Detection Scenario Platform (DSP)
Generate realistic, observable security activity for XDR and NDR customer POC validation. DSP helps POC engineers create repeatable security activity when a customer environment is too quiet to produce enough useful detections during an evaluation. It discovers reachable targets, executes controlled scenarios, records what happened, and produces evidence that can be compared with XDR/NDR detections.DSP proves what activity it generated. It does not automatically claim that an alert fired or that an XDR case was successfully correlated. Detection and case outcomes must be verified in the connected security platform.
Fastest path
1
Install DSP
On a Linux host with Python 3.11+, Git, and curl:
2
Configure the first run
In the menu choose Configure environment, set the authorized target CIDR, select local, and use normal for the first test.
3
Run and review
Choose Run scenario, then Show latest report to review what DSP generated.
Quick Start
Use the simplest local-mode path from prerequisites to the first report.
POC Workflow
See how target discovery, controlled activity, NDR/XDR detection review, and evidence fit together.
Scenario Coverage
Review the current network, DNS, web, identity, and host-behavior scenarios.
XDR Correlation Demo
Combine DSP evidence, NDR detections, and optional external alerts into an XDR investigation story.
What you need
For the simplest first run, prepare:- a Linux operator host with Python 3.11+,
git, andcurl - an authorized target CIDR
- network reachability from the DSP host to that target network
- access to the XDR/NDR console for detection review
What DSP gives you
Controlled scenarios
Generate repeatable scan, DNS, web, identity, protocol, and host-behavior activity.
Discovery-driven execution
Start from a CIDR and let DSP use discovered hosts/services to drive scenario execution.
Evidence per run
Keep structured events, traffic summaries, validation output, reports, and verification templates under one run ID.
Simple coverage profiles
Use
normal for representative targets or high to apply the same per-target volume across more discovered targets.Current validation boundary
DSP v1.4.0 is documented as READY WITH KNOWN LIMITATIONS. Local execution plus real JSP and PHP webshell execution are validated. ASPX/Windows IIS remains preview because real Windows webshell runtime validation is still pending.Check validation status
Review the exact provider and platform boundaries before a customer POC.