Visit builder.protoevidence.com, select Get Started, and complete Corelight Google Workspace sign-in.
State the behavior, integration, detection, or question you want to validate. A narrow, testable idea produces the most useful workspace.
CanWeBuildIt displays a URL like https://abcd1234.builder.protoevidence.com/?auth=….
The first visit exchanges the private token for a Secure, HttpOnly browser cookie and removes the token from the address bar. From then on, use the clean workspace URL.
The detection workspace includes code-server, Docker, Python, Zeek, Suricata, tshark, and common command-line tools.
Use the clean URL while the browser session is valid. If the cookie is cleared or expires, reopen the saved complete URL.
Every environment has a hard termination deadline. Move durable work to its project repository before that deadline.