Known State logo: a navy shield containing a letter K built from a network of connected nodes

Known State

Managed cybersecurity / SOC

Managed Cybersecurity & Custom Business Software. Know your state first.

Continuous threat detection and response, plus the business software your operation actually runs on. Built and monitored by one team.

A live animated network diagram runs behind this page: nodes represent monitored systems, cyan packets represent telemetry, and a red pulse shows an intrusion being intercepted by SentinelIQ.

01 / Live triage

An alert lands. Watch what happens next.

SentinelIQ ingests telemetry, correlates it across identity and network, and runs a scoped containment playbook — while the analyst watches the same stream you do.

  • Pick a scenario and follow the raw log stream in real time.
  • Every agent step is named, ordered and timestamped.
  • Containment is a playbook you approved, not a black box.

Illustrative scenarios built from real detection logic.

Telemetry stream

00:00:00
  • >

Agent chain

  1. Ingest
  2. Detect
  3. Correlate
  4. Decide
  5. Respond

Verdict

ANALYZING

Correlating signals

CONTAINED

Auto-response executed

See how it works

Agents ingest telemetry, score behaviour against your baseline, correlate across identity and network, then execute a scoped containment playbook.

02 / Finding to fix

Every finding ships with proof and a fix.

No severity badge without evidence. Each artifact carries the reproduction, the patch, and the full timeline of who did what and when.

  • Finding: reproducible request/response, not a scanner guess.
  • Fix: the exact change, reviewed before it goes out.
  • Timeline: detection, containment and closure, timestamped.

Real reports are generated per scan and expire on a signed URL.

High

Reflected XSS in search parameter

CWE-79 · OWASP A03:2021 · CVSS 7.4 · layer: web

AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Endpoint

GET /search?q=<payload>

Proof
> GET /search?q=%3Csvg%2Fonload%3Dconfirm(1)%3E HTTP/1.1
> Host: app.example.com
> Accept: text/html,application/xhtml+xml
> Cookie: session=<redacted>

< HTTP/1.1 200 OK
< Content-Type: text/html; charset=utf-8
< X-Content-Type-Options: nosniff
<
< <main class="results">
<   <h2>Results for <svg/onload=confirm(1)></h2>
<   <p class="empty">No matches found.</p>
< </main>

reflection: unencoded in HTML body context (offset 214)
sink: innerHTML via server-side template interpolation
validated: truededup: 9f3a…c21status: open

Illustrative output. Real reports are generated per scan and expire on a signed URL.

03 / Custom business software

The systems your business runs on.

Operations software with approval routes, SLAs and an audit trail. This is the surface, running — not a screenshot of one.

  • Approval routes and SLA timers that reflect your real policy.
  • Automated rules that write an immutable audit entry every time they fire.
  • Built and monitored by the same team that secures it.

Acme Distribution / Operations

⌘K

Intake 2

₹5,46,700

REQ-2201

Nandi Packaging₹1,84,200

Ron track

PO-4415

Vertex Cold Chain₹3,62,500

A4h left

Approval 3

₹4,51,050

PO-4412

Sundar Metals₹2,41,900

S4h left

INV-9930

Larkspur Freight₹96,400

Blocked · awaiting vendor GST doc

Soverdue 1d

GRN-8871

Orbit Components₹1,12,750

Mon track

Fulfilment 1

₹5,08,300

PO-4390

Meghna Textiles₹5,08,300

Aon track

Automation rules

  • PO over ₹2L → route to Finance
  • Vendor doc expiring in 7d → notify owner
  • GRN mismatch > 2% → hold payment

Rules run server-side. Every trigger is written to the audit log.

Audit trail

  • 14:02:11 rule:po_threshold routed PO-4412 → Finance
  • 14:00:52 rule:grn_variance held payment on GRN-8871
  • 13:58:40 s.mehta approved INV-9930
  • 13:55:03 rule:vendor_docs flagged Larkspur Freight GST
  • 13:49:27 system synced 42 inventory lines
  • 13:44:19 a.rao created PO-4415

Throughput

Built to your process

Approval routes, SLAs and thresholds are configured to how your team already works, not to a template.

One team, one throat to choke

The people who built the workflow are the people monitoring it. No handoff between the software vendor and the security vendor.

Everything is auditable

Every automated action writes an immutable log entry with actor, rule and timestamp.

THREAT DETECTION AND RESPONSE

Five stages. One continuous loop.

Scroll to run the pipeline. Scroll back to rewind it.

Stage 1

Assess

We map every asset, identity, and gap. No guesswork.

Stage 2

Harden

Configuration, access, and patch debt closed in priority order.

Stage 3

Monitor

SentinelIQ watches continuously. Signals, not noise.

Stage 4

Respond

Playbooks contain the incident while humans verify.

Stage 5

Prove

Evidence and reporting your auditors accept first pass.

How we work

Four steps, no mystery

The same engagement shape for every client, from first call to monthly report.

  1. 01

    Scope & baseline

    We inventory your systems and record where you stand today.

  2. 02

    Deploy sensors

    Telemetry from endpoints, cloud, network and code flows into SentinelIQ.

  3. 03

    24x7 monitoring

    Detections are triaged by the platform and reviewed by our analysts.

  4. 04

    Contain & report

    Containment runs on agreed playbooks, then you get the written record.

What you get

Concrete deliverables written into the engagement — not implied outcomes.

Onboarding assessment

A written baseline of your attack surface, with prioritised findings and owners.

Monitored coverage

An agreed list of systems and data sources under continuous monitoring.

Response SLA

Contractual acknowledgement and containment targets by severity, agreed before go-live.

Monthly reporting

Findings, actions taken, open risk and framework control mapping, in one document.

Coverage, not counters

8
Attack surface layers monitored

Web · API · Mobile · Cloud · Network · SAST · CI/CD · LLM

14
MITRE ATT&CK tactics mapped

Detection rules mapped technique-by-technique. Blind spots shown, not hidden.

4
Frameworks your findings map to

Open findings mapped to specific SOC 2, ISO 27001, PCI DSS and NIST CSF controls.

0
Unverified findings shipped

Every finding carries reproducible proof and a dedup hash.

These describe what the platform covers — not customers, not blocked-attack counts. We don't publish a number we can't show you the source of.

GET A QUOTE

Tell us the shape of the problem.

Three steps. Your scope builds itself on the right as you choose.

Step 1 of 3 — What you need

What do you need? Choose all that apply.

Common questions

What does managed cybersecurity from Known State include?

24/7 SOC monitoring, threat detection and response, hardening, and audit-ready reporting, all run on SentinelIQ.

How fast is your response time?

Playbooks execute automatically within the scope you approve in advance. Anything outside that scope escalates to an analyst first. Containment targets are set contractually per severity before go-live, and we report against them monthly. Critical incidents are acknowledged and contained to the SLA you signed — not to an average we quote.

Do you build software as well as secure it?

Yes. We build BI dashboards, logistics management software, ERP systems, and custom internal tools.

Can you work alongside our existing IT team?

Standard. We plug into your stack and escalation paths rather than replacing your team.