Authorized active validation
Prove that protection works against controlled attack progression.
ProtectTheBox runs bounded, authorized security validation against a customer-controlled target. It connects preflight, execution, detection, enforcement, rollback, and customer-readable proof.
The promise
Test the system safely, see what detected and blocked the activity, identify remaining exposure, and preserve proof of teardown.
Designed for
Customers and Sotiras operators validating a collector and defensive controls in an approved scope.
What it delivers
A focused surface with a specific job.
Scoped requests
Record the target, source networks, time window, permitted techniques, exclusions, and enforcement mode.
Operator preflight
Require target ownership, authorization, telemetry readiness, source allowlisting, and rollback controls before launch.
Kali-style assessment runner
Use an isolated runner for approved scenarios without turning the customer portal into a general attack console.
Proof and recovery
Report detection, attacker friction, remaining exposure, durable fixes, cleanup, and independent qualification evidence.
How the work flows
From intent to verifiable result.
- 01
Request and authorize
Define a customer target and obtain explicit approval for a bounded scenario.
- 02
Preflight
Prove telemetry, source, window, runner, emergency stop, and rollback readiness.
- 03
Run and observe
Launch approved activity and correlate it with collector, detection, and enforcement evidence.
- 04
Teardown and report
Stop the runner, verify cleanup, record gaps, and deliver customer-readable proof.
Trust boundary
What this surface does not blur.
ProtectTheBox is active validation and always requires explicit customer scope and authorization.
Current live execution is support-assisted; the public page does not claim unrestricted self-service penetration testing.
Runner IPs, target IPs, and controlled attack observations remain tenant-private and never seed Public CTI.
Explore the system