Published work

The engineering is public before the invoice is.

RTFM maintains In a Box: thirteen self-hosted infrastructure and security blueprints. Configuration, dashboards, tests, trade-offs, and known gaps are all in the open. Read them, run them, and decide whether this is the standard you want in your environment.

SIEM in a Box Grafana dashboard: event counters, detection timeline, priority breakdown, and live security event stream.
SIEM in a Box — security overview, generated by make demo

01 — Context & Operations

AIBAssets in a Box

Know the blast radius before production teaches you.

Turns Terraform, Kubernetes, Ansible, Compose, CloudFormation, and Pulumi into a dependency graph with impact, drift, and security analysis. Runs in CI as a GitHub Action.

Established
Go · 1 ★
Race-tested · 80.4% coverage
Source ↗
OIBObservability in a Box

See what the system is doing without renting your telemetry back.

Prometheus, Loki, Tempo, Alloy, Grafana, and optional Pyroscope with ready-made dashboards, health tooling, and instrumented examples.

Established
Compose · 51 ★
12 validated stack variants
Source ↗
DIBDatabase in a Box

Give developers real databases, real tooling, and a safe place to learn.

Five database engines, six web UIs, monitoring, backups, migrations, sample data, and connection helpers in one development platform.

Active blueprint
CI-backed lab platform
Source not yet public

02 — Detection & Response

SIBSIEM in a Box

Detect what workloads do, not merely what their logs claim.

Falco runtime detection, routed alerts, searchable security events, MITRE ATT&CK dashboards, fleet collection, and optional private AI analysis.

Established
Python · 96 ★
64 tests
Source ↗
NIBNIDS in a Box

See hostile traffic before the incident report has to explain it.

Suricata deep packet inspection, CrowdSec behavioural detection, JA3/JA4 fingerprinting, and deliberate host or router blocking modes.

Developing
Shell · 11 ★
CI gap disclosed
Source ↗
SIB-K8sSIEM in a Box for Kubernetes

Bring runtime detection and explainable triage into the cluster.

An umbrella Helm chart wiring Falco, Falcosidekick, Loki, Grafana, and optional privacy-preserving AI analysis with three obfuscation levels.

Developing
Helm · 1 ★
Roadmap edges disclosed
Source ↗
CAIBCloud Audit in a Box

Keep the cloud audit trail. Keep the detections. Keep the evidence.

Collect, normalise, search, and detect across AWS, GCP, Azure, and Cloudflare on Vector, PostgreSQL with TimescaleDB, and Grafana.

Developing
70 tests
1M-event benchmark · HA and restore drills
Source not yet public

03 — Posture & Prioritisation

VIBVulnerability in a Box

Know which running images carry risk — and whether that risk is growing.

Discovers running container images, scans them with Trivy, retains vulnerability history, and feeds critical findings into AIB.

Active blueprint
Recurring scans, retained history
Source ↗
TIBThreat Intelligence in a Box

Fix the vulnerabilities attackers are actually using first.

Correlates VIB findings with CISA KEV and EPSS so active exploitation and probability — not CVSS alone — drive the queue.

Active blueprint
KEV and EPSS correlation shipped
Source ↗
CIBCompliance in a Box

Turn container policy from a spreadsheet promise into evidence.

Checks runtime configuration, SBOM licences, and base-image end-of-life status while retaining CycloneDX evidence for review.

Active blueprint
Runtime, SBOM, licence, EOL evidence
Source ↗

04 — Trust & Access

IIBIdentity in a Box

Put one identity boundary in front of the services you operate.

Packages Authentik with its data services, generated secrets, identity health metrics, and an operational Grafana view. OIDC, SAML, LDAP, SCIM, MFA, SSO.

Active blueprint
Authentik with health metrics
Source ↗
PIBPKI in a Box

Issue internal certificates automatically and catch expiry before users do.

Runs step-ca with ACME support, trust-bootstrap helpers, endpoint probing, and certificate-expiry dashboards.

Active blueprint
step-ca, ACME, endpoint monitoring
Source ↗

05 — Unified Suite

XIBSecurity Posture in a Box

One operational view across vulnerabilities, exploitation, compliance, identity, and PKI.

Composes VIB, TIB, CIB, IIB, and PIB with pinned submodules and a unified Grafana dashboard, while every tool stays independently deployable. No fake “single pane” promise.

Active blueprint
Shell · 1 ★
Five pinned, independent tools
Source ↗
How to read the maturity labels

Stated plainly, including the gaps.

Established

Broader test coverage and validation. Safe to build an engagement on.

Active blueprint

Shipped and focused, with lighter verification. Useful, and honest about it.

Developing

Usable core with gaps stated plainly in the documentation rather than discovered in production.