Published sample, not live customer evidence

Incident readiness review

Synthetic public sample from the OffSec suite. Not live incident response, not hack-back, not compromise, root-cause, or attribution evidence, and not a 24/7 service.

Sample case

Incident readiness review

Situation: a team needs a bounded readiness record for one named incident class and environment: preparation, unknowns, and open decisions on the package before an event.

Product: OFFSEC-INCIDENT-READYRun: pr_incident_demo_20260711130000Status: Synthetic, not live

How to use this sample

  1. 1. Read the walkthrough

    Open BUYER_WALKTHROUGH.md for the inspection order of this synthetic readiness package.

  2. 2. Inspect readiness observations

    Review sanitised preparation observations against the admitted scenario and environment.

  3. 3. Separate unknowns

    Findings and open decisions stay distinct from management assertions.

  4. 4. Stay inside the boundary

    This is readiness packaging only, not live IR command or a guarantee of incident outcome.

What you can inspect

  • sanitised readiness observations for the admitted scenario
  • posture and findings against preparation questions
  • unknowns, exclusions, and open decisions
  • receipt, evidence manifest, and hash sidecars
  • buyer walkthrough and historical reference output

Package files

Proofpack bytes are published as a .proofpack file (ZIP-compatible contents). Prefer the listed package files for browser inspection.

Legacy proofpack format

This sample uses an earlier proofpack format. It is not compatible with the current Bundle V1 verifier. A pinned historical verifier is not presently available. Downloads are preserved for historical inspection, not as a current verification result.

Boundaries

  • No hack-back, exploitation, destructive testing, or live incident command.
  • No compromise, root-cause, or attribution claim.
  • Not a 24/7 service, compliance certification, or continuous monitoring.
  • Synthetic trust keys only, not production signing custody.
  • Not live customer evidence, production verification for your environment, or compliance certification.
Sample: Incident readiness review | WitnessOps