RECONIFIED
  • [ Home ]
  • [ Platform ]
  • [ Features ]
  • [ Coverage ]
  • [ About ]
  • Request a demo
Request a demo
// About RECONIFIED //

Endpoint defense you can audit

RECONIFIED is a single-host Windows EDR/XDR console, designed so that every process, file, port and privileged action it uses can be inspected by you or a third-party auditor.

Audit checklist
Learn more

0
Kernel drivers or services
3s
Sensor scan interval
1Hz
Host telemetry sampling
11
Operator consent grants
// Principles //

Four rules the build never breaks

User mode only

Win32, ETW and documented Windows APIs. No minifilter, ELAM, PPL or kernel callback.

Consent before action

Each privileged action needs a matching operator grant and its own Windows UAC prompt.

Local by default

Telemetry, alerts and cases stay in SQLite under ProgramData. Egress only goes where you point it.

Tamper-evident audit

Grant, policy, containment and quarantine changes are chained with SHA-256, so edits and gaps show up.

// Architecture //

Two executables, four crates

Tauri 2 and WebView2 render the console. Rust owns sensors, storage and actions. The UI talks to the agent over Tauri commands, not a web API.

Audit checklist

reconified-app.exe

The Tauri console, tray, local API, sensors and SQLite. Runs at medium integrity.


Console

reconified-elevated.exe

One allowlisted action after a UAC prompt, then it exits. No WebView, no command line.


Elevated helper

reconified-core

Agent, scan cache, detection, policy, grants, hunt and the audit chain.


Agent

reconified-sensors

Windows collection and response through Win32, ETW, firewall and service APIs.


Sensors
// Audit checklist //

What an audit can verify

None of these checks need the vendor. Run them on any host with RECONIFIED and compare the results with this page.

No kernel driver, no service

Confirm neither appears in the process tree or in sc.exe. Only reconified-app.exe runs, at medium integrity.

Process tree, sc.exe
Check 01

Grants match the host

Read operator-grants.json and compare it with the sign-in task, the ETW session and the firewall rule list.

operator-grants.json
Check 02

The API rejects bad keys

Call /v1/health with no key and with the published development string. Both must return 401.

127.0.0.1:9477
Check 03

Listeners are loopback only

The read-only REST port 9477 and the SSO redirect port 9478 bind to 127.0.0.1 and nothing else.

netstat
Check 04

Secrets are locked down

local-api-key, local-policy-key and idp.json are readable only by SYSTEM, Administrators and the current user.

icacls
Check 05

The audit chain is intact

Run the verifier against tier1.db and record head_hash somewhere outside the host.

tier1.db
Check 06

Live response is allowlisted

Send a command outside the allowlist and confirm it is refused.

Live response
Check 07

No silent privilege

Firewall, terminate and ETW session creation fail from reconified-app.exe alone. A denied UAC prompt leaves the action failed.

UAC
Check 08

Sign-in start is LIMITED

If RECONIFIED\Background exists on an unpackaged install, its run level is LIMITED, not HIGHEST.

Task Scheduler
Check 09
// Frequently asked questions //

Have a question?

Straight answers about what RECONIFIED does and does not do on a Windows PC.

01/

Does RECONIFIED install a kernel driver or a service?

No. Collection and response run in user mode through documented Windows APIs. Two executables ship: the medium-integrity console and a one-shot elevated helper that exits after each action.

02/

What does the XDR side connect to?

Only what you configure: Entra risk detections and Microsoft 365 alerts through Graph, a TAXII 2.1 threat-intel server, a SIEM export destination and SOAR webhooks. With nothing configured, nothing leaves the PC.

03/

Which platforms are supported?

Windows only, one PC per console. A multi-tenant cloud console and a central policy server are not part of this build. Non-Windows builds of the sensor crate return UnsupportedPlatform.

04/

Can RECONIFIED act without my approval?

No. Every privileged action needs a matching operator grant and the elevated helper, and Windows shows UAC unless the helper is already elevated. Automatic termination and isolation stay off until you enable them.

RECONIFIED
Contact us
Email address
info@reconified.com
Platform
Windows, single host
Product
  • Home
  • Platform
  • Features
  • Coverage
  • About
  • Contact
Legal
  • Privacy Policy
  • Terms of Use
Copyright © RECONIFIED. Windows EDR/XDR console, version 1.0.