Official Benchmark Scorecards¶
Auditors must publish results using the standard scorecard layout validated by schemas/scorecard.schema.json.
UHBS is vendor-neutral: decoy classes and protocols are the normative vocabulary. Named products appear only as evaluation proof (not requirements or endorsements). The three scorecards below are sanitized fixtures from live Docker lab runs; full artifacts and tutorials live under Conformance lab reports.
Examples¶
Published full UHBS-Lab scorecards (evaluated 2026-07-27):
Each page links to the matching report hub (quick/ + full/ scorecards, report.json, methodology, tutorial).
Synthetic layout sample (not a lab run)¶
- Illustrative POSIX-Shell / GenAI-Augmented Decoy — vendor-neutral layout sample only (evaluated 2026-07-26)
Badge Snippets¶
After an official evaluation, maintainers can embed:





Submitting a Scorecard¶
- Complete a TPS
profile.yaml - Run the five-phase audit
- Emit a scorecard conforming to the schema
- Open a PR or issue using the Profile / Scorecard Submission template
Validate a published fixture locally:
uhbs validate-scorecard docs/conformance/fixtures/espot-web-api.scorecard.json --strict
uhbs validate-scorecard docs/conformance/fixtures/miniprint-low-interaction.scorecard.json --strict
uhbs validate-scorecard docs/conformance/fixtures/conpot-ics-scada.scorecard.json --strict
uhbs validate-scorecard docs/conformance/fixtures/cowrie-low-interaction.scorecard.json --strict
uhbs validate-scorecard docs/conformance/fixtures/endlessh-low-interaction.scorecard.json --strict
uhbs validate-scorecard docs/conformance/fixtures/opencanary-web-api.scorecard.json --strict