a real sealed test run, replayed

An unknown program phones out.
Watch the next eleven seconds.

Every number below is from the sealed receipt of customer test INC-20260915-105304-523b — a synthetic intruder planted on a clean machine. Nothing here is staged data.

01 · observe

A first-contact connection appears

upd4te.exe 198.51.100.23:4444country unknown · port never seen here

Unsigned. Never fingerprinted on this box. No history. (The address is a documentation-range TEST-NET address — the test can never touch a real host.)

02 · score

The governed brain scores it

The fuzzy unit weighs risk, persistence and port rarity; five trained neural nets vote; a fuzzy governor fuses the verdict.

0.000
⚠ ALARM

0.8625 crosses the governed 0.85 alarm band.

03 · incident

The dossier opens itself

INC-20260915-105304-523b · severity alarm

Who — upd4te.exe (identity unknown, fingerprint drift)
Where — 198.51.100.23:4444, country XX, first contact
Why — unknown unsigned process reaching a foreign host on a rare port

04 · seal

The catch becomes evidence

Chain-sealed and signed at the moment it happened:

05 · export

Hand it to anyone

Evidence bundle 75,456 bytes — incident dossier, CSVs, receipts, manifest and public key. Verification needs no account, no trust, no us.

9 / 9

checks passed — and the negative control held too:
a clean box produced silence. No crying wolf.

Replay the catch    Put it on your machine