The Proof Economy™ · ProofCorpus

Pull. Spin.
Prove.

Every pull assembles a full campaign: a kill chain of chained TTPs, a target stack, and an environment, matched to a Speed Daemon and ready to run. No two campaigns are the same.

ProofCorpus Unit // RNG-CERTIFIED 0 campaigns pulled
Campaign
Target Stack
Environment
Campaign manifest PH-000000
Kill chain — payloads included
This campaign's full kill chain — technique-by-technique, payloads included — unlocks with a work email.
Curation queue
Builds you've flagged this session. "Push" hits the endpoint constants at the top of the script — fill those in with your real webhook URLs before this does anything live.
Nothing flagged yet.
Push log
Every push attempt, timestamped, with the full manifest and TTP payload data captured at the moment it was sent, for manually cross-checking against what actually landed on the other end.
No pushes yet.
15/32
TTPs in this corpus carry a real, cited Atomic Red Team procedure: test name, GUID, executor, and the literal command, pulled live from the source repo, not written from memory. The other 17 say exactly why they don't have one instead of faking it.
For detection engineering
Every sourced TTP links back to the exact test file on GitHub. Check the GUID, check the command, check it yourself. Nothing here asks for trust.
For product marketing
The gap is the finding: nobody has standardized, cited detection tests for AI-agent attacks yet. First vendor to close that gap gets a claim nobody else can make.

What a campaign is

A campaign build is a starting spec, not a finished proof: a kill chain of TTPs, one target stack, one environment, assigned to an execution worker. Producers refine it into a full ProofHarness before it runs.

Why it's random

Fixed test suites get memorized and gamed. Randomized campaigns keep coverage honest and surface gaps a hand-picked corpus would skip.