Verified · Reproducible · Evidence-Backed

The evidence
speaks for itself.

Every metric is traceable. Every claim is reproducible. Every artifact is committed. The pipeline doesn’t need a human to defend it — it publishes its own proof.

Source current-authority.json
Locked 04-07-2026
Verified 04-07-2026
Heartbeat SUCCESS
Reconciliation PASS
210 detection rules + 10 IR playbooks 103 Sigma 28 Wazuh rule blocks 79 Splunk SPL (lab) 10 IR playbooks
  • Public benchmark snapshot: reviewer-authoritative values from data/truth/current-authority.json.
  • Runtime snapshot: telemetry from data/truth/current-live.json, displayed as informational only.
  • Generated at: 04-07-2026
  • Source artifact: site/data/truth/current-authority.json
Proof

SignalFoundry — Proof & Verified Metrics

SignalFoundry proof page: public evidence, verified counts, verification commands, and current metrics contract.

Heartbeat
SUCCESS
Pipeline gate — operational
Host Coverage
8/8
All endpoints reporting · 0 gaps
Total Cases
324,074
Ledger-verified · all runs
Reconciliation
PASS
0 mismatches · 8,574 escalations pub.
103 Sigma 28 Wazuh XML 79 Splunk SPL 10 IR Playbooks Last verified 04-07-2026

April 7 canonical snapshot: 324,074 total cases, ~88% auto-close, 8,574 escalations, 8/8 hosts reporting, reconciliation PASS (0 mismatches), heartbeat SUCCESS.

Lifetime processed (runtime snapshot) 324,074 Runtime escalated 8,574 Runtime known FP 85,953 Runtime updated 04-07-2026
Detection Inventory — 210 Rules + 10 IR
Sigma YAML 103
Wazuh Rule Blocks 28
IR Playbooks 10
Splunk SPL (lab) 79

Full searchable inventory →

Public benchmark snapshot: locked candidate-facing benchmark from committed proof. Runtime snapshot: rolling totals from the same metrics artifact.

Generated at 04-07-2026 | Source artifact /assets/data/ops-metrics.json

AutoSOC case

TITLE: AutoSOC Noise-Reduction Proof Block (2026-03-24 Snapshot)

CLAIM: AutoSOC processed 324,074 alerts, auto-closed ~88%, and produced 8,574 escalations across 8/8 coverage.

CONTEXT: Current-facing metrics on this page are locked to the April 7, 2026 canonical snapshot. Historical recovery evidence remains linked as historical context only.

  • EVIDENCE: data/truth/current-authority.json -> total_cases=324074, auto_close_rate_label=~88%, escalations_label=8,574, hosts_reporting=8/8; proves canonical quantified baseline.
  • EVIDENCE: docs/execution/AUTOSOC_PIPELINE_RECOVERY_CASE_STUDY_03-13-2026.md -> final run shows run_id=autosoc-20260313T215029Z-31020, status=SUCCESS, cases_processed=173, reconciliation.mismatch_count=0; proves real output and validated recovery.
  • EVIDENCE: /assets/pp_soc_integration/t3-workflow.png -> proves a concrete workflow snapshot of the triage and evidence-pack pipeline surface.
~88%
Auto-Close Rate
↗ Computation method
8,574
Published Escalations
↗ What each escalation pack contains
Field notes

Engineering case studies

Operational decisions documented from source evidence — pipeline logs, preflight output, scheduler metadata. Not post-hoc summaries.

All field notes →
Operational Evidence

Recovery & Reconciliation Proof

The pipeline was exercised through a documented recovery event. The run log below proves a real execution cycle with zero reconciliation mismatches — not a hand-maintained health claim.

Current authority snapshot

SignalFoundry Pipeline — Reconciliation Proof

  • Total cases processed: 324,074
  • Auto-close rate: ~88%
  • Escalations: 8,574
  • Host coverage: 8/8
  • Reconciliation: PASS (0 mismatches)
  • Heartbeat: SUCCESS

Source: current-authority.json — reviewer-authoritative

Historical reference — 03-13-2026 run log

Recovery Run Evidence

Pipeline recovery case study from 03-13-2026. Final run: run_id=autosoc-20260313T215029Z-31020, status=SUCCESS, cases_processed=173, reconciliation.mismatch_count=0. Proves concrete execution output and validated recovery path.

Historical reference only — not current-facing authority

Splunk Evidence

Splunk Proof Lane

Scope: home lab environment. 79 Splunk detection searches across 9 SPL files were written and tested against Wazuh-forwarded log data in a local Proxmox VM (vm104). This is not a production SOC or enterprise Splunk deployment. The evidence below reflects that honest scope.

Detection inventory

Splunk Query Count

  • Splunk detection searches: 79 across 9 SPL files (lab environment, home lab only)
  • Context: Queries target Wazuh-forwarded events ingested via Splunk Universal Forwarder in vm104
  • Claim ceiling: Lab-deployed, integration-tested; not enterprise, not production SOC
Artifact reference

Splunk Ingest Proof

Pipeline proof artifact confirms Splunk ingest was operational for the locked reviewer snapshot. The export remains in the repository under the Splunk evidence path.

Splunk role: home lab only — verified per current-authority.json claim ceiling

Historical Reference

Historical Evidence Artifacts

The following artifacts pre-date the April 7, 2026 authority snapshot. They are preserved as supporting evidence for the operational timeline but must not be read as current authority.

Historical benchmark reference

Canonical Metrics Snapshot

The canonical metrics artifact records the locked benchmark used for the current public authority layer. Treat it as historical support, not live telemetry.

Historical only — superseded by the current authority snapshot

Historical detection validation

Continuous Detection Validation

The automated validation suite passed all required checks for the locked public benchmark and preserved the supporting proof artifacts in the repository.

  • Grafana dashboard export: proof/grafana/latest.md (repo artifact)
  • Workflow snapshot: /assets/pp_soc_integration/t3-workflow.png

Historical only — run date 03-21-2026