OffSec + WitnessOps wiring (R1)

OffSec Shield — local server audit sample

OffSec collects read-only posture and ships a receipt-backed proof bundle. WitnessOps proves named workflows on /verify for PV/QV/WV receipt stages. This sample shows the Shield deliverable shape and honest limits — not a claim that your environment was audited.

Offer class: OffSec Local Server AuditArtifact class: Shield fixture proof bundleHost: Synthetic demo-host (fixture)WitnessOps /verify: Structural only (R2 adapter; see VERIFY_NOTE)

Run metadata

Receipt id
secsvc-local-fixture-a
Run id
local-fixture-a
Module
local-audit

Download artifacts

Proof boundary

  • Integrity checks use Shield MANIFEST.sha256 semantics (READY / MISMATCH / MISSING).
  • Does not prove regulatory compliance, EDR coverage, or that your production hosts match this fixture.
  • Schema map: offsecshield.receipt.v1 run_receipt.schema.json per SCHEMA_RECONCILIATION.md (R2: POST RECEIPT.json to /api/verify for structural checks only).

Sample id: offsec-shield-local-server-audit. Regenerate via OffSec-Lane publish-shield-sample-witnessops.sh.