Deliberately-contained detonation environment for web malware (webshells, HTTP-delivered exploits, scanner-driven RCE). A DetectionOnly WAF tap fronts a disposable Docker/Firecracker victim; events and samples flow one-way to an age-encrypted, audited sink on a separate host. 105 passing tests; most buyer-priority P0/P1 work already implemented.
DetCordon
Containment-first observation for hostile web payloads: a disposable, network-isolated victim, a DetectionOnly WAF tap, and a one-way encrypted evidence trail to an audited sink.
Completion estimate across public surface, working system parts, and remaining implementation depth.
Estimated present studio asset value at the current scope and maturity level.
Target studio asset value at the planned finished scope. Revenue status: pre-revenue.
Internal studio value estimates in USD. Current value is derived from completion percentage and is not booked revenue.
What is done
The buyer-critical slice is already implemented, not just architected.
- Two-host containment model: DetectionOnly WAF tap plus disposable Docker/Firecracker victim, isolated from an audited evidence sink on a separate host.
- Evidence-grade demo path: one command replays synthetic hostile traffic, produces an age-encrypted sample, and shows events in an operator dashboard.
- 105 passing tests, a containment-assurance checklist mapping every non-negotiable rule to generated-artifact evidence, and an authenticated operator dashboard.
What is left
The remaining work is production-hardening, not core architecture.
- TLS for inter-service event/sample/heartbeat traffic, currently plaintext by design for the demo/pilot stage.
- Broader test coverage on the core HTTP pipeline and VM lifecycle orchestrator.
- Multi-sandbox managed-lab scaling and a real tiered SKU/support-tier offer.
Commercial frame
This is an enterprise appliance sale, not a self-serve product — pricing and packaging reflect that.
- Pricing signal: illustrative only at this stage — Self-Hosted License, Managed Pilot, and Managed Production tiers, with final rates agreed per engagement.
- Best fit: security researchers, blue teams, and research labs analyzing unknown web payloads under real containment guarantees.
- Next step is a pilot conversation, not a checkout button — request one directly.
DetCordon's diligence-grade proof (containment assurance, buyer demo runbook) already exists — see the docs link below before assuming this is early-stage.