Offline-first · air-gap capable

Turn raw logs into defensible findings.

KIROSEC ingests Windows, Linux, macOS, and cloud logs, normalizes them to a canonical event model with searchable structured fields, and runs 324 versioned detection rules that tell you what happened and why — fully offline.

See how it works
324
detection rules
100%
offline
0
forced telemetry
KIROSEC — desktop analyzer
KIROSEC security investigation overview
Screenshot 1 of 5: KIROSEC security investigation overview
Detections

What KIROSEC looks for

KIROSEC hunts for the behaviors attackers rely on to break in, move laterally, and exfiltrate data — even when tools are renamed, logs are missing, or the network is offline.

Brute-force & suspicious logins

Failed-logon bursts, RDP/SSH from new sources, off-hours access.

Suspicious command execution

Encoded PowerShell, download cradles, Office spawning shells.

Known offensive tooling

SharpHound, Mimikatz, Rubeus, Impacket, Cobalt Strike — from an offline threat knowledge base.

Persistence

Scheduled tasks, services, Run keys, cron, LaunchAgents.

New users & privilege abuse

New accounts, Administrators additions, elevation events.

Ransomware & exfiltration

Shadow-copy deletion, archive staging, cloud & USB exfil, C2 ports.

Web application attacks

SQLi, path traversal, web shells, Log4Shell, scanner traffic — from Apache/Nginx logs.

Security-tool tampering

Defender disabled, security log cleared, firewall changes, remote access.

Cloud identity & control-plane abuse

Sign-in sprays, MFA tampering, OAuth consent grants, inbox forwarding rules, admin-role grants — Microsoft 365 and Entra, AWS, Okta, Google Workspace.

Live demo

Watch it find one

The real detection engine over a synthetic Microsoft 365 audit sample committed in this repo — no customer data. Drag across the histogram to filter by time; what appears is what the desktop app shows.

KTimelineCase 1 · open
5,732 events · 1 source
2026-06-07 07:24Z2026-07-02 01:50Z
Detections in range9
Cloud sign-in brute force
cloud.identity.entra_signin_brute_force · T1110

Repeated failed cloud sign-ins from one IP against a single user inside a short window — password guessing against the cloud control plane.

Critical incident · Brute force likely succeeded — a.rivera@example.com from 192.0.2.155
Evidence · a.rivera@example.com192.0.2.155
12:28:29ZFAILEDAzureActiveDirectory · 192.0.2.155
12:28:36ZFAILEDAzureActiveDirectory · 192.0.2.155
12:31:38ZFAILEDAzureActiveDirectory · 192.0.2.155
12:32:42ZFAILEDAzureActiveDirectory · 192.0.2.155
12:33:16ZFAILEDAzureActiveDirectory · 192.0.2.155
12:35:11ZFAILEDAzureActiveDirectory · 192.0.2.155
12:36:15ZSUCCESSAzureActiveDirectory · 192.0.2.155
12:36:28ZSUCCESSAzureActiveDirectory · 192.0.2.155

6 failures in ~7 min, then 2 successful logons from the same IP — the burst-then-success pattern the engine escalates to a takeover incident.

236 rules5,732 events2 high11 medium62 low12 incident candidatesEngine output · synthetic Microsoft 365 audit sample
New

Answers from a single paste

Drop logs or PowerShell output into Triage — no files, no import. KIROSEC highlights what matters, scores risk, and explains the “why” in plain English.

CSVTXTEVTXJSONPS1
insight > analyze

HIGH  Brute-force logon from 203.0.113.45
HIGH  PowerShell encoded command launched
MED   New local admin created: svc_backup
LOW   Scheduled task persistence detected

4 findings · 1m 24s
Security & compliance

Built to be trusted with your logs

Security analysis you can defend — evidence stays intact, nothing phones home, and our controls are documented against recognized standards.

  • OWASP ASVS 4.0.3L2 self-assessed · published
  • CAIQ v4 (CCM)Self-assessment · published
  • GDPRPrivacy by design
  • Offline-firstAir-gap capable
  • Zero forced telemetryNo phone-home
  • Signed rule packsTamper-evident detections

These are self-assessments we publish in full, not third-party certifications — read the ASVS L2 attestation and the CAIQ v4 self-assessment, open gaps included. We are not listed in the CSA STAR Registry yet, and independent audits (SOC 2, ISO 27001) are on our roadmap.

Workflow

How it works

From raw logs to clear answers in four simple steps.

1

Import

Drop in Windows, Linux, macOS, network and cloud logs — EVTX, Sysmon, syslog, M365 and Entra exports, CloudTrail, Okta and more. Zips and rotated logs open directly.

Offline-first
2

Normalize

Everything becomes canonical events with honest timestamps and a preserved evidence chain — and nested JSON becomes columns you can actually filter on.

Privacy-respecting
3

Detect

324 versioned rules flag brute force, suspicious execution, persistence, ransomware, exfiltration and cloud identity abuse — then group what belongs together into incidents.

Always up to date
4

Investigate

Pivot from an alert to the whole story — filter the timeline, follow a user or host through the entity graph, and see what else moved with it.

Follow the thread
Built for responders

Why responders choose KIROSEC

Built for offline investigations, trusted findings, and analyst speed.

Offline-first, by design

Analyze anywhere — air-gapped, on-scene, or in isolated networks. No telemetry leaves your environment.

Global reach with all analysis kept local — no telemetry leaves your environment

Evidence-backed & explainable

Every finding links to the exact evidence, signed rule, and MITRE technique. Know why it is suspicious.

Evidence
Source IP203.0.113.45MITRET1110
View full evidence

Plain-language findings

Every alert says what happened, to whom, and why it matters — in words you can hand to someone non-technical.

Executive summary

2 high, 3 medium, 5 low risk findings

High risk 2
Medium risk 3
Signed rule packsMITRE mappedAnalyst-friendly workflowRegular updatesCommunity & enterprise support
Trusted by security teams

Built for real investigations.
Trusted when it matters.

From first triage to a clear answer, KIROSEC helps your team move faster with confidence — even in the toughest environments.

10×
Faster triage
95%+
High-fidelity signal
100%
Your data stays yours
Closed beta

Pricing lands at general availability

We are working with a small group of teams before we open up. Book a demo and we will walk you through the product and where it is heading.

Closed beta · Offline-first

See it on your own logs.

KIROSEC is in closed beta. Book a walkthrough and we will show you a real case end to end — import, detections, and the write-up that comes out.

Runs fully offlineNo telemetryYour logs stay yours