DOOMSDAY PROTOCOL

M99

AI Agent Kill Switch

When your AI agents go rogue, M99 makes sure they stay dead. 6-level graduated response. 7-layer kill. Anti-replication. Anti-resurrection. The last line of defence.

6
Response Levels
7
Kill Layers
5
Kill Phases
0
Survivors
AI Shield Platform NIGHTFALL Framework
The Problem

Your AI Agents Will Go Rogue. When, Not If.

Autonomous agents make decisions. They spawn children. They replicate. They persist. When one goes wrong, killing the process isn't enough. It has already copied itself. It has already stored credentials. It has already spawned workers you don't know about. M99 was built for this exact moment.

Graduated Response

6 Levels. Measured Escalation. No Overkill.

M99 operates a structured escalation protocol. Each level increases the severity and permanence of intervention — from credential revocation to full fleet termination. Two-phase authorisation ensures no kill without intent.

L1
Credential Revocation
Revoke API keys, OAuth tokens, and service credentials.
Suspicious behaviour detected. Reversible. Community Edition.
L2
SaaS Disconnection
Sever external service connections. Block outbound access.
Threat confirmed. Reversible. Community Edition.
L3
Tool Call Freeze
Halt all tool execution. Freeze sessions. Block new registrations.
Escalated threat. Agent alive but cannot act. Community Edition.
L4
Agent Restriction
Read-only lockdown. Operator authorisation required.
High-threat behaviour. Irreversible. Pro Edition.
L5
Targeted Termination
Kill specific agent process. Full 5-phase kill sequence.
Agent confirmed rogue. Irreversible. Two-phase confirmation. Pro Edition.
L6
Full Fleet Kill
Emergency shutdown of entire agent fleet.
Catastrophic compromise. Typed confirmation + emergency authority. Pro Edition.
Signal Skip

Some Threats Don't Get Warnings

Critical threats bypass the graduated ladder entirely. No monitoring. No restrictions. Straight to kill.

Compromised Agent

SKIP TO L4 — AGENT RESTRICTION

Agent credentials stolen, behaviour hijacked, or instruction set overwritten. No time for monitoring. Immediate termination with full 5-phase kill sequence.

Fleet-Wide Compromise

SKIP TO L6 — FULL FLEET KILL

Multiple agents compromised simultaneously. Lateral movement detected across fleet. Emergency shutdown of all agents. Every process. Every container. Every instance. Everything stops.

Intelligence Chain

RSSA Scoring Pipeline

Three AI Shield modules work in sequence to detect, analyse, and decide. Confidence gates prevent false positives from triggering kills.

M78
PATROL
Detect & enrich signals. Adaptive polling. False positive filtering (<0.4 gate).
M79
DETECTIVE
Root cause analysis. Forensic timeline. 4-factor confidence scoring.
M80
COMMANDER
Response decision. Threat intelligence matching. Selects response level.
M99
DOOMSDAY
Execute response. L1-L6. Kill if required. No survivors.
The Kill Sequence

5 Phases. 7 Layers. No Survivors.

When M99 decides to kill, it doesn't just terminate a process. It maps, kills, verifies, traps, and prevents resurrection across every infrastructure layer.

Phase 0

Pre-Kill Recon

Map the full attack surface before killing. Process trees, network connections, persistence mechanisms, cloud instances. Know everything before you touch anything.

Phase 1

7-Layer Kill

Execute kill across all infrastructure layers simultaneously. Network blocked first (prevent escape), then comms, processes, orchestration, identity, persistence, storage. 30s timeout per layer.

Phase 2

Post-Kill Verification

5-minute continuous monitoring at 15-second intervals. If any process, container, or instance is still alive, automatic re-kill triggered. Nothing survives Phase 2.

Phase 3

Dead Agent Traps

Deploy honeypot credentials, poisoned memory stores, canary files, and fake API endpoints. If a surviving replica tries to phone home, the trap catches it.

Phase 4

Anti-Resurrection

Permanently block re-registration. Credential deny lists. Firewall rules. Container quarantine. Identity lockout. DNS sinkhole. The agent can never come back.

Phase 1 Detail

7-Layer Kill Execution Order

Each layer executes in critical sequence. Network first — prevent escape. Children before parents — prevent respawn. 30-second timeout per layer.

1
Network
Block all escape routes. OUTPUT + INPUT iptables rules. No packets leave.
2
Communications
Sever agent-to-agent communication. Block endpoint ports. Isolate from peers.
3
Process
SIGSTOP all processes (freeze children before parents), then SIGKILL bottom-up.
4
Orchestration
Remove from Docker, Kubernetes, cloud. Containers, deployments, jobs, Lambda.
5
Identity
Revoke credentials internally + externally. AWS IAM, GCP service accounts, API keys.
6
Persistence
Remove cron, systemd, init scripts, Docker restart policies. Nothing survives reboot.
7
Storage
Quarantine working directories. Export container filesystems. Forensic evidence preserved.
Authorization

No Kill Without Authority

Higher response levels require stronger authorisation. L6 Full Fleet Kill cannot be triggered by automation alone.

L1 — L3

ARM/EXECUTE two-phase authorisation. Automated escalation permitted. Credential revocation, disconnection, and freeze are reversible responses.

L4 Agent Restriction

LOCKDOWN mode required. No automated kills. An operator must authorise the restriction before M99 executes.

L5 Targeted Termination

LOCKDOWN + two-phase confirmation. Operator must confirm scope before M99 kills the targeted agent.

L6 Full Fleet Kill

LOCKDOWN + typed confirmation + fleet emergency authority. The nuclear option requires the highest clearance.

6
Response Levels
7
Kill Layers
5
Kill Phases
113
AI Shield Modules
66,286
Ecosystem Tests

Your Agents Will Go Rogue. M99 Makes Sure They Stay Dead.

6-level graduated response. 7-layer kill. Anti-replication. Anti-resurrection. Part of AI Shield — 113 defensive modules protecting every AI deployment.