Groundzero: Building an Isolated Kernel and Exploit Lab
A bring-up log for the GCP lab where the sensor runs against real kernels: what validated, what broke, and what the first cloud runner exposed.
How we keep a security product honest: deterministic fixtures, seeded regressions, kernel-level runners, and the evidence behind every claim. No fluff, just what we built and what it caught.
A security tool cannot be tested like a normal CLI. We built a standing assurance platform around deterministic fixtures, real-kernel runners, preserved artifacts, and red runs that prove the system can fail loudly.
A bring-up log for the GCP lab where the sensor runs against real kernels: what validated, what broke, and what the first cloud runner exposed.
Counting vulnerabilities is not the same as measuring risk. A reachability-first view of a real image, with the graph evidence to back it.
If the feed moves under you, your results are not reproducible. How we pin the database so repeated runs produce identical, provable output.
Matched fixtures that prove a finding is real, not theoretical, by exercising the path on a vulnerable build and confirming the patch closes it.
An AI evaluator that reads deterministic reports and cites them — and the hard line that keeps a probabilistic system from ever becoming the oracle.