ACTIVE ALERTS
0
● forensic records held
Unidirectional, payload-blind detection across six threat classes — every alert kept with the exact evidence that raised it.
10.99.0.0/24 — a veth pair captured by the same sensor that watches the public
NIC. The enclave does not fabricate anything: it observes packets on an interface, runs the
same detectors it runs on real intrusion traffic, and writes an alert only if the evidence
crosses threshold. Every alert below was therefore derived from observed traffic, and
the terminal prints what was sent next to what the sensor logged.
10s, so an alert cannot appear the instant a button is pressed. If a
scenario reports no detection, the traffic really was sent and the sensor really did not
classify it — the panel says so rather than showing a reassuring summary.
Select a scenario above and press Run. The output below is the real stdout of the command that generates the traffic, streamed line by line.