KRYOS-XS Console / Service 05
Account-Compromise Assessment
Distinguish legitimate unusual behavior from potential account compromise using available identity evidence.
What this service does
The problem, the evidence, and what stays with you
The problem addressed
Unusual login activity looks identical whether a researcher is travelling or an account has been taken over, and the wrong call either strands fieldwork or leaves an intruder inside.
Authorized information required
Login location, device history, authentication events, administrative activity, file access, sharing activity, user role, recent behavioral changes and related alerts.
The intelligence layer ArtOfTheHack adds
The safe and dangerous explanations are compared directly, evidence age is checked and the assessment escalates when the available facts cannot support a determination.
The decision value you receive
A compromise likelihood with the competing explanation stated, a proportionate response and a recovery path.
What remains under your control
The identity administrator approves, and enforcement runs in the organization's own identity platform.
Workflow
The six-stage governed sequence
Nothing in this sequence is skipped. Evidence precedes inference, authority precedes action, and verification precedes assurance.
Stage 01
Define
The exact question is stated: is this account compromised, or behaving unusually for a legitimate reason.
Output feeds stage 02: Gather
Stage 02
Gather
Login location, device history and authentication events are collected.
Output feeds stage 03: Connect
Stage 03
Connect
Administrative activity, file access and sharing activity are joined to the same identity.
Output feeds stage 04: Compare
Stage 04
Compare
User role, recent behavioral changes and related security alerts are weighed against the benign explanation.
Output feeds stage 05: Recommend
Stage 05
Recommend
A proportionate response is proposed with the required authority named.
Output feeds stage 06: Verify
Stage 06
Verify
Account state is rechecked after the approved action and the outcome recorded.
Closes the sequence and returns evidence to the decision record
Hard boundary
Where evidence is insufficient, KRYOS escalates rather than creating false certainty. Enforcement runs in the organization's own identity platform.
Evidence in
What the workflow reads
- Login location
- Device history
- Authentication events
- Administrative activity
- File access
- Sharing activity
- User role
- Recent behavioral changes
- Related security alerts
Decision out
What the workflow returns
- Compromise likelihood with the competing explanation stated
- Confidence and uncertainty
- Missing information
- Recommended response
- Required approver
- Verified outcome
Authority and action
Who decides, who acts, how it is verified
- Service posture
- Advisory with approval-gated action
- Acting API
- Google Workspace admin APIs, and identity provider session and credential APIs where connected.
- Approving authority
- The identity administrator, joined by the staff-safety authority where personal safety is implicated.
- Verification
- Session state, recovery path and subsequent account activity are checked after the action.
- Rollback and reversal
- Access restoration and recovery steps are defined before the action is approved.
Connection
What must be authorized
- Google Workspace login and admin evidence
- Identity provider integration where available
- Delivery
- Authorized API integration, webhooks, or structured evidence submissions. No endpoint agent, no appliance, no product replacement.
- System of record
- The connected source platform remains the system of record and the point of enforcement. ArtOfTheHack proposes; the source system acts.
- Cost to the grantee
- KRYOS-XS is provided at no cost to eligible nonprofits under a grant funded by James Scott and administered by the Embassy Row Project.
- Read-only advisory operation by default
- Human approval for high-impact actions
- Least-privilege, revocable permissions
- Explicit blind spots instead of assumed facts
- Reversible enforcement wherever technically available
Product
Where this capability sits
Product 02
KRYOS-XS Console
A centralized Cyber Decision Operations Hub that converts alerts, identity risks, access questions, data exposures and response requirements into one prioritized decision queue.
Adjacent capabilities
Other capabilities in this product
Alert Triage and Incident Adjudication
Consolidate security alerts into a prioritized decision queue and connect related events so the broader situation is evaluated.
Access and Entitlement Review
Identify unnecessary, outdated or unusually powerful access and recommend what should change.
Privileged-Access Governance
Understand who holds administrative authority, why it exists, whether it remains necessary and what compromise would cost.
External-Party Access Governance
Decide which external access should be retained, restricted, reviewed or revoked.
OAuth and Automation Authority Governance
Evaluate applications, integrations and automated agents requesting organizational access, before and after the grant.
Guided Incident and Response Workflows
Guide teams through structured response without depending on anyone remembering every step during a crisis.
Board, Funder and Framework Reporting
Turn the accumulated Decision Ledger into clear institutional reporting generated from real decision history.
