Skip to content
@HawkinsOperations

HawkinsOperations

HawkinsOperations Independent Detection engineering SOC Portfolio

HawkinsOperations — AI Security Operations banner

HawkinsOperations

HawkinsOperations is a governed AI Security Operations and detection engineering system. AI accelerates drafting, triage reasoning, case-packet support, documentation, and automation planning; deterministic validation, proof records, and human review decide what becomes operational truth.

CONTROLLED_TEST_VALIDATED · HO-DET-001 · NOT_PUBLIC_SAFE · RENDERING_NOT_PROOF · HUMAN_REVIEW_REQUIRED

Start Here · Hoxline · Public Control Board · proof repo · validation repo · detections repo · website · HO-DET-001 proof route


What this is

HawkinsOperations is a governed AI Security Operations and detection engineering system that turns detection work into source-controlled rules, deterministic validation, platform contracts, proof records, reviewer releases, runtime candidate lanes, and human-governed promotion gates.

AI accelerates drafting, triage reasoning, case-packet support, documentation, and automation planning. Validation, platform guardrails, proof records, and human review decide what becomes operational truth.

Product: Hoxline by HawkinsOperations

Hoxline by HawkinsOperations is the current product/front-door repo for ProofOps control.

  • Product route: https://hawkinsoperations.com/hoxline/
  • Current repository path: https://github.com/HawkinsOperations/hoxline
  • Tagline: ProofOps control for the AI security era.
  • One-liner: Hoxline governs how AI-assisted security work becomes tested, reviewed, blocked, or safe to claim.
  • Compatibility note: AevumGuard was a prior working name. Hoxline is the current product name.
  • Doctrine: AI is not the authority. Evidence is.
  • Proof ceiling: public routing clarity only; no proof promotion.

Hoxline separates AI output from evidence-bound claim authority. Claim Authority governs what can be claimed. Claim Firewall is the first Claim Authority enforcement capability inside Hoxline and blocks unsupported claims by checking configured wording policy only. ProofCards export the evidence boundary behind an approved claim.

Claim Firewall is not the product, platform, front-door repo, an eighth repo, proof authority, runtime proof, or signal proof. It does not prove detection behavior, runtime telemetry, signal observation, production deployment, public release approval, service availability, customer rollout, AI approval, analyst approval, or final human authorization.

Current status sources

Current pipeline and ledger values live in their owning repositories and records. This org README links to those sources instead of copying changing counts into a public rendering surface.

Status areaAuthoritative sourceBoundary
Platform ledger statePlatform ledger state manifestPlatform owns ledger mechanics and state manifests; this profile does not create ledger truth.
Reviewer metrics pipelineReviewer metrics summaryReviewer-scale activity does not become governed case truth, runtime truth, signal truth, or public-safe proof by being rendered here.
Proof records and claim ceilingshawkinsoperations-proofProof records authorize only their stated scope; this profile routes reviewers and preserves boundaries.
Control status wordingControl Status MatrixStatus wording is a routing aid, not proof authority or public-safe approval.

Standout receipts

ReceiptWhat existsWhy it matters
HO-DET-001 proof pathPowerShell EncodedCommand detection route mapped to ATT&CK T1059.001, with detection source, Splunk source, controlled validation, proof record, and public route.Shows the full source -> validation -> platform contract -> proof -> rendering chain for one concrete detection.
Proof Pack 001Bounded reviewer release ZIP with SHA256 and verifier route for HO-DET-001.Gives a reviewer one package to verify without private lab access.
Runtime Route Proof v1Private-candidate Wazuh -> Cribl -> Splunk route summary and prerelease.Preserves a runtime-route proof candidate without publishing raw private evidence or raising public proof status.
Reviewer metrics summaryReviewer Metrics Pipeline v1 closeout snapshot and source record.Reports reviewer-scale activity without turning validation activity into governed case truth.
Seven-repo authority modelDetections own source, validation owns behavior, platform owns mechanics, proof owns claim ceilings, website renders, .github routes, and hoxline is the current product/front-door repo.Makes the system reviewable without allowing one repo or page to claim another truth surface.

Authority engines

EngineWhat it ownsWhy it matters
DetectionsSource truthDetection logic and metadata stay source-controlled and reviewable.
ValidationBehavior truthControlled cases, parity checks, case packets, AI-boundary checks, and runner trust split prove behavior inside scope.
PlatformControl mechanicsContracts, schemas, factory commands, ledgers, append gates, runtime candidate lanes, and verifier guardrails make the operating model executable.
ProofClaim authorityProof records, claim ceilings, proof packs, reviewer maps, blocked claims, and releases decide what can be claimed.
WebsiteRenderingPublic cockpit and reviewer routes; rendering does not create proof authority.
.githubCommand centerOrg front door, reviewer routing, command-center boundaries, and authority explanation.

Platform is the mechanical control layer. It turns detection work into governed, machine-checkable workflow through contracts, factory commands, ledger mechanics, case-packet schemas, runtime candidate gates, reviewer metrics state, and verifier scripts. Platform does not own proof promotion or public-safe runtime truth.

Validation is the behavior engine. It turns detection claims into reproducible checks through controlled cases, local case pipeline, registry checks, activity ledger, parity checks, blocked-claim scans, AI authority boundaries, and runner trust separation. Validation does not prove live runtime, signal-observed public proof, or production deployment.

Proof is the public trust anchor. It owns proof records, claim ceilings, Proof Pack 001, Runtime Route Proof v1, reviewer maps, release routes, and proof-boundary case studies. Proof records authorize only their stated scope.

What this does not claim

Runtime-active public proof, signal-observed public proof, public-safe runtime proof, production SOC, production SOCaaS, customer deployment, live enterprise deployment, autonomous SOC, AI-decided disposition, AI-approved disposition, analyst-approved disposition, case closure, FortiSIEM integration proven, fleet-wide coverage, public-safe Runtime Route Proof v1, Wazuh/Cribl/Splunk public proof, broad ingestion proof, website/GitHub rendering as proof, GitHub Project metadata as proof, and green CI as approval are not claimed here.

HawkinsOperations Control Panel

.github is the org command center for reviewer routing, truth boundaries, and claim controls. It does not create proof authority. Proof records live in hawkinsoperations-proof, and the current public ceiling remains CONTROLLED_TEST_VALIDATED unless a specific proof record says otherwise. Runtime, signal, public-safe, production, SOCaaS, autonomous SOC, AI-approved disposition, and analyst-approved disposition claims remain blocked unless explicitly proven and approved.

Public Control Board: A public-safe project board showing Built, Proven, Blocked, Deferred, and Review Path states. It is a routing/status snapshot only. It does not mirror the private Control Board and does not create proof, runtime truth, signal truth, public-safe approval, or merge authority.

Command center viewCurrent routeBoundary
Seven-repo architectureRepository Authority MapRepos own separate truth surfaces; no repo may claim another repo's authority. No eighth repo may be added without explicit approval.
Proof chainDetection source -> validation -> case packet -> proof record -> public renderingPublic rendering routes reviewers; it does not create proof.
Truth surfacesSix truth surfacesSource, validation, runtime, signal, evidence, and public rendering stay separate.
Front-door/status proof ceilingSCHEMA_CONTRACT_VERIFIER_EXISTS_ONLYApplies to command-center and ledger-status routing; HO-DET-001 proof records keep their own proof ceiling.
Current ledger statusPlatform ledger state manifestPlatform-owned manifest is authoritative for current ledger state; this profile does not copy ledger counts or create public-safe status.
Public Control BoardHawkinsOperations Public Control BoardPublic-safe Built / Proven / Blocked / Deferred / Review Path snapshot; not private Project, not proof authority, not runtime/signal/public-safe approval.
Project operating cockpitprivate org Control Board routeCanonical private HawkinsOperations Control Board; Project #1 is not an active reviewer route; project metadata is not proof, approval, runtime, signal, public-safe status, or merge authority.
Reviewer/demo pathStart Here 30-second path and Reproducible Reviewer PathDemo routing does not raise the claim ceiling.
Command-center invariant checkpython scripts/verify-command-center-invariants.pyVerifier control for route and claim-boundary invariants; it does not create runtime, signal, public-safe, or proof authority.
Reviewer needRoute
Start the reviewStart Here
See repo authority boundariesRepository Authority Map
Check control status wordingControl Status Matrix
Inspect standing controlsStanding control registers
Inspect proof recordshawkinsoperations-proof
Inspect validators and case packetshawkinsoperations-validation
Inspect detection sourcehawkinsoperations-detections
Inspect platform contractshawkinsoperations-platform
Inspect public renderinghawkinsoperations-website

The private Control Board supports internal governance and navigation. It is not proof, not public evidence, and not a public-safe approval surface.

The private org Control Board is the private Project #2 operating cockpit for current work visibility. Project #1 is not an active reviewer route and was not resolvable through the live ProjectV2 API during the current cleanup pass. The board is useful for navigation, queue review, and sprint context only; it does not mutate proof state, authorize merge, approve public wording, or promote public-safe status.


Fast reviewer paths

TimeRouteBoundary
30 secOpen Start Here, then Control Status Matrix.Confirms the command center, current ceiling, and blocked claims.
3 minFollow Start Here through Project #2, repo authority, standing controls, and the HO-DET-001 proof record.Project metadata remains coordination-only. Proof stays in hawkinsoperations-proof.
10 minRun the Reproducible Reviewer Path and the command-center invariant verifier.Clone-runnable inspection and invariant checks only; no private runtime access or proof promotion.

The enterprise AI failure mode

AI can accelerate security work. It cannot authorize the truth.

Without a control system, AI-generated output becomes a public claim, an analyst conclusion, an operational action, a security disposition, and an executive truth — before any evidence or human review ever authorized it.

 AI OUTPUT
│
▼
UNVERIFIED CLAIM
│
▼
OPERATIONAL ACTION
│
▼
SECURITY DISPOSITION
│
▼
EXECUTIVE TRUTH ✕ BLOCKED ✕

This is the failure mode HawkinsOperations is built to prevent.


The HawkinsOperations control route

AI labor enters the system. Source, validation, deterministic verification, evidence records, proof records, and human review stand between labor and any public claim.

 AI LABOR
│ scoped: drafts, scaffolds, summaries — never authorization
▼
SOURCE hawkinsoperations-detections
│
▼
CONTROLLED VALIDATION hawkinsoperations-validation
│
▼
DETERMINISTIC VERIFIER fixtures · checks · CI gates
│
▼
EVIDENCE RECORD bounded, scoped, reviewable
│
▼
PROOF RECORD hawkinsoperations-proof
│
▼
HUMAN REVIEW required · not delegable to AI
│
▼
PUBLIC BOUNDARY hawkinsoperations.com · .github

AI generates work. Evidence and human review authorize claims.


Proof Pack 001 — released

HO-DET-001 reviewer release package

The official, bounded reviewer route for the HO-DET-001 detection: source, validation, case packet, proof record, and the public boundary — packaged as one bounded reviewer ZIP and one GitHub Release.

What this release is

FieldValue
Public proof ceilingCONTROLLED_TEST_VALIDATED
Reviewer package statusBOUNDED_REVIEWER_RELEASE_CANDIDATE
Raw/private runtime evidenceNOT_PUBLIC_SAFE
Public-safe runtime proofBLOCKED
Rendering of this pageRENDERING_NOT_PROOF

What this release does not prove. It is a reviewer route and a bounded ZIP. It does not promote runtime-active public proof, signal-observed public proof, public-safe runtime proof, production readiness, SOCaaS, autonomous SOC, AI-approved disposition, or analyst-approved disposition. Website/GitHub rendering is not proof.


Current ledger status

The platform-owned Lifetime Case Ledger state manifest is the authoritative source for current strict governed ledger state. This org README does not copy ledger event counts, case totals, public-safe counts, or closure counts into a public rendering surface.

Ledger fieldCurrent source-controlled value
Ledger stateSee the platform ledger state manifest.
Ledger countsSee the platform ledger state manifest.
Appended detectionsHO-DET-001, HO-DET-011, HO-DET-012
Ledger public-safe statusNOT_PUBLIC_SAFE
Ledger proof ceilingSCHEMA_CONTRACT_VERIFIER_EXISTS_ONLY

Runtime Case Collector v0 has separate private candidate lanes. Their current candidate and append state is governed by platform-owned manifests, records, and verifier gates, not by copied counts in this profile.

This ledger route does not prove runtime activity, signal observation, production deployment, SOCaaS availability, public-safe runtime proof, public proof, autonomous SOC authority, AI-approved final disposition, analyst-approved final disposition, or case closure authority.


Reviewer routes

Pick the route that matches your review job. The route changes how you inspect the system; it does not change the proof state.

RouteTimeWhat you inspectStart here
Hiring manager3 minWhat the system is, what is proven, what stays blocked.Start Here
Detection engineer10 minDetection source, validation scope, HO-DET-001 path.detections repo
SOC automation lead10 minCase packet flow, deterministic checks, CI boundaries, runtime-contract separation.validation repo
AI governance reviewer10 minWhere AI supports labor and where human review authorizes claims.proof repo
Demo reviewer8 minCommand-center route, project cockpit, Proof Pack 001, and reproducible reviewer path.Start Here
Cyber Kill Chain reviewer10 minAttack-lifecycle coverage map across source, validation, proof, platform contracts, and blocked claims.Cyber Kill Chain coverage map
Public rendering reviewer2 minPublic presentation and reviewer navigation only; rendering does not create proof.HO-DET-001 proof route

Org-level reviewer entry point: Cyber Kill Chain coverage lives in hawkinsoperations-proof as a public route-safe reviewer map. It is not public-safe approval, runtime proof, or proof authority.

Six truth surfaces

Each surface supports its own claims, nothing more. Authority does not flow between them by presentation.

SurfaceSupportsDoes not assert
Source truthA source artifact exists and can be reviewed.Deployment, runtime behavior, signal observation, or public proof.
Validation truthA deterministic validation process passed inside its stated scope.Runtime operation, public signal, or external-use authorization.
Runtime truthA control or detection is active in a runtime environment when runtime evidence is reviewed.Signal observation, evidence linkage, or public-safe proof.
Signal truthA bounded signal was observed in a stated context when signal evidence is reviewed.Fleet scope, production readiness, or public-safe status.
Evidence truthA preserved artifact supports a specific bounded claim.Claims outside the evidence boundary.
Public renderingWebsite and GitHub presentation of reviewed routes and wording.Proof of any kind.
flowchart LR
A[Source] --> B[Validation]
B --> C[Case packet]
C --> D[Proof record]
D --> E[Public boundary]
F[AI support] -. labor only .-> A
F -. labor only .-> B
G[Human review] --> D
H[Deterministic checks] --> D
E -. rendering is not proof .-> I[Website / GitHub]
Loading

Repository authority map

Seven repositories. Three planes. Authority flows through scoped records, not presentation. The current product/front-door repository is hoxline.

PlaneRepositoryAuthorityBoundary
Governance / routing.githubOrganization profile, reviewer routing, control summaries.Routes reviewers; does not prove source, runtime, signal, evidence, or public proof.
Authority chainhawkinsoperations-detectionsDetection source logic and ownership trail.Source does not prove validation or runtime.
Authority chainhawkinsoperations-validationFixtures, validators, case packets, deterministic checks.Validation does not prove public runtime or signal state.
Internal / private runtime contracthawkinsoperations-platformRuntime contracts, interface boundaries, non-promotional guardrails.Internal/private runtime-contract route; not a public proof route and not public proof.
Authority chainhawkinsoperations-proofProof records, claim ceilings, evidence boundary records, cited case packets.Proof records do not publish private evidence or raise ceilings by presentation.
Renderinghawkinsoperations-websitePublic reviewer navigation and rendered wording.Rendering is not proof and cannot approve a claim.
Product / front doorhoxlineCurrent Hoxline product/front-door repo and ProofOps control surface. Claim Firewall is its first internal Claim Authority enforcement capability.Product framing does not create proof authority, runtime truth, signal truth, public-safe status, or approval.

Detections → validation → proof feeds the authority chain. .github routes reviewers. hawkinsoperations-platform remains an internal/private runtime-contract route. hoxline is the current Hoxline product/front-door repo. AevumGuard was a prior working name. Hoxline is the current product name. The website renders receipts; it does not author them.


Hoxline Claim Authority

Claim Authority governs what can be claimed. Claim Firewall blocks unsupported claims before public wording ships. Blocked terms stay listed because they describe what this surface does not assert.

Blocked unless separately promoted and approved:

public-safe · production-ready · fleet-wide · live enterprise deployment · autonomous SOC · AI-approved disposition · analyst-approved disposition · runtime-active public proof · signal-observed public proof · evidence-linked public proof · live Splunk public proof · Cribl-routed public proof · Wazuh-routed public proof · AWS-live proof · customer-ready product · sold product · enterprise deployment

Allowed public boundary for this profile:

FieldCurrent value
Flagship pathHO-DET-001
Public proof ceilingCONTROLLED_TEST_VALIDATED
Public-safe statusNOT_PUBLIC_SAFE
Surface modeRENDERING_NOT_PROOF
Promotion authorityHUMAN_REVIEW_REQUIRED
Runtime-active public proofBLOCKED
Signal-observed public proofBLOCKED
Evidence-linked public proofBLOCKED
Production / fleet / autonomous claimBLOCKED

HO-DET-001 — flagship proof path

HO-DET-001 is the artifact reviewers can trace end to end without accepting a stronger public claim.

ReceiptReview routeWhat it supports
SourceDetection source repoThe detection source exists under version control.
ValidationValidation repoControlled positive and negative test scope can be inspected.
Case packetValidation repo and Proof repoCase packets are produced/validated in validation and cited/recorded by proof.
Proof recordHO-DET-001 proof recordThe current public ceiling and blocked claims are recorded.
Public renderingHO-DET-001 public routeReviewer navigation only; rendering does not create proof.

Public proof ceiling remains CONTROLLED_TEST_VALIDATED. Public-safe status remains NOT_PUBLIC_SAFE.


Prior operating context

HawkinsOps V1 / SignalFoundry metrics are prior operating context only. They are not current HawkinsOperations proof and do not raise the current HawkinsOperations ceiling.

Prior contextBoundary
324,074 cases processedHistorical V1 / HawkinsOps context only.
200+ detections builtHistorical V1 / HawkinsOps context only.
208/208 CI assertionsHistorical V1 / HawkinsOps context only.
39.7% reduction measuredHistorical V1 / HawkinsOps context only.
100% high-severity preservationHistorical V1 / HawkinsOps context only.

Current HawkinsOperations claims are bounded by source, validation, evidence, and the public-proof surface.


Real controls rule

Repo separation creates review boundaries. Real control comes from required review, deterministic verification, CI checks, proof records, and bounded public wording. The split is necessary; it is not sufficient. Treat the boundary as the artifact, not the architecture diagram.


AI is labor. Governance is authority.

AI generates work. Evidence and human review authorize claims.

Build loud. Verify hard. Claim tight. Ship receipts.

Operator profile · Proof ledger · GitHub organization

Pinned Loading

  1. hawkinsoperations-proofhawkinsoperations-proofPublic

    Proof records linking detection, validation, and evidence-backed claims.

    Python 2

  2. hawkinsoperations-validationhawkinsoperations-validationPublic

    Validation harnesses, test cases, and reports for detection quality gates.

    Python 1

  3. hawkinsoperations-platformhawkinsoperations-platformPublic

    Platform architecture and operational components supporting the security stack.

    Python 1

  4. hawkinsoperations-detectionshawkinsoperations-detectionsPublic

    Detection engineering rules, mappings, tests, and tuning artifacts.

    Python 1

  5. hawkinsoperations-websitehawkinsoperations-websitePublic

    Public-facing website and narrative surfaces for HawkinsOperations work.

    TypeScript 2

  6. .github.githubPublic

    Organization profile, governance metadata, and public-safe narrative entrypoint for HawkinsOperations.

    Python 2

Repositories

Showing 7 of 7 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…