Detection

Detection & protection families

hoaxeye groups detections into families. Each family decides when to run, which verdicts it can emit, and how the operator can configure its mode. The card grid below links to the per-family page; HoaxShield is the one card that's a protection layer rather than a detection family.

Live

Roadmap

Architecture concepts

Two pages explain the architecture every family below sits on. They're worth reading once before the family pages.

  • Rule engine — modes, verdict strings, risk buckets, fail-closed / fail-open, per-server operator control.
  • False positives — three filtering layers, anonymized snippet-hash corpus, an honest iteration history, and operator-final say on every action.

How to read each family page

Every live family page is structured the same way:

  • What it protects against. One paragraph, generic — no signal internals.
  • Modes. What observe / score / enforce mean for this family.
  • Verdicts. The verdict strings you'll see in dashboard logs.
  • Latency / cadence. Measured numbers with the methodology footnote.
  • False-positive history. What used to misfire, how we fixed it, why it's better now.
  • Operator recommendation. Which mode to start in for typical server types.