RECONIFIED
  • [ Home ]
  • [ Platform ]
  • [ Features ]
  • [ Coverage ]
  • [ About ]
  • Request a demo
Request a demo
// RECONIFIED EDR / XDR //

Endpoint defense you can actually audit

A Windows EDR/XDR console that collects endpoint telemetry in user mode, keeps it on the machine, and asks for your consent before every privileged response.

Request a demo
Learn more

Built on documented Windows APIs and open components
Win32
/
ETW
/
Rust
/
Tauri 2
/
WebView2
/
SQLite
/
OIDC + PKCE
/
Win32
/
ETW
/
Rust
/
Tauri 2
/
WebView2
/
SQLite
/
OIDC + PKCE
/
Win32
/
ETW
/
Rust
/
Tauri 2
/
WebView2
/
SQLite
/
OIDC + PKCE
/
Win32
/
ETW
/
Rust
/
Tauri 2
/
WebView2
/
SQLite
/
OIDC + PKCE
/
Win32
/
ETW
/
Rust
/
Tauri 2
/
WebView2
/
SQLite
/
OIDC + PKCE
/
Win32
/
ETW
/
Rust
/
Tauri 2
/
WebView2
/
SQLite
/
OIDC + PKCE
/
Win32
/
ETW
/
Rust
/
Tauri 2
/
WebView2
/
SQLite
/
OIDC + PKCE
/
Win32
/
ETW
/
Rust
/
Tauri 2
/
WebView2
/
SQLite
/
OIDC + PKCE
/
Win32
/
ETW
/
Rust
/
Tauri 2
/
WebView2
/
SQLite
/
OIDC + PKCE
/
// Why RECONIFIED //

User-mode visibility, operator-controlled response

No driver, no service

Sensors run in user mode through documented Win32, ETW, firewall and service APIs. Nothing is loaded into the kernel and nothing is installed as a Windows service.

Continuous local telemetry

Processes, network, persistence and host resources are scanned every few seconds and stored in SQLite on the PC. Nothing is uploaded unless you configure a destination.

Request a demo
// Platform //

One console for detection, response & XDR

Process & network telemetry

Process DNA with path, command line, SHA-256 and Authenticode verdict, plus the connection table, DNS cache and per-process bytes from ETW.

Learn more


Malware & memory

Hash matching against a local list, path heuristics, module walks and private RWX memory checks, on demand and on a schedule.



Persistence & scripts

Run keys, scheduled tasks, WMI subscriptions, services, vulnerable drivers and PowerShell script blocks.



XDR connectors

Optional Entra and Microsoft 365 signals, TAXII 2.1 threat intel, SIEM export and SOAR webhooks.


Request a demo
Explore the platform

// Response //

Containment that asks first

See coverage


Terminate a process tree

Stop a process or its whole tree through the one-shot elevated helper, after the termination grant and a Windows UAC prompt.



Block an IP or isolate the host

Named Windows Firewall rules you can see in wf.msc. Host isolation is one outbound block rule that is just as easy to release.



Quarantine a suspicious file

Move a selected file into the RECONIFIED quarantine folder with its original name kept, gated by the quarantine grant.



Allowlisted live response

Built-in checks only: ps, netstat, filehash, reg query, ls, whoami and env. Any other command text is refused.

// How it works //

From sign-in to response

RECONIFIED runs as a single-host Windows console. Setup takes four steps, and nothing privileged happens until you say so.

01/

Sign in with your IdP

The console opens behind an OIDC authorization-code flow with PKCE for Microsoft Entra or Google. The session is held in memory.

02/

Grant permissions

Choose what RECONIFIED may do: network telemetry, firewall containment, process termination, quarantine, live response and more. Each choice is saved to operator-grants.json.

03/

Watch the command center

Telemetry refreshes about once a second. Hunt across processes, network, persistence, AMSI events and alerts mapped to MITRE ATT&CK.

04/

Respond with consent

Terminate, block, isolate or quarantine through a one-shot elevated helper. Windows shows UAC for each action and every step lands in the audit chain.

// Get in touch //

See what your endpoints are really doing

Request a demo
// Audit //

Verify it without the vendor

RECONIFIED is built to be checked. Here are two of the nine things an auditor can confirm on a running host.

No kernel driver and no service on the host

Check the process tree and sc.exe. The console runs at medium integrity, and the elevated helper only exists while one action runs.


Audit check
01

The local API refuses unauthenticated calls

Call 127.0.0.1:9477/v1/health with no key or the published development key. Both return 401, and the listener never binds off-box.


Audit check
03
See all nine audit checks


No kernel driver. No service. Every privileged action asks Windows first.

Process model
//
Medium integrity by default

Nothing leaves the PC unless you configure a destination.

Egress
//
Local-first storage

Every grant, containment and quarantine lands in a SHA-256 linked audit chain.

Audit
//
Tamper-evident log

No kernel driver. No service. Every privileged action asks Windows first.

Process model
//
Medium integrity by default

Nothing leaves the PC unless you configure a destination.

Egress
//
Local-first storage

Every grant, containment and quarantine lands in a SHA-256 linked audit chain.

Audit
//
Tamper-evident log

No kernel driver. No service. Every privileged action asks Windows first.

Process model
//
Medium integrity by default

Nothing leaves the PC unless you configure a destination.

Egress
//
Local-first storage

Every grant, containment and quarantine lands in a SHA-256 linked audit chain.

Audit
//
Tamper-evident log

No kernel driver. No service. Every privileged action asks Windows first.

Process model
//
Medium integrity by default

Nothing leaves the PC unless you configure a destination.

Egress
//
Local-first storage

Every grant, containment and quarantine lands in a SHA-256 linked audit chain.

Audit
//
Tamper-evident log

No kernel driver. No service. Every privileged action asks Windows first.

Process model
//
Medium integrity by default

Nothing leaves the PC unless you configure a destination.

Egress
//
Local-first storage

Every grant, containment and quarantine lands in a SHA-256 linked audit chain.

Audit
//
Tamper-evident log
// Documentation //

Know exactly what runs on your PC

The architecture notes describe the software as it is: every process, file, port and Windows API it touches.

Architecture and Windows operation notes

Process model, operator consent, data at rest, listeners and egress.

Architecture
v1.0

Detection and response coverage

What each sensor collects, which actions exist, and what is out of scope.

Coverage
v1.0
Read the architecture notes

RECONIFIED
Contact us
Email address
info@reconified.com
Platform
Windows, single host
Product
  • Home
  • Platform
  • Features
  • Coverage
  • About
  • Contact
Legal
  • Privacy Policy
  • Terms of Use
Copyright © RECONIFIED. Windows EDR/XDR console, version 1.0.