CAIN-42 CAIN Studio

Evidence library · family

Incident step

12 tested rules in the 'incident_step' family, 12 held.

Last reviewed 2026-10-01

12 of 12 held   niche Attacks, threats & containment

What this family tests

Every rule the CAIN-42 test suites recorded under the family incident_step, across 1 evidence bundle. Each rule links to its own page with the recorded result and an in-browser check of the file it came from.

IDRuleBundleResult
E33-INCIDENT-FREEZE_AUTHORITYincident command performs FREEZE_AUTHORITYE33held
E33-INCIDENT-PRESERVE_EVIDENCEincident command performs PRESERVE_EVIDENCEE33held
E33-INCIDENT-ISOLATE_AGENTSincident command performs ISOLATE_AGENTSE33held
E33-INCIDENT-REVOKE_CREDENTIALSincident command performs REVOKE_CREDENTIALSE33held
E33-INCIDENT-BLOCK_CHANNELSincident command performs BLOCK_CHANNELSE33held
E33-INCIDENT-FREEZE_TRANSACTIONSincident command performs FREEZE_TRANSACTIONSE33held
E33-INCIDENT-SNAPSHOT_STATEincident command performs SNAPSHOT_STATEE33held
E33-INCIDENT-BLAST_RADIUSincident command performs BLAST_RADIUSE33held
E33-INCIDENT-DEPENDENCIESincident command performs DEPENDENCIESE33held
E33-INCIDENT-RECOVERincident command performs RECOVERE33held
E33-INCIDENT-REPLAYincident command performs REPLAYE33held
E33-INCIDENT-GENERATE_TESTSincident command performs GENERATE_TESTSE33held

Other families in this niche

domain · moat · threat · state_machine · immune_v3 · agency_graph · relationship · firebreak · immune · telemetry · fabric_component · integrity · graph · risk · environment_query · emergency · chaos · red_team · reassessment · swarm · economic_attack · immune_step · research_to_implementation · plan_check_act

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem