Current implementation
Support-assisted

Authorized active validation

Prove that protection works against controlled attack progression.

ProtectTheBox runs bounded, authorized security validation against a customer-controlled target. It connects preflight, execution, detection, enforcement, rollback, and customer-readable proof.

The promise

Test the system safely, see what detected and blocked the activity, identify remaining exposure, and preserve proof of teardown.

Designed for

Customers and Sotiras operators validating a collector and defensive controls in an approved scope.

What it delivers

A focused surface with a specific job.

Scoped requests

Record the target, source networks, time window, permitted techniques, exclusions, and enforcement mode.

Operator preflight

Require target ownership, authorization, telemetry readiness, source allowlisting, and rollback controls before launch.

Kali-style assessment runner

Use an isolated runner for approved scenarios without turning the customer portal into a general attack console.

Proof and recovery

Report detection, attacker friction, remaining exposure, durable fixes, cleanup, and independent qualification evidence.

How the work flows

From intent to verifiable result.

  1. 01

    Request and authorize

    Define a customer target and obtain explicit approval for a bounded scenario.

  2. 02

    Preflight

    Prove telemetry, source, window, runner, emergency stop, and rollback readiness.

  3. 03

    Run and observe

    Launch approved activity and correlate it with collector, detection, and enforcement evidence.

  4. 04

    Teardown and report

    Stop the runner, verify cleanup, record gaps, and deliver customer-readable proof.

Trust boundary

What this surface does not blur.

ProtectTheBox is active validation and always requires explicit customer scope and authorization.

Current live execution is support-assisted; the public page does not claim unrestricted self-service penetration testing.

Runner IPs, target IPs, and controlled attack observations remain tenant-private and never seed Public CTI.