Published work

The engineering is public before the invoice is.

RTFM maintains In a Box: eleven published self-hosted infrastructure and security blueprints. Configuration, dashboards, tests, trade-offs, and known gaps are all in the open. Read them, run them, and decide whether this is the standard you want in your environment.

SIEM in a Box Grafana dashboard: event counters, detection timeline, priority breakdown, and live security event stream.
SIEM in a Box — security overview, generated by make demo
The deployable set

Three blueprints safe to build an engagement on.

Established maturity: broader test coverage, validated variants, verified recovery. These are the options behind the Hardened Deployment engagement.

Established

AIBAssets in a Box

Know the blast radius before production teaches you.

Turns Terraform, Kubernetes, Ansible, Compose, CloudFormation, and Pulumi into a dependency graph with impact, drift, and security analysis. Runs in CI as a GitHub Action.

Go
Race-tested · 80.4% coverage
Source ↗
OIBObservability in a Box

See what the system is doing without renting your telemetry back.

Prometheus, Loki, Tempo, Alloy, Grafana, and optional Pyroscope with ready-made dashboards, health tooling, and instrumented examples.

Compose
12 validated stack variants
Source ↗
SIBSIEM in a Box

Detect what workloads do, not merely what their logs claim.

Falco runtime detection, routed alerts, searchable security events, MITRE ATT&CK dashboards, fleet collection, and optional private AI analysis.

Python · 96 ★
64 tests
Source ↗
The surrounding suite

Eight more, shipped and honest about their verification depth.

01 — Detection & Response

NIBNIDS in a Box

See hostile traffic before the incident report has to explain it.

Suricata deep packet inspection, CrowdSec behavioural detection, JA3/JA4 fingerprinting, and deliberate host or router blocking modes.

Developing
Shell
CI gap disclosed
Source ↗
SIB-K8sSIEM in a Box for Kubernetes

Bring runtime detection and explainable triage into the cluster.

An umbrella Helm chart wiring Falco, Falcosidekick, Loki, Grafana, and optional privacy-preserving AI analysis with three obfuscation levels.

Developing
Helm
Roadmap edges disclosed
Source ↗

02 — Posture & Prioritisation

VIBVulnerability in a Box

Know which running images carry risk — and whether that risk is growing.

Discovers running container images, scans them with Trivy, retains vulnerability history, and feeds critical findings into AIB.

Active blueprint
Recurring scans, retained history
Source ↗
TIBThreat Intelligence in a Box

Fix the vulnerabilities attackers are actually using first.

Correlates VIB findings with CISA KEV and EPSS so active exploitation and probability — not CVSS alone — drive the queue.

Active blueprint
KEV and EPSS correlation shipped
Source ↗
CIBCompliance in a Box

Turn container policy from a spreadsheet promise into evidence.

Checks runtime configuration, SBOM licences, and base-image end-of-life status while retaining CycloneDX evidence for review.

Active blueprint
Runtime, SBOM, licence, EOL evidence
Source ↗

03 — Trust & Access

IIBIdentity in a Box

Put one identity boundary in front of the services you operate.

Packages Authentik with its data services, generated secrets, identity health metrics, and an operational Grafana view. OIDC, SAML, LDAP, SCIM, MFA, SSO.

Active blueprint
Authentik with health metrics
Source ↗
PIBPKI in a Box

Issue internal certificates automatically and catch expiry before users do.

Runs step-ca with ACME support, trust-bootstrap helpers, endpoint probing, and certificate-expiry dashboards.

Active blueprint
step-ca, ACME, endpoint monitoring
Source ↗

04 — Unified Suite

XIBSecurity Posture in a Box

One operational view across vulnerabilities, exploitation, compliance, identity, and PKI.

Composes VIB, TIB, CIB, IIB, and PIB with pinned submodules and a unified Grafana dashboard, while every tool stays independently deployable. No fake “single pane” promise.

Active blueprint
Shell
Five pinned, independent tools
Source ↗
How to read the maturity labels

Stated plainly, including the gaps.

Established

Broader test coverage and validation. Safe to build an engagement on.

Active blueprint

Shipped and focused, with lighter verification. Useful, and honest about it.

Developing

Usable core with gaps stated plainly in the documentation rather than discovered in production.

Two further blueprints — Database in a Box and Cloud Audit in a Box — are in development and will be listed here when their source is published.