Transfers
Source-controlled detections
Rule logic, ATT&CK mapping, status metadata, and review history are version-controlled and auditable.
A governed implementation model for AI-assisted detection engineering and security operations.
HawkinsOperations demonstrates a governed SOCaaS-style implementation model for AI-assisted detection engineering and security operations: detection work, telemetry confidence, validation, case packets, support-only AI triage, human review, and proof-controlled reporting.
Public inspection layer
SOC workflow
Each stage owns a distinct truth. AI supports labor; verifiers gate evidence; humans authorize claims.
Source-controlled rules + ATT&CK context
Detection source, rule logic, status metadata, and ATT&CK-aligned context live in the detections repo. Reviewable in plain text, version-controlled, mappable.
Route contracts + visibility evidence
Telemetry routes and contracts are treated as visibility or private/internal evidence. Public-safe runtime/signal status requires a separate promotion gate.
Deterministic verifiers + controlled fixtures
Controlled-test validation packages and fixtures support controlled validation claims. Verifiers fail closed; no runtime promotion happens here.
Case packets, support gates, blocked actions
Case-packet schemas and samples model analyst support, response gates, and blocked actions. Mutation, closure, and disposition authority stay outside the contract.
Sanitized summaries + missing context
AI may summarize sanitized facts and call out missing context. It does not decide disposition, close cases, approve actions, or promote proof.
Visible reviewer + MERGE_APPROVED
Visible human review is the authority layer. AI is below human review; CI is below human review; momentum is below human review.
Reviewer packets at the current ceiling
Proof Pack 001 and proof records route reviewer claims under the current ceiling. Website rendering remains a route to proof, not proof itself.
Detection to proof
A repo-visible loop reviewers can trace end-to-end. Runtime, signal, and production promotion sit outside this loop on purpose.
Source rule + ATT&CK context in detections repo.
Controlled fixtures + deterministic verifier pass.
SOAR-shaped case structure with support-only AI fields.
Schema, claim-boundary, and parity gates fail closed.
Proof record / card under the current ceiling.
Website route + reviewer packet to the bounded truth.
Public claim boundary stops at the reviewer surface. Runtime / signal / production / customer / fleet promotion requires separate gates.
Claim ladder
Controlled validation is real. Public runtime proof is not promoted until a separate evidence and approval gate fires.
Validation packages, controlled fixtures, and deterministic verifiers run on every PR. This is the strongest publicly supported tier.
Runtime contracts, truth-spine schemas, and case-packet structures exist in source. Initialization is repo-visible.
Private runtime support is acknowledged in boundary docs (e.g. RS003 Cribl route marker). Evidence stays private; public-safe status remains BLOCKED_PENDING_REVIEW.
Mirrored visibility, Zeek packets, and other observation surfaces exist privately. They are not promoted into public NDR, Suricata, or cross-source proof.
Public runtime, signal-observed, or public-safe runtime claims remain blocked. They require separate capture, verifier, checklist, and human approval gates.
Production-ready, customer-validated, partner-endorsed, and fleet-wide claims are not made anywhere on this surface.
Transferable model
Each item is repo-visible discipline that maps to real security operations work without requiring HawkinsOperations infrastructure.
Transfers
Rule logic, ATT&CK mapping, status metadata, and review history are version-controlled and auditable.
Transfers
Validation packages, schema checks, and claim-boundary scanners fail closed before merge.
Transfers
SOAR-shaped case packets with support-only AI fields, blocked actions, and dry-run defaults.
Transfers
Visible human review sits above CI, above AI output, above implementation momentum.
Transfers
Scanners, record boundaries, and record-is-not-rendering rules keep public copy below evidence ceilings.
Transfers
The public-facing Governance Saves subset models what controls fired looks like across merge, claim, runtime, evidence, and validator surfaces.
Evidence routes
Start with the strongest bounded reviewer package, then inspect detections, validation, and Governance Saves.
HAWKINSOPERATIONS_PROOF_PACK_001 routes a bounded HO-DET-001 reviewer package at CONTROLLED_TEST_VALIDATED.
Inspect pathOpen routePublic-facing subset: what was blocked, what control fired, why it matters.
Inspect pathOpen routeDetection portfolio, validation status, ATT&CK mapping, and proof boundaries.
Inspect pathOpen route8 controlled-test validation packages and 85 fixtures with blocked runtime / signal states.
Inspect pathClaim ceiling
HawkinsOperations is not presented as a production SOCaaS platform.
Customer validation, partner endorsement, and live enterprise deployment are not claimed.
Runtime-active public proof and public signal-observed proof remain blocked unless separately proven and approved.
AI-approved disposition, autonomous SOC, and analyst-approved-by-AI wording remain blocked.
Repos
Clone-runnable route through all six repos without private runtime access.
Inspect pathOpen routeObserved checks, report-only controls, and website rendering boundaries.
Inspect pathOpen routeBounded reviewer status and plan emitter; platform visibility, not proof promotion.
Inspect path