XCOM.DEV XCOM.DEV · SENSE

Layer 01 · SENSE · four-layer stack

Sense

The layer that touches the adversary — directly, continuously, in production.

Before any reasoning happens, something real must be observed. Our honeypot sensors pose as vulnerable internet-facing services and receive genuine attack traffic. Nothing here is synthetic: every number below is a live query into production telemetry.

Query /api/metrics →Attack map
L1 · PROOFLive figures
Honeypot events
D1 · honeypot_logs
Events / 24h
live window
Events / last hour
live window
Arrival rate λ
model · per second
L1 · HOWHow sensing works
step 1

Decoys on the open internet

Vulnerable-looking services exposed on purpose. Attackers find them the same way they find anything: scanning.

step 2

Probes become events

Each probe is logged as an event — source, timing, protocol, payload shape. Individually noise; in aggregate, a live map of adversarial behaviour.

step 3

IOCs extracted

IPs, credential patterns, fingerprints — indicators of compromise ready for correlation in layer 02.

step 4

Poisson modelling

Arrivals follow $P(k) = (\lambda t)^k e^{-\lambda t}/k!$ per window. λ is estimated live from the last hour; the homepage overlays observed counts on this model. Deviation from the model is itself signal.

L1 · NEXTWhere the signal goes
→ L2

Agent swarm

IOCs and events are correlated by 48 specialised agents.

→ layer 02 · connect
→ page

Attack map

Geographic and temporal view of live attack activity.

→ attack-map.html
→ contract

Manifesto

Why “proven, not claimed” is a design rule, not a slogan.

→ /vision