What is Kronyx?

PentestingEDRNetwork SecurityKronyx AIv1.0

Kronyx is an enterprise security platform built around three core components: Endpoint Detection & Response (EDR), Network Security, and Pentesting — the platform's core capability, and the reason the other two exist. EDR and Network give you continuous visibility into your endpoints and infrastructure; Pentesting is what turns that visibility into proof, by actively attacking your own domains and servers the way a real attacker would and telling you exactly what's exploitable.

The EDR component monitors every enrolled endpoint in real time: tracking running processes, flagging suspicious binaries, detecting persistence mechanisms, and managing the full investigation lifecycle. The Network component discovers devices on your infrastructure, analyses traffic patterns, maps topology, and detects network-level threats.

Pentesting is where that visibility gets tested, not just observed. It runs real scanning tools — vulnerability scanning, TLS/SSL auditing, port scanning, and API fuzzing — against domains and servers you own, tracks every result as a Finding with a real CVE/CVSS score where one applies, and generates a complete, presentation-ready PDF penetration test report on demand. If you only set one thing up first, make it a Pentesting target — it's the fastest way to see real, verified security posture rather than passive monitoring data.

Kronyx also includes Kronyx AI, a built-in assistant that analyses endpoint and network telemetry, summarises suspicious behaviour, and helps analysts investigate incidents in plain language.

The platform is designed around transparency. Every alert has an audit trail. Every investigation is documented. Every detection is based on observable indicators — no black boxes, no unexplained scores.

New here? Request sandbox access, jump to Quick Start, or open the full documentation for module setup guides and reference.

Platform Structure

Kronyx is organised into three top-level components accessible from the dashboard sidebar: EDR, Network, and Pentesting. Each contains dedicated modules grouped by function.

EDR
  • Detection & Response
  • • Devices
  • • Autoruns
  • • Binaries
  • • Collected Files
  • Management
  • • Escalations
  • • Investigations
  • • Reports
  • Security & Access
  • • Teams
Network
  • Discovery & Analysis
  • • Network Discovery
  • • Traffic Analysis
  • • Network Topology
  • Security
  • • WiFi Security
  • • Port Services
  • • Threat Detection
  • Monitoring
  • • Bandwidth Usage
Pentesting
  • Targets & Scanning
  • • Targets (Domains & Servers)
  • • Scan Types
  • • Full Scan & Scheduling
  • Results & Access
  • • Findings & CVSS
  • • PDF Reports
  • • SARIF / Slack Export
  • • Server Terminal

EDR — Detection & Response

Devices

The central registry of all endpoints enrolled in Kronyx. Each device runs a lightweight agent that continuously reports health and security telemetry.

The device list shows every enrolled endpoint with its current status, operating system, last heartbeat timestamp, and live resource metrics (CPU, memory, disk). From the device detail view you can browse the remote file system, view running processes, and collect files for analysis.

StatusMeaning
ConnectedAgent active and reporting normally
WarningConnected but reporting elevated resource usage
DisconnectedNo heartbeat received — investigate
Full Devices reference

Autoruns

Monitors persistence mechanisms on enrolled endpoints — the locations where malicious software installs itself to survive reboots.

Kronyx tracks autorun entries across Windows registry run keys, startup folders, scheduled tasks, Windows services, macOS login items, LaunchAgents/Daemons, and Linux systemd services and cron jobs. New entries are flagged automatically.

Full Autoruns reference

Binaries

Analyses executables discovered on managed endpoints and checks them against VirusTotal to identify malicious or suspicious files.

Each binary entry shows the file name, path, SHA256 hash, VirusTotal detection score, and the device it was found on. Unsigned binaries are flagged automatically.

VerdictRecommended Action
CleanNo action required
SuspiciousReview context and location
MaliciousTreat as confirmed threat — open investigation immediately
UnknownManually review — unknown does not mean safe
Full Binaries reference

Collected Files

A centralised repository of files pulled from managed endpoints for analysis or evidence preservation.

Every collected file has MD5, SHA1, and SHA256 hashes recorded at the moment of collection. Files can be linked directly to open investigations to build an evidence record.

Full Collected Files reference

EDR — Management

Escalations

Define automated rules that trigger notifications or actions when specific security events occur — ensuring the right person is alerted at the right time.

Rules are configured with a trigger condition (severity level, binary verdict, new autorun, device disconnected, network threat) and an action (notify a team member, notify all admins, or automatically open an investigation).

Full Escalations reference

Investigations

A structured workspace to document and track the full lifecycle of a security event from detection through containment and resolution.

Each investigation has a title, severity, assigned investigator, linked evidence (binaries, autoruns, collected files, network threats), and a full change timeline. Every update is timestamped and attributed to the user who made it.

Full Investigations reference

Reports

Generate summaries of security activity for management review, compliance audits, or team retrospectives.

Select a report type, set the date range, and optionally filter by device, severity, or investigator. Reports cover security posture, threat activity, investigation summaries, and per-device health.

Full Reports reference

EDR — Security & Access

Teams

Manage user accounts, roles, and access within your Kronyx organisation.

RoleAccess Level
AdminFull access to all settings, data, and user management
AnalystOperational access — alerts, investigations, reports
ViewerRead-only access to dashboards and data
Full Teams reference

Network — Discovery & Analysis

Network Discovery

Scans your local network to discover all connected devices and build a live asset inventory.

Results populate in real time as devices respond. New devices are highlighted — review them to confirm they belong on your network. Any unrecognised device should be investigated immediately.

Full Network Discovery reference

Traffic Analysis

Monitors network traffic flowing through your environment and identifies anomalous patterns at the flow level.

The dashboard shows live connection data, top talkers, protocol breakdown, and a historical bandwidth timeline. Common threat patterns detected include data exfiltration, DNS tunnelling, C2 beaconing, and lateral movement.

Full Traffic Analysis reference

Network Topology

A visual map of how devices on your network are connected and related to each other.

Nodes represent devices; edges represent observed connections. Node colour indicates risk status. Kronyx tracks topology changes over time — new devices and connections are logged and can trigger escalation rules.

Full Network Topology reference

Network — Security

WiFi Security

Scans for wireless networks in range and assesses their security posture.

Each detected network is assessed for encryption strength and SSID/BSSID anomalies. Rogue access points — unauthorised APs mimicking your corporate network — are flagged automatically.

Full WiFi Security reference

Port Services

Scans hosts on your network for open ports and identifies what services are running.

Select a scan scope (Quick / Standard / Full), enter a target IP or range, and run the scan. High-risk ports (SSH, RDP, SMB, Telnet, VNC) are flagged with remediation guidance.

Full Port Services reference

Threat Detection

Analyses network traffic behaviour in real time to identify indicators of compromise and active threats.

Categories include C2 communication, data exfiltration, lateral movement, port scanning, DNS anomalies, brute force, and known malicious IPs. Each alert shows the raw traffic data that triggered it.

Full Threat Detection reference

Network — Monitoring

Bandwidth Usage

Tracks network bandwidth consumption per device and across the network, supporting both operational visibility and anomaly detection.

After 7 days of monitoring, Kronyx builds a per-device baseline. Sustained high outbound traffic from a workstation is a common early indicator of data exfiltration.

Full Bandwidth Usage reference

Pentesting — Targets & Scanning

Overview

Pentesting is Kronyx's core capability — the piece that turns everything else the platform collects into an active, adversarial test of your own infrastructure. Real scanning tools, run against your domains and servers, with every result tracked as a Finding carrying severity, a real CVE/CVSS score where one applies, and remediation guidance.

EDR and Network tell you what's running and what's connected. Pentesting tells you what's actually exploitable — the difference between passive monitoring and a verified, fixable security posture. It's the fastest way to get real value out of Kronyx, and worth setting up before anything else.
Full Pentesting reference

Targets (Domains & Servers)

Add a domain — verified via a DNS TXT record — or a server, verified by a real SSH connection, before running active scans against it.

Domains also support passive recon (subdomain discovery, GitHub code-leak search, related domains, CIDR scan) before verification. Servers get real, encrypted credential storage and both key- and password-based auth.

Full Targets reference

Scan Types

Four active scan types map to real, industry-standard tools: Nuclei (vulnerability scanning), a port scanner, testssl.sh (TLS/SSL audit), and Schemathesis-based API fuzzing.

Full Scan Types reference

Full Scan & Scheduling

Run every active scan for a target in a single click, or turn on scheduled scanning to have Kronyx re-test automatically on an interval you choose.

Full Scheduling reference

Pentesting — Results & Access

Findings & CVSS

Every scan result lands as a unified Finding, shared with endpoint and network data, with a real CVSS score resolved — never fabricated — wherever one genuinely applies.

Full Findings reference

PDF Reports

Generate a complete, presentation-ready penetration test report — executive summary, charts, severity-grouped findings, and remediation guidance — directly from real scan results.

Full PDF Reports reference

Exporting

Push findings into your existing tooling — SARIF export (also covers DefectDojo import) or an on-demand Slack notification.

Full Exporting reference

Server Terminal

Every verified server includes a live SSH terminal built directly into Kronyx for fast manual checks, alongside the automated scans.

Full Server Terminal reference

Quick Start

Get your organisation set up and protected in under 30 minutes. Follow these steps in order.

StepActionWhere
1Request sandbox accessrequest form
2Wait for credentialsWe email login details after provisioning
3Sign in and complete onboardingsign in
4Invite your teamEDR → Teams
5Enrol your first deviceEDR → Devices
6Configure escalation rulesEDR → Escalations
7Run a network discovery scanNetwork → Discovery
8Add a pentest target and run your first scanPentesting → Targets
The Admin Setup Guide walks through each step in full detail with screenshots, recommended escalation rules, and a setup checklist.

Research Principles

Kronyx is built as an open, research-oriented platform. The design prioritises transparency, auditability, and evidence integrity over automation and abstraction.

PrincipleImplementation
Full audit trailEvery action is logged with timestamp, user, and affected resource
Transparent detectionsEvery alert shows the raw data that triggered it
Evidence chain of custodyCollected files include hash records and a full collection timeline
Investigator accountabilityAll investigation changes are attributed to the user who made them
No black boxesAll detection logic is based on observable, documented indicators
Open investigation lifecycleInvestigations move from Open → In Progress → Resolved with a full history
Kronyx does not use unexplained risk scores. When a threat is flagged, the reason is always visible — the specific file, connection, process, or behaviour that triggered the alert.

Ready for sandbox access?

Request a private sandbox. We review your request, provision a fresh environment, and email you login details. There is no instant Create Account flow.