KnyX Autonomous Investigations is the newest AI-powered capability from RiskProfiler, a digital risk protection and external threat intelligence platform. Announced on August 5, 2026, the solution helps security teams investigate, validate and remediate external cyber threats through policy-governed automation. RiskProfiler is showcasing the technology live at Black Hat USA and will also demonstrate it at DEF CON 34 in Las Vegas.
Why Manual Threat Triage No Longer Works
Modern security operations centres are flooded with alerts. Look-alike domains, typosquatted websites, leaked credentials, vendor breach notifications, live phishing pages and raw threat intelligence feeds all compete for attention at the same time. Detection tools keep firing alerts, yet every incident still needs to be investigated and validated largely by hand. As a result, analysts burn hours on repetitive checks, responses get delayed, and real risks stay exposed for longer.
KnyX Autonomous Investigations was built to remove that bottleneck. Instead of adding one more dashboard, it automates the entire investigation lifecycle through a continuous four-step workflow: Alert, Investigate, Verdict and Remediate.
How KnyX Autonomous Investigations Works
The platform’s AI agents collect the same evidence a human analyst would gather, weigh it, and produce a confidence-scored verdict. Where customer-defined policies allow, the agents then execute or initiate remediation actions automatically.
Importantly, the agents do not rely on free-form AI outputs alone. Each investigation follows deterministic, structured steps. Evidence is schema-validated and every action is logged, so verdicts remain transparent, reproducible and defensible in front of auditors, boards and regulators.
Speed Without Losing Control
Automation in cybersecurity always raises a question of trust. KnyX addresses this by keeping governance at the centre of every action. Each remediation step follows policies defined by the customer, so organisations choose whether an action runs automatically, goes to a human for approval, or stays disabled entirely.
Additional safeguards include:
- Credential validation runs only on verified, customer-owned domains and authorised identity providers.
- Vendor breach claims are cross-checked against multiple trusted sources before any response begins.
- Every investigation records its inputs, outputs, evidence, execution history and the exact versions of agents and skills used.
Together, these controls create a complete audit trail for review, governance and compliance, giving security leaders the confidence to switch on autonomous response one action at a time.
Five Autonomous Agents Available at Launch
At launch, KnyX ships with five focused agents that cover the most repetitive, high-volume investigations on a modern security team’s plate:
Leaked Credential Investigation
This agent validates compromised credentials and, where policy permits, triggers policy-based password resets, cutting off account-takeover attempts early.
Look-Alike and Typosquatting Domain Investigation
It analyses suspicious domains that imitate the brand and helps teams separate harmless pages from active fraud infrastructure.
Live Phishing Page Analysis
The agent inspects live phishing pages, captures screenshots and hosting details, and assembles takedown-ready evidence packages.
Vendor Breach Validation
It cross-checks third-party breach claims across trusted sources and assesses real exposure before anyone raises a false alarm.
Threat Intelligence Filtering and Prioritisation
It filters massive threat intelligence volumes against the organisation’s technology stack, vendor ecosystem and risk environment, so only relevant signals reach analysts.
What Security Leaders Are Saying
Setu Parimi, Co-Founder and CTO of RiskProfiler, said security teams do not lack detection tools but are drowning in triage, repeating the same manual investigations thousands of times every week. He explained that KnyX performs that work like a senior analyst and then acts where policy allows, with every step governed by customer-defined controls and backed by evidence, enabling CISOs to adopt autonomous response without losing oversight.
Kamran Siddique, CISO at Steve Madden, said he had held back on autonomous response for years because letting a tool act on its own was never something he could defend to his board. In his words, KnyX is the first solution that let him enable it one action at a time, with a policy and an audit trail behind every move — automation he can actually defend.
Live Demos at Black Hat USA and DEF CON 34
RiskProfiler’s founding team will be in Las Vegas for Black Hat USA from August 1 to 6 and for DEF CON 34 from August 6 to 9, running live, one-to-one demonstrations of all five agents. Organisations that want an early look can schedule a personalised demo at riskprofiler.io/demo.
About RiskProfiler
RiskProfiler helps security teams discover, validate and disrupt external threats such as brand and domain abuse, phishing, leaked credentials and third-party risk through a unified digital risk protection platform. Its KnyX layer adds autonomous AI agents that investigate and respond to threats that traditional tools only alert on, combining the speed of automation with policy-based governance, structured evidence and a complete audit trail. More information is available at riskprofiler.io.
Final Thoughts
Alert volume is not going down, and hiring alone will not close the triage gap. KnyX Autonomous Investigations points to a more sustainable model: AI agents handle the repetitive investigative heavy lifting, humans keep policy control, and every automated move leaves a clean audit trail. For organisations tired of alert fatigue, that balance of speed and governance may be the difference between watching threats and actually stopping them.
Frequently Asked Questions
What is KnyX Autonomous Investigations?
KnyX Autonomous Investigations is an AI-powered capability from RiskProfiler that automates the investigation, validation and policy-governed response to external cyber threats.
Will KnyX take actions without human approval?
Only where customer-defined policies allow. Each action can be fully automated, routed for human approval, or disabled completely.
Where can I see a live demonstration?
RiskProfiler is demonstrating all five agents at Black Hat USA (August 1–6) and DEF CON 34 (August 6–9) in Las Vegas. Demos can be scheduled at riskprofiler.io/demo.



