SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
United States
RiskProfiler launches KnyX Autonomous Investigations

RiskProfiler launches KnyX Autonomous Investigations

Wed, 5th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

RiskProfiler has launched KnyX Autonomous Investigations, a new product designed to automate investigations and responses to external cyber threats.

The launch adds an AI-based investigation layer to the company's digital risk protection and external threat intelligence offering, focusing on security alerts that would otherwise require manual analyst review.

Automated investigations

Security teams are dealing with a rising volume of alerts from sources such as leaked credentials, phishing pages, look-alike domains, vendor-breach signals and threat-intelligence feeds. KnyX is intended to move beyond detection by taking alerts through investigation, verdict and remediation.

According to RiskProfiler, the system uses AI agents to gather evidence, assess incidents and produce confidence-scored verdicts. Where customer policies allow, it can also execute or initiate remediation actions.

The investigation process is based on deterministic, structured steps rather than free-form AI outputs. Each case is supported by schema-validated evidence and an audit trail that records inputs, outputs, execution history, and the versions of the agents and skills used.

Policy-based control

The aim is to address a central concern for security teams considering automation in incident response: whether they can act quickly without giving up control. Organisations can set policies so remediation actions are carried out automatically, sent for approval or disabled.

At launch, KnyX includes agents for leaked credential investigations and policy-based password resets, look-alike and typosquatted domain investigations, live phishing-page analysis and evidence collection, vendor-breach validation and exposure assessment, and threat-intelligence filtering and prioritisation.

These functions are designed to validate compromised credentials, assemble evidence for takedown processes, cross-check breach claims and reduce large volumes of threat data based on an organisation's technology stack, vendor relationships and broader risk environment.

Guardrails in place

RiskProfiler also outlined some operating limits. Credential validation is carried out only for verified customer-owned domains and authorised identity providers, while vendor-breach claims are checked against multiple trusted sources before any response is initiated.

The product is now available to customers.

Setu Parimi outlined the rationale for the launch.

"Security teams do not lack detection tools. What they are increasingly drowning in is triage, with the same manual investigations being repeated thousands of times every week," said Setu Parimi, Co-Founder & CTO, RiskProfiler. "KnyX Autonomous Investigations performs that work the way a senior analyst would and then takes the next step by acting where policy allows. Every step is governed by customer-defined controls and backed by evidence, enabling CISOs to adopt autonomous response without losing oversight."

The product has also been endorsed by an early user in a senior security role.

"We've held back on autonomous response for years because 'let the tool act on its own' was never a sentence I could say to my board. KnyX is the first thing that let me turn it on one action at a time, with a policy and an audit trail behind every move. It's automation I can actually defend," said Kamran Siddique, CISO at Steve Madden.