Registry
Coverage map of HawkinsOps closed claims and their Ledger review state. Every case study gets a row. Every row names its status honestly: reviewed, queued, not yet assigned, or a system surface that pairs at the component-claim level.
Claim status matrix
The matrix collapses this registry into claim families: supported wording, blocked wording, current route, paired external surface, and next gate. Unreviewed rows are unresolved on RayleeOps, not disproven.
System & flagship
SignalFoundry
System surface Paired via component claims below.
Detection Coverage
System surface Paired via component claims below.
Signal Architecture — AutoSOC System Model
System surface Paired via component claims below.
March 2026 System Hardening & Pipeline Evolution
No public review
Incident response & recovery
Production Race Condition Recovery
Resolved Reviewed on The Ledger: The Pipeline Ate Itself at Five Hundred Thousand.
Pipeline Fault Recovery — Two Failure Domains
No public review
IR Case: Level 12 FIM Alert — Triage to BENIGN
No public review
IR Playbook Library
No public review
CVE-2025-55130 — Detect to Remediation
No public review
Hotfix RCA: Triage Quality Chart Renderer
No public review
AutoSOC Infrastructure Cutover
No public review
Detection engineering
Sigma Detection Library
Reviewed/narrowed- Artifact / surface
- case-study-sigma-library
- Supported claim
- 103-rule Sigma library with count, drift, UUID uniqueness, and strict content validation.
- Blocked claim
- runtime signal; universal SIEM deployability.
- What changed
- File/count proof was separated from runtime/signal proof.
- Next gate
- link runtime/signal proof artifact before any signal or deployability claim.
- Receipt
- The Counter Certified Nothing
Wazuh Rule Blocks — Authored and Validated
No public review
Wazuh Windows Telemetry Remediation
Reviewed/narrowed- Artifact / surface
- case-study-wazuh
- Supported claim
- Historical primary-endpoint process-creation telemetry restoration and manager-to-indexer delivery validation during remediation window.
- Blocked claim
- fleet-wide visibility; current-runtime visibility.
- What changed
- Historical remediation-window proof was separated from current/fleet claims.
- Next gate
- link evidence/proof artifact for current and fleet visibility before either claim is made.
- Receipt
- The Dashboard Lied Politely
Wazuh Detection Harness
No public review
Splunk Detection Rule Audit — Four Noise Sources
No public review
Migrating Legacy Detection Rules from Python 2 to Python 3
No public review
Threat hunting
Live Splunk Threat Hunt — EventID 4688
No public review
When AI Tooling Looks Like a LOLBin
No public review
Infrastructure & hardening
Enterprise Security Hardening
No public review
Audit Policy Baseline Assessment
No public review
Cowrie Honeypot + Wazuh + Grafana
No public review
Honeypot (Wazuh) Sanitized Alert Proof
No public review
PP_SOC Integration — Live Detection Workflow
No public review
Cross-cutting sub-claims
Auto-close metric — ~88% headline figure
Queued Sub-claim across signalfoundry, case-studies, and proof. Review question: defend the headline with caveats, or retract.