is
- containment-first observation
- disposable sandbox plus separate sink
- encrypted, provenance-oriented evidence
- a review-gated pilot foundation
prototype / demo
DetCordon places a disposable victim behind a DetectionOnly HTTP tap. Events and encrypted samples leave the sandbox for an audited sink on a separate host.
No production or formal sandbox-escape assurance is claimed.
current system
The DetectionOnly tap records request metadata while the hostile interaction continues.
The victim runs in time-boxed Docker or Firecracker isolation with default-drop egress.
Telemetry and sample uploads use distinct channels. Bodies do not travel in event records.
The sink computes SHA-256, age-encrypts samples, audits writes, and emits offline-verifiable bundles.
operating boundaries
Containment depends on live-host configuration, kernel isolation, physical sink separation, and operator discipline. Those remain part of every deployment review.
diligence trail
A finding closes only when implementation enforces the boundary, a regression proves rejection, and generated defaults agree. Current status belongs in the repository register, not a static marketing number.
managed pilot
A useful pilot defines workload class, evidence retention, analyst access, success criteria, and remediation gates before hostile workloads are introduced.
Prefer email? sales@ragbaz.cc