SOC intervention.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"515\" src=\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/RADAR-DECIPHER-Flowintel-integration-1024x515.png\" alt=\"\" class=\"wp-image-2182\" srcset=\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/RADAR-DECIPHER-Flowintel-integration-1024x515.png 1024w, https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/RADAR-DECIPHER-Flowintel-integration-300x151.png 300w, https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/RADAR-DECIPHER-Flowintel-integration-768x386.png 768w, https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/RADAR-DECIPHER-Flowintel-integration-1536x772.png 1536w, https:\/\/abstractionslab.com\/wp-content\/uploads\/2026\/03\/RADAR-DECIPHER-Flowintel-integration.png 1699w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Flowintel incident cases created automatically by DECIPHER with full RADAR context: scenario, detection type, risk tier, CTI breakdown, and IOC set.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">RADAR Health Checks And Attack Simulation<\/h3>\n\n\n\n<p>v0.8 adds a health check tool, an Ansible-driven diagnostic framework that verifies the reachability and functional status of all RADAR stack components on both manager and agent nodes. Complementing it, an attack simulation tool provides a controlled harness for exercising all three production scenarios \u2014 GeoIP anomaly, log volume change, and suspicious login \u2014 using dedicated Python simulation modules, with a companion Ansible playbook extending simulation support to remote agents.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">SpecEngine Tooling And Traceability Infrastructure<\/h3>\n\n\n\n<p>v0.8 consolidates all SpecEngine scripts from <strong><a href=\"https:\/\/abstractionslab.github.io\/c5dec\/website\/product-presentation.html\" target=\"_blank\" rel=\"noreferrer noopener\">C5-DEC v1.2<\/a><\/strong>, adding <code>c5graph.py<\/code> (interactive Cytoscape.js specification graph), <code>c5mermaid.py<\/code> (Mermaid-to-SVG\/PNG rendering for Doorstop items), and <code>prune_bad_links.py<\/code> (automated link hygiene). The existing <code>c5traceability.py<\/code> and <code>c5browser.py<\/code> have been upgraded with richer coverage metrics, per-column filtering, and correct numeric sorting, and both are now integrated into the <code>publish.sh<\/code> workflow.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Specification Completeness, TRP Consolidation, And Product Website<\/h3>\n\n\n\n<p>New and revised HARC, LARC, and SWD items achieve technical specification completeness across RADAR and SONAR, with explicit source-file references replacing verbose pseudocode. The previously separate TRA and TRB test execution document types have been merged into a unified TRP (Test Case Execution Report) format. v0.8 also introduces the <a href=\"https:\/\/abstractionslab.github.io\/idps-escape\/website\/product-presentation.html\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>IDPS-ESCAPE product presentation page<\/strong><\/a>, providing a user-oriented visual overview of the platform.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Availability<\/h2>\n\n\n\n<p>IDPS-ESCAPE v0.8 product presentation page:<\/p>\n\n\n\n<p><a href=\"https:\/\/abstractionslab.github.io\/idps-escape\/website\/product-presentation.html\">https:\/\/abstractionslab.github.io\/idps-escape\/website\/product-presentation.html<\/a><\/p>\n\n\n\n<p>IDPS-ESCAPE v0.7 and v0.8 are available now as free and open-source releases on GitHub, including updated documentation, user manuals, Ansible deployment automation, and a complete technical specification tree with traceability coverage:<\/p>\n\n\n\n<p><a href=\"https:\/\/github.com\/AbstractionsLab\/idps-escape\">https:\/\/github.com\/AbstractionsLab\/idps-escape<\/a><\/p>\n\n\n\n<p>A live specification browser and traceability statistics report at:<br><a href=\"https:\/\/abstractionslab.github.io\/idps-escape\/traceability\/index.html\">https:\/\/abstractionslab.github.io\/idps-escape\/traceability\/index.html<\/a><\/p>\n\n\n\n<p>Community feedback and contributions are welcome.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>March 15, 2026 \u2014 Abstractions Lab announces the joint release of IDPS-ESCAPE v0.7 and v0.8. Together, these two releases represent [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_uag_custom_page_level_css":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[6,10],"tags":[9],"class_list":["post-2176","post","type-post","status-publish","format-standard","hentry","category-cyfort","category-idps-escape","tag-software-release-2"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>IDPS-ESCAPE (V0.7 + V0.8): SONAR, DECIPHER CTI, RADAR risk engine - Abstractions Lab<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"IDPS-ESCAPE (V0.7 + V0.8): SONAR, DECIPHER CTI, RADAR risk engine - Abstractions Lab\" \/>\n<meta property=\"og:description\" content=\"March 15, 2026 \u2014 Abstractions Lab announces the joint release of IDPS-ESCAPE v0.7 and v0.8. Together, these two releases represent [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/\" \/>\n<meta property=\"og:site_name\" content=\"Abstractions Lab\" \/>\n<meta property=\"article:published_time\" content=\"2026-03-15T12:55:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-03-17T10:08:43+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2024\/09\/1D1B2_LOG_IDPS-ESCAPE_v1.0-1-150x150.png\" \/>\n<meta name=\"author\" content=\"Arash\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Arash\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/\"},\"author\":{\"name\":\"Arash\",\"@id\":\"https:\/\/abstractionslab.com\/#\/schema\/person\/10b4b9712018e5e507e00132a88e77ac\"},\"headline\":\"IDPS-ESCAPE (V0.7 + V0.8): SONAR, DECIPHER CTI, RADAR risk engine\",\"datePublished\":\"2026-03-15T12:55:00+00:00\",\"dateModified\":\"2026-03-17T10:08:43+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/\"},\"wordCount\":723,\"publisher\":{\"@id\":\"https:\/\/abstractionslab.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2024\/09\/1D1B2_LOG_IDPS-ESCAPE_v1.0-1-150x150.png\",\"keywords\":[\"software-release\"],\"articleSection\":[\"CyFORT\",\"IDPS-ESCAPE\"],\"inLanguage\":\"en-GB\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/\",\"url\":\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/\",\"name\":\"IDPS-ESCAPE (V0.7 + V0.8): SONAR, DECIPHER CTI, RADAR risk engine - Abstractions Lab\",\"isPartOf\":{\"@id\":\"https:\/\/abstractionslab.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2024\/09\/1D1B2_LOG_IDPS-ESCAPE_v1.0-1-150x150.png\",\"datePublished\":\"2026-03-15T12:55:00+00:00\",\"dateModified\":\"2026-03-17T10:08:43+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/#primaryimage\",\"url\":\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2024\/09\/1D1B2_LOG_IDPS-ESCAPE_v1.0-1.png\",\"contentUrl\":\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2024\/09\/1D1B2_LOG_IDPS-ESCAPE_v1.0-1.png\",\"width\":1024,\"height\":1024},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/abstractionslab.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"IDPS-ESCAPE (V0.7 + V0.8): SONAR, DECIPHER CTI, RADAR risk engine\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/abstractionslab.com\/#website\",\"url\":\"https:\/\/abstractionslab.com\/\",\"name\":\"Abstractions Lab\",\"description\":\"Verifiably secure digital solutions built upon solid mathematical foundations\",\"publisher\":{\"@id\":\"https:\/\/abstractionslab.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/abstractionslab.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/abstractionslab.com\/#organization\",\"name\":\"itrust Abstractions Lab\",\"url\":\"https:\/\/abstractionslab.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/abstractionslab.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2025\/02\/3A1_LOG_AbstractionsLab_v2.0.png\",\"contentUrl\":\"https:\/\/abstractionslab.com\/wp-content\/uploads\/2025\/02\/3A1_LOG_AbstractionsLab_v2.0.png\",\"width\":1200,\"height\":600,\"caption\":\"itrust Abstractions Lab\"},\"image\":{\"@id\":\"https:\/\/abstractionslab.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/github.com\/AbstractionsLab\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/abstractionslab.com\/#\/schema\/person\/10b4b9712018e5e507e00132a88e77ac\",\"name\":\"Arash\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/secure.gravatar.com\/avatar\/3e21649c41f8d3255f9aff1106db20563cc93deb3fbc49d9333921d0d780b2a0?s=96&d=mm&r=g\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/3e21649c41f8d3255f9aff1106db20563cc93deb3fbc49d9333921d0d780b2a0?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/3e21649c41f8d3255f9aff1106db20563cc93deb3fbc49d9333921d0d780b2a0?s=96&d=mm&r=g\",\"caption\":\"Arash\"},\"url\":\"https:\/\/abstractionslab.com\/index.php\/author\/arash\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"IDPS-ESCAPE (V0.7 + V0.8): SONAR, DECIPHER CTI, RADAR risk engine - Abstractions Lab","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/","og_locale":"en_GB","og_type":"article","og_title":"IDPS-ESCAPE (V0.7 + V0.8): SONAR, DECIPHER CTI, RADAR risk engine - Abstractions Lab","og_description":"March 15, 2026 \u2014 Abstractions Lab announces the joint release of IDPS-ESCAPE v0.7 and v0.8. Together, these two releases represent [&hellip;]","og_url":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/","og_site_name":"Abstractions Lab","article_published_time":"2026-03-15T12:55:00+00:00","article_modified_time":"2026-03-17T10:08:43+00:00","og_image":[{"url":"https:\/\/abstractionslab.com\/wp-content\/uploads\/2024\/09\/1D1B2_LOG_IDPS-ESCAPE_v1.0-1-150x150.png","type":"","width":"","height":""}],"author":"Arash","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Arash","Estimated reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/#article","isPartOf":{"@id":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/"},"author":{"name":"Arash","@id":"https:\/\/abstractionslab.com\/#\/schema\/person\/10b4b9712018e5e507e00132a88e77ac"},"headline":"IDPS-ESCAPE (V0.7 + V0.8): SONAR, DECIPHER CTI, RADAR risk engine","datePublished":"2026-03-15T12:55:00+00:00","dateModified":"2026-03-17T10:08:43+00:00","mainEntityOfPage":{"@id":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/"},"wordCount":723,"publisher":{"@id":"https:\/\/abstractionslab.com\/#organization"},"image":{"@id":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/#primaryimage"},"thumbnailUrl":"https:\/\/abstractionslab.com\/wp-content\/uploads\/2024\/09\/1D1B2_LOG_IDPS-ESCAPE_v1.0-1-150x150.png","keywords":["software-release"],"articleSection":["CyFORT","IDPS-ESCAPE"],"inLanguage":"en-GB"},{"@type":"WebPage","@id":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/","url":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/","name":"IDPS-ESCAPE (V0.7 + V0.8): SONAR, DECIPHER CTI, RADAR risk engine - Abstractions Lab","isPartOf":{"@id":"https:\/\/abstractionslab.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/#primaryimage"},"image":{"@id":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/#primaryimage"},"thumbnailUrl":"https:\/\/abstractionslab.com\/wp-content\/uploads\/2024\/09\/1D1B2_LOG_IDPS-ESCAPE_v1.0-1-150x150.png","datePublished":"2026-03-15T12:55:00+00:00","dateModified":"2026-03-17T10:08:43+00:00","breadcrumb":{"@id":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/#primaryimage","url":"https:\/\/abstractionslab.com\/wp-content\/uploads\/2024\/09\/1D1B2_LOG_IDPS-ESCAPE_v1.0-1.png","contentUrl":"https:\/\/abstractionslab.com\/wp-content\/uploads\/2024\/09\/1D1B2_LOG_IDPS-ESCAPE_v1.0-1.png","width":1024,"height":1024},{"@type":"BreadcrumbList","@id":"https:\/\/abstractionslab.com\/index.php\/2026\/03\/15\/idps-escape-v0-7-v0-8-sonar-anomaly-detection-decipher-cti-integration-risk-aware-automated-response-engine\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/abstractionslab.com\/"},{"@type":"ListItem","position":2,"name":"IDPS-ESCAPE (V0.7 + V0.8): SONAR, DECIPHER CTI, RADAR risk engine"}]},{"@type":"WebSite","@id":"https:\/\/abstractionslab.com\/#website","url":"https:\/\/abstractionslab.com\/","name":"Abstractions Lab","description":"Verifiably secure digital solutions built upon solid mathematical foundations","publisher":{"@id":"https:\/\/abstractionslab.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/abstractionslab.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/abstractionslab.com\/#organization","name":"itrust Abstractions Lab","url":"https:\/\/abstractionslab.com\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/abstractionslab.com\/#\/schema\/logo\/image\/","url":"https:\/\/abstractionslab.com\/wp-content\/uploads\/2025\/02\/3A1_LOG_AbstractionsLab_v2.0.png","contentUrl":"https:\/\/abstractionslab.com\/wp-content\/uploads\/2025\/02\/3A1_LOG_AbstractionsLab_v2.0.png","width":1200,"height":600,"caption":"itrust Abstractions Lab"},"image":{"@id":"https:\/\/abstractionslab.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/github.com\/AbstractionsLab"]},{"@type":"Person","@id":"https:\/\/abstractionslab.com\/#\/schema\/person\/10b4b9712018e5e507e00132a88e77ac","name":"Arash","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/secure.gravatar.com\/avatar\/3e21649c41f8d3255f9aff1106db20563cc93deb3fbc49d9333921d0d780b2a0?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/3e21649c41f8d3255f9aff1106db20563cc93deb3fbc49d9333921d0d780b2a0?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/3e21649c41f8d3255f9aff1106db20563cc93deb3fbc49d9333921d0d780b2a0?s=96&d=mm&r=g","caption":"Arash"},"url":"https:\/\/abstractionslab.com\/index.php\/author\/arash\/"}]}},"uagb_featured_image_src":{"full":false,"thumbnail":false,"medium":false,"medium_large":false,"large":false,"1536x1536":false,"2048x2048":false},"uagb_author_info":{"display_name":"Arash","author_link":"https:\/\/abstractionslab.com\/index.php\/author\/arash\/"},"uagb_comment_info":0,"uagb_excerpt":"March 15, 2026 \u2014 Abstractions Lab announces the joint release of IDPS-ESCAPE v0.7 and v0.8. Together, these two releases represent [&hellip;]","_links":{"self":[{"href":"https:\/\/abstractionslab.com\/index.php\/wp-json\/wp\/v2\/posts\/2176","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/abstractionslab.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/abstractionslab.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/abstractionslab.com\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/abstractionslab.com\/index.php\/wp-json\/wp\/v2\/comments?post=2176"}],"version-history":[{"count":22,"href":"https:\/\/abstractionslab.com\/index.php\/wp-json\/wp\/v2\/posts\/2176\/revisions"}],"predecessor-version":[{"id":2232,"href":"https:\/\/abstractionslab.com\/index.php\/wp-json\/wp\/v2\/posts\/2176\/revisions\/2232"}],"wp:attachment":[{"href":"https:\/\/abstractionslab.com\/index.php\/wp-json\/wp\/v2\/media?parent=2176"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/abstractionslab.com\/index.php\/wp-json\/wp\/v2\/categories?post=2176"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/abstractionslab.com\/index.php\/wp-json\/wp\/v2\/tags?post=2176"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}