Legacy SOC automation and detection engineering archive. Active development now lives in HawkinsOperations.
Important
Status: V1 retired. This repository is preserved as a historical archive and donor proof surface. Current work has moved to HawkinsOperations.
If you arrived here from LinkedIn, GitHub search, Microsoft Teams, old portfolio links, or an older HawkinsOps reference, start with HawkinsOperations. This repo is the historical V1 archive, not the current operating system.
- Current organization: https://github.com/HawkinsOperations
- Current website: https://hawkinsoperations.com
- Current proof route: https://hawkinsoperations.com/proof/ho-det-001/
- Current proof repo: https://github.com/HawkinsOperations/hawkinsoperations-proof
- Current detections repo: https://github.com/HawkinsOperations/hawkinsoperations-detections
- Current validation repo: https://github.com/HawkinsOperations/hawkinsoperations-validation
HawkinsOperations is a governed detection engineering, SOC automation, and AI security operations system split across six public repositories:
| Repository | Authority role |
|---|---|
| .github | Organization command center and reviewer routing |
| hawkinsoperations-detections | Detection source truth |
| hawkinsoperations-validation | Controlled validation truth |
| hawkinsoperations-platform | Contracts, ledgers, and automation boundaries |
| hawkinsoperations-proof | Proof records, claim ceilings, and reviewer packets |
| hawkinsoperations-website | Public reviewer navigation only |
Boundaries that matter:
- Website rendering is not proof.
- GitHub rendering is not runtime truth.
- Green CI is not final authority.
- AI is support labor, not final security authority.
- Human review and deterministic validation control claim promotion.
| Audience | Best next link | Why |
|---|---|---|
| Recruiters | https://hawkinsoperations.com | Current public reviewer front door |
| SOC leaders | https://hawkinsoperations.com/proof/ho-det-001/ | Current bounded HO-DET-001 proof route |
| Detection engineers | https://github.com/HawkinsOperations/hawkinsoperations-detections | Current detection source truth |
| Security reviewers | https://github.com/HawkinsOperations/hawkinsoperations-proof | Current proof records and claim ceilings |
| AI security reviewers | https://hawkinsoperations.com/ai-security | AI support-labor and human review boundary |
| Legacy context | https://hawkinsops.com | Closed V1 proof surface and historical snapshot |
HawkinsOps V1 remains useful as historical context for the original SOC automation and detection engineering work.
Historical V1 snapshot only:
- 324,074 processed cases
- approximately 88 percent auto-close
- 8,574 reviewer-escalated evidence packs
- 0 reconciliation mismatches
- 211 historical detection artifacts
These metrics are historical HawkinsOps V1 context only. They are not current HawkinsOperations runtime proof, production proof, public-safe proof, customer deployment proof, or SOCaaS availability proof.
This archive preserves the V1 public record: detection content, case studies, proof-pack material, verification infrastructure, and reviewer paths from the original HawkinsOps system. Treat it as legacy source and historical review context.
For current work, use HawkinsOperations:
HawkinsOps V1 showed that the original system could produce reviewable SOC automation and detection engineering artifacts. HawkinsOperations is the active governed successor architecture, built to separate source truth, validation truth, platform contracts, proof records, governance routing, and public rendering.
Do not treat this archive as the current operating architecture. Do not treat historical V1 metrics as current runtime proof. Do not treat rendered pages, badges, or repository presence as proof beyond their stated scope.