Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

KRYOS-XS Console / Service 10

Guided Incident and Response Workflows

Guide teams through structured response without depending on anyone remembering every step during a crisis.

What this service does

The problem, the evidence, and what stays with you

The problem addressed

Complex response should not depend on someone remembering every step during a crisis, and pressure produces containment that stops services to people.

Authorized information required

The incident evidence, affected users and systems, available containment options and the authority model for each action.

The intelligence layer ArtOfTheHack adds

Containment options are compared for consequence and reversibility, the required authority is established and the sequence is ordered before anything is executed.

The decision value you receive

A structured response with authority, rollback and verification attached to every step, and the final outcome preserved.

What remains under your control

Every consequential action requires human authorization and executes in the organization's own systems.

Workflow

The six-stage governed sequence

Nothing in this sequence is skipped. Evidence precedes inference, authority precedes action, and verification precedes assurance.

  1. Stage 01

    Investigate

    The evidence is reviewed and affected users and systems identified.

    Output feeds stage 02: Evaluate

  2. Stage 02

    Evaluate

    Containment options are compared for consequence and reversibility.

    Output feeds stage 03: Confirm authority

  3. Stage 03

    Confirm authority

    Required authority is established and approval requested.

    Output feeds stage 04: Execute

  4. Stage 04

    Execute

    The selected action is executed or recommended in the organization's own systems.

    Output feeds stage 05: Verify

  5. Stage 05

    Verify

    The result is verified and rolled back if necessary.

    Output feeds stage 06: Record

  6. Stage 06

    Record

    The final outcome and evidence are preserved for reporting and review.

    Closes the sequence and returns evidence to the decision record

Hard boundary

Every consequential action requires human authorization, and action is possible only where the existing platform exposes a supported API.

Evidence in

What the workflow reads

  • Suspicious account investigation
  • Phishing response
  • External exposure containment
  • Privilege reduction
  • Access revocation
  • Incident escalation
  • Ransomware containment planning
  • Recovery sequencing
  • Evidence preservation
  • Leadership notification

Decision out

What the workflow returns

  • Ordered response sequence
  • Required authority at each step
  • Rollback requirement
  • Verified result
  • Preserved evidence and final outcome

Authority and action

Who decides, who acts, how it is verified

Service posture
Advisory with approval-gated action
Acting API
The existing enforcement platform action APIs, identity, cloud, mail or endpoint, where they are connected.
Approving authority
A named human authority for each action in the sequence.
Verification
The result of every executed action is verified and the incident record updated with the outcome.
Rollback and reversal
No action enters the sequence without a rollback requirement recorded alongside it.

Connection

What must be authorized

  • Google Workspace admin actions
  • Connected identity, cloud, mail or endpoint action APIs where available
Delivery
Authorized API integration, webhooks, or structured evidence submissions. No endpoint agent, no appliance, no product replacement.
System of record
The connected source platform remains the system of record and the point of enforcement. ArtOfTheHack proposes; the source system acts.
Cost to the grantee
KRYOS-XS is provided at no cost to eligible nonprofits under a grant funded by James Scott and administered by the Embassy Row Project.
  • Read-only advisory operation by default
  • Human approval for high-impact actions
  • Least-privilege, revocable permissions
  • Explicit blind spots instead of assumed facts
  • Reversible enforcement wherever technically available