Published sample — not live customer evidence
Incident readiness review
Synthetic public sample from the OffSec suite. Not live incident response, not hack-back, not compromise, root-cause, or attribution evidence, and not a 24/7 service.
Sample case
Incident readiness review
Situation: a team needs a bounded readiness record for one named incident class and environment — preparation, unknowns, and open decisions on the package before an event.
How to use this sample
1. Read the walkthrough
Open BUYER_WALKTHROUGH.md for the inspection order of this synthetic readiness package.
2. Inspect readiness observations
Review sanitised preparation observations against the admitted scenario and environment.
3. Separate unknowns
Findings and open decisions stay distinct from management assertions.
4. Stay inside the boundary
This is readiness packaging only — not live IR command or a guarantee of incident outcome.
What you can inspect
- sanitised readiness observations for the admitted scenario
- posture and findings against preparation questions
- unknowns, exclusions, and open decisions
- receipt, evidence manifest, and hash sidecars
- buyer walkthrough and offline verification path
Package files
- BUYER_WALKTHROUGH.md
- receipt.json
- evidence_manifest.json
- findings.json
- report.md
- verification_result.json
Proofpack bytes are published as a .proofpack file (ZIP-compatible contents). Prefer the listed package files for browser inspection.
Offline verification
Offline product verifier path: witnessops-incident-ready verify with the proofpack ZIP, detached signature, and separately obtained trust registries. Require status: valid for named checks only.
Trust registries for this sample are synthetic and test-only. Obtain any production trust material through a channel separate from the proofpack. /verify is for supported public receipt types; this suite sample is inspected primarily via the package files and offline product verifier.
Boundaries
- No hack-back, exploitation, destructive testing, or live incident command.
- No compromise, root-cause, or attribution claim.
- Not a 24/7 service, compliance certification, or continuous monitoring.
- Synthetic trust keys only — not production signing custody.
- Not live customer evidence, production verification for your environment, or compliance certification.