Security software organization

Security for what comes next.

Two controls. The decision stays on systems you operate.

Two products. One posture.

Today

Terminator Sec

Endpoint and DNS control

Block, sinkhole, or prompt before a connection opens.

  1. Intercept
  2. Score
  3. Block
  4. Ask
  5. Allow
Open the product
Transition

QuantumShield

Cryptographic transition

Inventory public-key use, then move to ML-KEM and ML-DSA.

  1. Inventory
  2. RSA and ECC
  3. Hybrid TLS
  4. ML-DSA
Open the product

See the name before the socket opens.

01

Intercept

UDP, TCP, and DoH on the host.

02

Score

Blocklist, then entropy, then wording.

03

Act

Block, ask, or allow. Nothing leaves the device.

On the host

  • Trie and bloom blocklists
  • Generated-name check
  • Process and filesystem guard
  • Local fleet policy

Result

  • Known malware never connects
  • Lookalike names ask first
  • No vendor DNS log
  • No SOC queue required
$ terminator-sec scan :5353
[+] trie loaded
[+] scoring udp/tcp/doh
12 names observed · 3 blocked · 1 prompt
Go Core Daemon

In-Memory Engine & Interceptor Architecture

< 0.1ms lookup

Compiled in Go. Zero heap allocations per lookup cycle. Operates as a local DNS proxy (UDP/TCP/DoH :53) with zero external telemetry.

Tier 1

Radix Trie + Bloom Filter

O(k) domain prefix & suffix matching across 500k+ IOC feeds.

Tier 2

Shannon Entropy & Lexical Heuristics

Real-time DGA anomaly scoring without off-device cloud lookups.

Tier 3

Local IPC & eBPF Socket Hooks

Process-level attribution linking outbound queries to caller PIDs.

Sandbox DNS intercept

Pick a name. The host blocks, asks, or allows.

  1. 1 · Hear the query
  2. 2 · Score on the host
  3. 3 · Block, ask, or allow

This name is already on a local blocklist.

Decision

Score the name to see what the host would do.

Known malware is blocked. Machine-generated names are blocked. Lookalike login pages ask the person first. Ordinary sites are allowed through.

What the agent recorded On device
00:00:00 READY Listening on the host. Blocklist loaded. Nothing sent off-device. n/a

Start with an inventory. Then move the edge.

01

Discover

CBOM of RSA, elliptic curves, and SHA-1.

02

Protect

Hybrid ML-KEM at the TLS edge.

03

Trust

ECDSA and ML-DSA on one certificate.

04

Sign

LMS only where a stateful signature fits.

  1. TodayRSA still verifies

    Recorded ciphertext is the reason to plan now.

  2. This yearNot a cutover

    Research machines do not retire production RSA.

  3. NextHybrid edge

    Legacy clients stay. PQC clients require ML-KEM.

Sandbox CBOM inventory

Build a sample inventory. Each row is one component.

  1. 1 · Repositories
  2. 2 · Images
  3. 3 · Live TLS
  4. 4 · Inventory

Sample estate

Five components. Not a scan of a real repository.

What you will see

Public-key systems that need a migration plan, and one edge that is already hybrid.

RSA and elliptic curves are the Shor concern. AES is a key-size note, not the same problem. Research machines do not retire production RSA this year.

Where Algorithm Used for What to do Why
Build the inventory to walk the sample estate one component at a time.

What stays inside.

Kept

  • DNS decision
  • Blocklists and process policy
  • Certificate keys
  • SIEM export, on your retention

Not this

  • Managed SOC
  • CVE subscription
  • A date when RSA fails
  • A scan from this website
  1. 1 · Place the agent
  2. 2 · Read the CBOM
  3. 3 · Hybrid TLS
  4. 4 · Dual signatures

A topology you can inspect.

Data store

Sample console.

Illustrative counts. Not a live tenant.

Findings closed0%
Assets0
Open findings0
Critical0
PQC readiness0%

Both controls, one graph.

Sample data, in the browser. Nothing on your network is scanned.

Ask a question. The answer is a path through the nodes.

Retrieved path

Click a node, or ask a question.

Score a name or build the inventory first if you want those facts in the graph. RSA and elliptic curves are already here. AES is here as a different kind of note.

Find what you are exposed to. Prepare for what is next.

Talk to the security team.

Endpoint rollout or cryptographic migration. We reply within four business hours.