Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

KRYOS-XS Console / Service 05

Account-Compromise Assessment

Distinguish legitimate unusual behavior from potential account compromise using available identity evidence.

What this service does

The problem, the evidence, and what stays with you

The problem addressed

Unusual login activity looks identical whether a researcher is travelling or an account has been taken over, and the wrong call either strands fieldwork or leaves an intruder inside.

Authorized information required

Login location, device history, authentication events, administrative activity, file access, sharing activity, user role, recent behavioral changes and related alerts.

The intelligence layer ArtOfTheHack adds

The safe and dangerous explanations are compared directly, evidence age is checked and the assessment escalates when the available facts cannot support a determination.

The decision value you receive

A compromise likelihood with the competing explanation stated, a proportionate response and a recovery path.

What remains under your control

The identity administrator approves, and enforcement runs in the organization's own identity platform.

Workflow

The six-stage governed sequence

Nothing in this sequence is skipped. Evidence precedes inference, authority precedes action, and verification precedes assurance.

  1. Stage 01

    Define

    The exact question is stated: is this account compromised, or behaving unusually for a legitimate reason.

    Output feeds stage 02: Gather

  2. Stage 02

    Gather

    Login location, device history and authentication events are collected.

    Output feeds stage 03: Connect

  3. Stage 03

    Connect

    Administrative activity, file access and sharing activity are joined to the same identity.

    Output feeds stage 04: Compare

  4. Stage 04

    Compare

    User role, recent behavioral changes and related security alerts are weighed against the benign explanation.

    Output feeds stage 05: Recommend

  5. Stage 05

    Recommend

    A proportionate response is proposed with the required authority named.

    Output feeds stage 06: Verify

  6. Stage 06

    Verify

    Account state is rechecked after the approved action and the outcome recorded.

    Closes the sequence and returns evidence to the decision record

Hard boundary

Where evidence is insufficient, KRYOS escalates rather than creating false certainty. Enforcement runs in the organization's own identity platform.

Evidence in

What the workflow reads

  • Login location
  • Device history
  • Authentication events
  • Administrative activity
  • File access
  • Sharing activity
  • User role
  • Recent behavioral changes
  • Related security alerts

Decision out

What the workflow returns

  • Compromise likelihood with the competing explanation stated
  • Confidence and uncertainty
  • Missing information
  • Recommended response
  • Required approver
  • Verified outcome

Authority and action

Who decides, who acts, how it is verified

Service posture
Advisory with approval-gated action
Acting API
Google Workspace admin APIs, and identity provider session and credential APIs where connected.
Approving authority
The identity administrator, joined by the staff-safety authority where personal safety is implicated.
Verification
Session state, recovery path and subsequent account activity are checked after the action.
Rollback and reversal
Access restoration and recovery steps are defined before the action is approved.

Connection

What must be authorized

  • Google Workspace login and admin evidence
  • Identity provider integration where available
Delivery
Authorized API integration, webhooks, or structured evidence submissions. No endpoint agent, no appliance, no product replacement.
System of record
The connected source platform remains the system of record and the point of enforcement. ArtOfTheHack proposes; the source system acts.
Cost to the grantee
KRYOS-XS is provided at no cost to eligible nonprofits under a grant funded by James Scott and administered by the Embassy Row Project.
  • Read-only advisory operation by default
  • Human approval for high-impact actions
  • Least-privilege, revocable permissions
  • Explicit blind spots instead of assumed facts
  • Reversible enforcement wherever technically available