Security command centre

Unidirectional, payload-blind detection across six threat classes — every alert kept with the exact evidence that raised it.

STREAMING LIVE Verifying chain…
ACTIVE ALERTS
0
● forensic records held
CRITICAL / HIGH
0
▲ priority for analyst
THROUGHPUT
0
↗ events / second
p95 LATENCY
—
◷ ingest → alert
STREAM LAG
0
≡ pending in queue

Alerts over time, by class

detection stream · newest right

Threat distribution

by class

Source → destination relationships

edge colour = threat class · width = alert volume

Confidence distribution

normalized detector score

Top source hosts

by alert volume

Correlated incidents

source-centric risk · multi-signal

Live detection feed

select an alert to inspect the exact detector evidence

Aggregate flow-CSV assessment

ThreatAnchor flowEvidence signalSeverityScore

Evaluator self-test

generate real attack traffic and watch the sensor observe it
idle
What this does. Each button sends genuine attack traffic across 10.99.0.0/24 — a veth pair captured by the same sensor that watches the public NIC. The enclave does not fabricate anything: it observes packets on an interface, runs the same detectors it runs on real intrusion traffic, and writes an alert only if the evidence crosses threshold. Every alert below was therefore derived from observed traffic, and the terminal prints what was sent next to what the sensor logged.

Read the terminal, not just the red badge. A flow is only emitted after it has been idle for 10s, so an alert cannot appear the instant a button is pressed. If a scenario reports no detection, the traffic really was sent and the sensor really did not classify it — the panel says so rather than showing a reassuring summary.
Live command output IDLE
Select a scenario above and press Run.

The output below is the real stdout of the command that generates the traffic,
streamed line by line.