Current implementation
Lab capability

Collector qualification and honeypot proof

Prove collection, parsing, detection, and blocking before rollout.

Collector Lab is the passive test harness for Sotiras collectors. It combines deterministic parser replay, controlled fixtures, live collector installation, and honeypot observations into repeatable qualification evidence.

The promise

Show that a collector installs, ingests, parses, classifies, maps, blocks when appropriate, and produces evidence that another reviewer can verify.

Designed for

Sotiras operators, developers, and reviewers qualifying collector behavior and release claims.

What it delivers

A focused surface with a specific job.

Parser replay

Run deterministic fixtures through supported parsers and verify expected classifications without live attack traffic.

Live collector proof

Install real agents in controlled targets and verify first evidence, asset mapping, health, and enforcement behavior.

Honeypot observations

Observe unsolicited hostile activity on lab services while retaining provenance and publication controls.

Qualification records

Preserve manifests, outcomes, freshness, reviewer approval, and evidence used by customer-readiness gates.

How the work flows

From intent to verifiable result.

  1. 01

    Select a collector

    Choose the parser, agent, service, platform, and expected evidence contract.

  2. 02

    Replay or deploy

    Use deterministic replay first, then install the collector on a bounded lab target when needed.

  3. 03

    Verify behavior

    Check ingestion, classification, asset mapping, enforcement, privacy, and failure handling.

  4. 04

    Qualify the proof

    Require fresh evidence and independent review before using it in a release-readiness claim.

Trust boundary

What this surface does not blur.

Collector Lab is a passive qualification and honeypot surface, not the Kali-style active assessment runner.

Synthetic fixtures, replay addresses, and controlled test traffic are never published as public threat intelligence.

Qualifying unsolicited hostile indicators may be promoted to Public CTI only under provenance, privacy, confidence, and publication policy.