Two Generals · Cyber Forensics Test Lab

Track-back.
Never hack-back.

SENTINEL lures an attack into a trap, feeds it bait, documents everything in a forensics lab, and hands a tokenized evidence package straight to law enforcement — protecting a single family or an entire nation. We never touch anyone else's machine. That is what keeps it lawful.

  • 10working modules
  • 3protection tiers
  • 0machines we attack

Nothing ever touches a system we don't own.

No captured malware is ever executed.

Trackers are passive tokens — they identify, they never attack.

Evidence goes to the FBI IC3 / CISA, not back at the attacker.

The pipeline

One flow, from the attack to the government

Every hostile email, text, link, or intrusion on your own decoy surface follows the same documented path. It is caught, studied, and turned into evidence — before anything is allowed back out the door.

  1. 01

    The lure lands

    A decoy inbox receives a hostile email, SMS, or link on infrastructure we own. To the attacker it looks like a real target.

  2. 02

    Pulled into the trap

    VigilantGuard routes the artifact into an isolated sandbox. It is held, never allowed to touch anything real.

  3. 03

    Bait is served

    The trap serves fake-but-real-looking credentials, keys, and files — all watermarked and tokenized, so any theft is trackable.

  4. 04

    Forensics documents it

    The lab classifies the artifact, extracts indicators, checks for a known signature or "cure," and writes a documented case file.

  5. 05

    Tokenized track-back

    Tamper-evident tracker tokens are minted and bound to the case. Passive only — they identify the artifact, they never strike back.

  6. 06

    Handoff to authorities

    A chain-of-custody evidence bundle with an integrity hash is packaged for FBI IC3 / CISA. Government tier gets its own isolated stream.

A hostile data packet being pulled into an isolated containment chamber while tokenized tracer lines flow toward a government shield.
The trap: a hostile packet is contained, baited, and turned into tracked evidence — routed to the shield, never back at a person.
Cyber Caller ID & Blocker

Caller ID for your network

Just like your phone screens a call, SENTINEL screens every inbound connection. Nothing gets through until it proves who it is with the right token — and everything is logged, whether it's welcome or not.

Screen first

Every caller drops into a sandbox before it can reach anything real. A copy is made; the original is held at the door.

Test the copy

The sandbox tears the copy apart to learn everything about it. If it's clean and the token checks out, the held original is released — with a verification anchor added.

Leave a message

Unknown callers are challenged, exactly like a caller-ID screen. No valid token, no entry — the attempt is recorded.

Typed tokens

A person's token, a business's token, and a government token are all structurally different. A token that doesn't match what the caller should carry is flagged instantly.

Instant rotation

The moment a breach or forged token is seen, the token type is switched across your systems — so the stolen one is already useless.

One call log

Who called, what token they showed, the verdict, the severity, and the exact time — all in a single running log, like a call history.

The platform

Ten modules. One console.

Each piece runs on its own and connects into the unified Cyber Forensics Test Lab. All local-first, all built and verified — 45 of 45 automated checks passing.

PhishBot 3.0

Filter & Track-Back Gateway

Scans incoming email, text, and links, flags what's hostile, and sanitizes dangerous links into safe tokenized ones before they can do harm.

Cyber Caller ID

Caller ID & Blocker

Screens every inbound connection, forces a valid typed token, sandboxes a copy first, logs every call, and rotates tokens the instant a breach is seen.

VigilantGuard

Honeypot & Deception Grid

Decoy servers and bait files that quietly pull an intruder in, auto-clone a clean decoy, and hold the hostile copy in a sealed glovebox.

Forensics

Forensics Lab & Malware Microscope

Analyzes captured artifacts as inert bytes — never executed — documents the case, and grows a signature catalog to spot repeats.

Vault

Air-Gapped Encrypted Vault

AES-256-GCM authenticated encryption with tiered key derivation. Even the file listing reveals nothing. Family to government-grade.

Trace, not touch

On-Chain Ransom Tracing

Follows the public money trail with read-only taint analysis. Produces a law-enforcement referral. Never moves or seizes a single coin.

Sovereign overlay

Sovereign Packet Layer

Jurisdiction-aware tokenized egress — domestic vs. international — with cryptographic tenant isolation. Connects to the Sovereign Control Tower.

Identity Fabric 20/20

Sovereign Identity Fabric

Rotating, typed identity tokens for person, business & government — split by domestic vs. international — so no one can ever claim to be someone they are not. Even the cloud gets a token going in and a different one coming out.

Egress Guard EGR-

Outbound Egress Guard

Caller ID for everything leaving your system. Sensitive data is tokenized and traced on the way out, so it can never be hijacked in transit — and the most sensitive material rotates fastest.

Critical-Infra 13/13

Critical-Infra Air-Gap

True isolation for nuclear, grid & industrial control — not on any network whatsoever. A one-way data diode, an air-gapped vault on the protected high side, separate zones, and instant lockdown on any forged crossing.

Watch

See it, then learn it

The first film sets the doctrine in motion. The second walks through every module, step by step, with the words on screen and a narrator explaining each one.

The Doctrine FilmTrack-back, never hack-back — with on-screen captions.
The Full WalkthroughEvery module explained — narrated, with words on screen.
Learn the threats

A short curriculum on what attacks look like

SENTINEL is also a teaching tool. Know the lure before it reaches you — here's how the most common attacks work and how track-back answers each one.

01 Phishing email — the fake "urgent" message

What it looks like: An email that seems to come from your bank, boss, or a service you use, pushing you to click a link or "verify" your login right now.

Tells: urgency and threats, a mismatched sender address, links whose real destination differs from the text, and generic greetings.

How SENTINEL answers: PhishBot 3.0 scans the message, flags it, and rewrites the dangerous link into a safe tokenized one. A copy is routed to the trap so the attempt is documented, not just deleted.

02 Smishing — the phishing text message

What it looks like: A text about a "package delivery," "toll charge," or "suspicious login," with a short link.

Tells: unknown numbers, shortened links, and a request to tap a link or reply with personal info.

How SENTINEL answers: The decoy SMS surface catches the lure, PhishBot 3.0 classifies it, and the link is tokenized so any click can be traced back through the case file.

03 Malicious links & attachments

What it looks like: A link or file that installs malware or steals credentials the moment it's opened.

Tells: unexpected attachments, files that ask you to "enable content," and links that redirect several times.

How SENTINEL answers: The artifact is detonated only inside a simulated sandbox — never on a real machine — and studied under the forensics microscope as inert bytes.

04 Ransomware — files held hostage

What it looks like: Your files are encrypted and a note demands cryptocurrency to get them back.

Tells: sudden file-extension changes, a ransom note on the desktop, and a countdown timer.

How SENTINEL answers: The vault keeps an air-gapped encrypted copy so you're never held hostage, and on-chain tracing follows the ransom's public money trail for a law-enforcement referral — trace, not touch.

05 Why "track-back" is legal and "hack-back" is not

The line: Reaching into an attacker's system to retaliate is a federal crime under the Computer Fraud and Abuse Act (18 U.S.C. §1030). Honeypots, canary tokens, and beacons on your own systems are lawful active defense.

How SENTINEL stays on the right side: everything runs on infrastructure you own, nothing reaches out to anyone, and evidence goes to the authorities — who are the ones allowed to act.

Want this as a classroom module? The curriculum can be dropped into a whiteboard or LMS as a widget. See the docs.

Who it protects & pricing

One doctrine, three scales

Simple, honest pricing. Every plan starts with a free trial on hardware you already own — no data ever leaves your network.

Family

Protect a household.

$149/ year

Up to 5 people · 1 household

  • Phishing & smishing shield
  • Personal encrypted vault
  • Cyber Caller ID screening
  • Plain-language threat lessons
Start free trial
Most popular

Business

Protect an organization.

$499/ month

Per site · up to 50 seats

  • Everything in Family, plus:
  • Deception grid & decoy servers
  • Forensics case documentation
  • Tokenized evidence for referrals
  • Outbound Egress Guard & tiered team vault
Start free trial

Government

Protect a nation.

Custom

Agency & critical-infrastructure

  • Everything in Business, plus:
  • Critical-Infra Air-Gap & data diode
  • Sovereign Identity Fabric & Packet Layer
  • On-chain ransom tracing
  • Direct FBI IC3 / CISA handoff
Contact us

Prices are introductory and shown in USD. Nonprofits, schools, and houses of worship: ask about reduced pricing at Kristen@bornbetween2generals.com.

Get started

Stand your ground — lawfully.

Request a free trial for your family, business, or agency, or join the briefing list for updates on new modules and the doctrine.