SecOps Center
Decoy services (SSH · HTTP · DB · file-share) and honeytokens (AWS keys · DB rows · canary URLs) that scream the moment anyone touches them. Zero false positives by design — anyone interacting with a decoy is confirmed malicious.
Until the deploy layer ships, the “armed decoys” you see referenced in the Deception & Hunt Pack tabs reflect design state, not live listeners in your VPC. We won’t ship a fake “Deploy Honeypot” button that mutates ephemeral server-side state and pretends to stand up real infra.
Continuously-run hunt packs (LOLBAS execution, ETW-tamper / event-log-clear, Sysmon baseline, nightly persistence sweep) that are git-versioned, ATT&CK-tagged, and CI-tested against real fleet telemetry.
No fleet-scale endpoint telemetry is ingested today, so there is nothing real to hunt across. We won't show fabricated rule-hit counts, host counts, or event volumes against an ingest pipeline that doesn't exist yet.
An OCSF-normalised data lake, universal streaming ingest (EDR, cloud-audit, identity, network, app-access, container-runtime), and a unified correlation graph that collapses many alerts into one scored incident.
Today's live signal correlation happens in the Correlator/Autopilot shield on real bus topics — see the Incidents view. This tab described a much larger always-on data-lake platform that isn't built. We won't show fake events/sec, fake node/edge counts, or fake ATT&CK coverage % for a lake that doesn't exist.
Deeper autonomous-response playbooks with human-in-the-loop tiers (L1 auto-execute, L2 propose-approve, L3 review-only) — disable-user, isolate-host, and kill-token/rotate-secret flows with step-by-step rollback and live run counts.
The SOAR Playbooks tab lists real playbooks from /api/v1/modules/secops/playbooks and lets you execute them — that part is live. This tab described richer per-playbook analytics (run counts, approval rates, mean-time-to-contain) that no backend produces yet. We won't fabricate run counts or approval rates.
Canary tokens embedded in CI-runner secrets and decoy subdomains (dev-old., staging-backup., admin-legacy.) that trip the moment anyone touches them, plus a tarpit for confirmed scanners.
This overlaps with the Honeypot tab's roadmap — same underlying deploy layer, not yet in your VPC. See the Honeypot tab for the full status. We won't show fabricated "ARMED" canaries or scan-hit counts for decoys that don't exist.
An in-perimeter AI copilot for analysts: alert triage/clustering, natural-language hunt queries, "why did this fire" explanations, drafted comms/reports (human-reviewed before send), and a full audit log of every tool call — with hard blocks on model-autonomous destructive actions.
Nothing here is wired to a model or a data source today — there is no instant-response analyst copilot in production. It depends on the detection core and hunt packs above shipping first. We won't fabricate throughput multipliers, query counts, or tool-call logs for a copilot that doesn't exist.