# Adversarial Prediction

The prediction engine runs a small set of hypotheses against the rolling
event window. Each hypothesis can produce zero or more predictions. A
prediction is a claim about what the attacker will do next, with a
confidence score and a reason.

## The hypotheses

### 1. Secret-file ladder

    /.env       → /.git/config (0.82), /config.php (0.61), /backup.zip (0.55)
    /backup.zip → /db.sql (0.72), /.git/config (0.58)
    /.git/config → /.git/HEAD (0.77), /backup.zip (0.49)

### 2. Recon → exploit escalation

    confidence = min(0.9, 0.45 + 0.15 × low_score_count)

### 3. Credential-stuffing cadence

    confidence = min(0.92, 0.5 + 0.1 × login_count)

### 4. Sequential ID enumeration

    confidence = 0.74 for the next ID, 0.61 for the one after

### 5. Cross-region coordination

    confidence = min(0.85, 0.4 + 0.08 × region_count)

## Prediction lifecycle

    made ────► standing ────► hit   (match arrives within 30s)
                    │
                    └────────► expired (no match within 30s)

The engine runs every 3 seconds. Standing predictions decay after 30
seconds if no matching event arrives. Hits are logged to `morph_log`.