Documentation

How to use
every KSE solution.

Account setup, dashboard walkthroughs, and detailed step-by-step guides for each module in the Kosmonel Security Ecosystem.

What is KSE?

The Kosmonel Security Ecosystem (KSE) is a modular cybersecurity platform. You deploy only the solutions you need across four layers - Monitor, Assess, Simulate, and Govern - while sharing assets, alerts, and risk context across your entire stack.

Most teams start with Website Monitoring - the module available at launch - and expand to the remaining solutions as they ship. Each solution has its own workflows and dashboards, but findings are designed to flow between modules: monitoring alerts inform vulnerability priorities, pentest results feed compliance evidence, and threat intelligence enriches identity anomalies.

This documentation covers account setup, the KSE workspace, billing, and step-by-step guides for every solution in the catalog. Modules marked Coming soon include setup guidance so you are ready when they launch.

  • Monitor - continuous visibility across websites, exposure, threat intel, assets, and identity
  • Assess - structured testing for web applications and network infrastructure
  • Simulate - phishing campaigns and security awareness measurement
  • Govern - vulnerability backlog, cloud posture, and compliance evidence

Create an account

Creating a KSE account starts at registration and finishes when you verify your email, build your solution stack, and complete checkout. Your workspace and organization are provisioned after payment succeeds.

  1. Start registration

    Open /register or choose Get started from any solution page on this site.

  2. Enter your details

    Provide your first and last name, email, business name, business type, company size, country, and (optionally) phone, website, state, city, and GST number. A business email helps when you later verify domains for Website Monitoring.

  3. Create a strong password

    Use at least 12 characters with uppercase, lowercase, a number, and a special character. Email OTP multi-factor authentication is required on every sign-in by default - you do not need to enable it separately.

  4. Verify your email

    Enter the 6-digit verification code sent to your inbox. Codes expire after a few minutes - request a new one if needed, and check spam or promotions if it does not arrive.

  5. Build your KSE stack and check out

    The onboarding wizard walks you through selecting solutions, plans, billing cycle, and payment. After checkout succeeds, your organization is created and you can sign in to the workspace.

If your company already has a Kosmonel workspace, ask an owner or admin for an invite instead of creating a duplicate account.

Your first login

After checkout, sign in to open the KSE workspace and the modules on your plan.

  1. Sign in

    Go to your KSE login, enter your email and password, then enter the 6-digit email OTP sent to your inbox. MFA is on for every sign-in by default.

  2. Email OTP on every login

    KSE uses email one-time passwords for multi-factor authentication. There is no authenticator-app setup step in Settings - each login prompts for a fresh code after your password is accepted.

  3. Review your dashboard

    The workspace dashboard shows your security posture score, analytics, recent alerts, and quick actions for your purchased tools.

  4. Manage billing anytime

    Open Billing from the sidebar destination linked under Settings → Billing, or go directly to /billing. Renew, review invoices, and manage your stack there.

Workspace overview

The KSE workspace is your command center. Navigation and layout stay consistent so you learn the interface once and reuse it across every module.

The left sidebar lists core workspace areas: Dashboard, Assets, Risk Center, Incidents, and Reports. All eleven KSE solutions live under the <strong>Tools</strong> dropdown - only launched modules on your plan open as active; others show as Coming soon. Support sits directly below Tools.

  • Dashboard - posture score, analytics charts, top risks, and executive summary
  • Assets - centralized inventory of websites, APIs, IPs, and domains
  • Risk Center - prioritized findings with remediation guidance
  • Incidents - security alert triage and assignment stream
  • Reports - executive and technical exports across solutions
  • Tools - quick access to every KSE module (launched and Coming soon)
  • Notifications - top-bar bell for account activity (sign-ins, password recovery, renewals)
  • Settings - profile, security, organization, billing, support, and sessions
  1. Open a solution

    Expand Tools in the sidebar and select a module, or open All solutions to browse your stack.

  2. Search the workspace

    Press Ctrl+K (or +K on Mac) or use the search control in the top navigation to jump to pages and actions.

  3. Account notifications

    Open the bell icon in the top bar to review account notifications such as new sign-ins and subscription reminders. Security alert triage lives under Incidents.

Plans & subscriptions

KSE modules are selected during onboarding or from the workspace Billing / renewal flows. Website Monitoring and WAPT use subscription tiers with usage limits. Network VAPT and similar advisory engagements are priced by scope.

  1. Compare plans

    Open any solution page for tier details, or go to Billing (also linked from Settings → Billing) to review your current subscription and renewals.

  2. Choose tier and limits

    For Website Monitoring, pick a tier based on website count and check frequency. For WAPT, match Web Assets and monthly Scan Credits to your portfolio (Starter, Growth, Business, or Enterprise). For Network VAPT, choose a scope package or contact sales for a custom engagement.

  3. Complete checkout or renew

    New accounts check out during onboarding. Existing subscribers renew or change the stack from Billing. Subscriptions invoice for the selected billing cycle; engagement services bill per statement of work.

  4. Activate modules

    Purchased, launched tools appear under Tools as soon as entitlements sync after payment. Complete each module's setup guide below (for example DNS verification for Website Monitoring).

Plan changes that lower limits are applied at renewal. Remove excess assets first if the new tier includes fewer websites or Web Assets than you currently have.

Profile & team

Accurate profile and team settings ensure alerts, invoices, and reports reach the right people.

  1. Update your profile

    Open Settings from the top bar. Update personal details, business information, and location so invoices and account records stay accurate.

  2. Manage organization

    Under Settings → Organization in the settings sidebar (or go to /organization), invite colleagues and assign roles: Admin (billing and configuration), Analyst (triage and response), or Observer (view-only). The inviting owner keeps the Owner role.

  3. Security and password

    Use Settings → Security to reset your password with an email verification code. Sign-in continues to require email OTP after any password change.

Monitor Available

24/7 Website Security Monitoring

Watch everything. Miss nothing.

Continuous checks for uptime, TLS, headers, DNS, exposure, defacement, domain expiry, and client-side threat behavior.

What it does

  • Multi-module checks Uptime, SSL/TLS, headers, exposure, DNS, domain expiry, defacement, and client-side UBA.
  • Alerting & recovery Incident and recovery emails, priority queue on Growth plans, and a full alert timeline.
  • DNS verification Assets activate only after domain ownership is proven.
  • Executive reporting Security posture PDFs and fleet summaries for Business-tier customers.

Before you begin

  • Active Website Monitoring subscription
  • Ownership of the domain you want to monitor
  • Access to DNS settings for verification

How to use it

  1. Open the workspace

    Sign in and go to Assets or open Monitor from the Tools menu.

  2. Add a domain

    Enter the root domain (for example example.com) and an optional display name.

  3. Verify via DNS

    Add the TXT record shown in the workspace, then click Verify now.

  4. Review monitoring

    Once verified, checks run automatically. Open the monitoring console for alerts, drill-down, and PDF reports.

Typical workflow

Add your domain Verify via DNS TXT Monitoring activates on Kosmonel Review dashboard & alerts

Works with

Tips

  • Verify the apex domain before adding subdomains as separate assets.
  • Keep the DNS TXT record in place - periodic re-checks confirm continued ownership.
Monitor Coming soon

Asset Discovery & Inventory

You can't protect what you haven't inventoried.

Automated inventory of domains, IPs, cloud resources, and shadow IT from multiple discovery sources. Coming soon - join the waitlist to be notified when provisioning opens.

What it does

  • Multi-source discovery DNS brute-force, CT logs, ASN mapping, and cloud API connectors.
  • Ownership tagging Business unit, owner, environment, and data classification labels.
  • Drift detection Alert when new subdomains or services appear without approval.
  • Export & API CMDB sync and JSON/CSV export for GRC workflows.

Before you begin

  • Waitlist or enterprise monitor bundle
  • DNS domain seeds and/or cloud read-only credentials

How to use it

  1. Join the waitlist

    Sign up from the Asset Discovery page. You will be notified when your tenant is provisioned.

  2. Connect seeds

    Provide known domains and optional read-only cloud API keys for AWS, Azure, or GCP.

  3. Run initial discovery

    The first pass may take several hours. Subdomains, IPs, and cloud resources populate the inventory graph.

  4. Tag and classify

    Assign business unit, environment, owner, and criticality to each asset.

  5. Enable drift alerts

    Get notified when new subdomains or services appear without change approval.

  6. Export or sync

    Download CSV or JSON, or sync to your CMDB to drive monitoring and pentest scope.

Typical workflow

Connect seeds & cloud Discover & classify Review inventory Enable monitoring

Works with

Tips

  • Review shadow IT findings with network teams before enabling broad monitoring scans.
Monitor Coming soon

Exposure Intelligence

See what the internet already knows about you.

OSINT-driven discovery of leaked credentials, shadow assets, and public sensitive paths. Coming soon - request access to be notified when continuous exposure monitoring launches.

What it does

  • Credential leak monitoring Alert when employee or customer emails appear in breach dumps.
  • Subdomain & cert discovery Find forgotten hosts and misissued certificates.
  • Sensitive path indexing Detect publicly reachable admin panels, backups, and config files.
  • Reputation signals Blacklist and malware reputation checks for your domains.

Before you begin

  • Access enabled on your account when the module launches
  • Primary domains and brand names to monitor

How to use it

  1. Request access

    Request access from the Exposure Intelligence product card or email support@kosmonel.com.

  2. Seed domains and brands

    Add root domains, common subdomains, and brand keywords for typosquat monitoring.

  3. Review discoveries

    Certificate transparency, DNS changes, paste-site mentions, and indexed sensitive paths appear in the feed.

  4. Triage by severity

    Prioritize credential leaks and publicly reachable admin panels immediately.

  5. Remediate and verify

    Take down exposures, rotate credentials, and confirm items stay closed on re-scan.

Typical workflow

Seed domains & brands Continuous OSINT collection Correlate & score Alert & remediate

Works with

Tips

  • Pair with Website Monitoring so remediated exposures stay under continuous watch.
Monitor Coming soon

Identity Threat Detection

Protect identities as aggressively as infrastructure.

Detection of suspicious logins, MFA bypass attempts, and account takeover patterns from IdP telemetry. Coming soon - register interest for the design partner program.

What it does

  • Login anomaly detection Geo velocity, device fingerprint, and TOR/VPN signals.
  • MFA health Coverage gaps and bypass attempt alerting.
  • Privileged session monitoring Admin actions flagged against baseline behavior.
  • Threat intel correlation Cross-reference with known malicious IPs from KSE network.

Before you begin

  • IdP integration (Azure AD, Okta, or Google Workspace) or auth log export
  • Baseline period of 7–14 days for normal login patterns

How to use it

  1. Join the waitlist

    Register interest to participate in early access.

  2. Connect your IdP

    OAuth or SIEM log ingestion brings login events into KSE for analysis.

  3. Establish baselines

    The system learns typical geographies, devices, and times for each user group.

  4. Investigate anomalies

    Review impossible travel, MFA fatigue, credential stuffing, and privileged session spikes.

  5. Respond and harden

    Force password resets, revoke sessions, or tighten conditional access policies.

Typical workflow

Connect IdP / logs Establish baselines Detect anomalies Respond & harden

Works with

Tips

  • Correlate with Threat Intelligence IP reputation for faster triage.
Monitor Coming soon

Threat Intelligence Network

Collective defense powered by real attack telemetry.

Shared attacker profiles, geo correlation, and cross-customer signal fusion from real attack telemetry. Coming soon as a standalone Tools destination - client-side collection is available today inside Website Monitoring.

What it does

  • Global actor profiles IP reputation, attack types, severity history, and target spread.
  • Client-side agent Embed a lightweight script to catch SQLi, XSS, and scanner behavior in browsers.
  • Geo visualization Live maps of attack origin and targeted pages.
  • Silent visitor checks Warn when a known bad actor hits your site - before they exploit.

Before you begin

  • Website Monitoring with the client-side agent enabled on verified sites
  • Permission to embed JavaScript on monitored properties

How to use it

  1. Open Client UBA in monitoring

    From Tools → Monitor, open the client-side / UBA checks view (for example /monitor/checks/client-uba). This is where the install snippet lives today.

  2. Deploy the client-side agent

    Copy the asset-specific Installation snippet from that page and place it before the closing </body> tag in the site's global layout. A tag manager is also supported when it injects the unchanged snippet into the page DOM on every protected page.

  3. Confirm ingestion

    Generate a test visit. Events should appear in the live feed within minutes once the agent is active.

  4. Explore actor profiles

    When the Threat Intelligence workspace opens, known attackers accumulate reputation scores with attack history and targeted pages.

  5. Use geo visualization

    Maps show origin countries and targeted URLs. Filter by time range during investigations.

  6. Enable visitor checks

    Warn when a known malicious IP visits your site. Export indicators to your WAF or edge firewall.

Typical workflow

Deploy client-side agent Events ingest to KSE Network correlates actors Dashboard & alerts

Works with

Tips

  • The agent focuses on attack patterns, not personal user data.
  • Cross-reference alerts with Exposure Intelligence for the same actor infrastructure when that module launches.
Assess Available

Network VAPT

Map the attack surface of your network perimeter and internal segments.

Expert-led external and internal network penetration testing with a phased engagement model. Coming soon - engagement pricing and scoping will open with the Assess layer launch.

What it does

  • External perimeter Internet-facing assets, mail servers, VPN endpoints, and exposed management interfaces.
  • Internal segmentation Validate VLAN isolation, east-west controls, and privilege boundaries.
  • Wireless assessment Optional Wi-Fi security review for corporate and guest networks.
  • Compliance mapping Findings mapped to ISO 27001, SOC 2, and RBI cyber hygiene where applicable.

Before you begin

  • Scoped IP ranges or cloud VPC identifiers
  • Written authorization from asset owners
  • Maintenance window for intrusive internal testing if required

How to use it

  1. Define scope

    List external IPs, domains, and internal subnets. Document excluded systems in the statement of work.

  2. Align inventory

    Share your asset list or connect Asset Discovery so testers and your team reference the same hosts.

  3. External assessment

    Testers enumerate internet-facing services and validate perimeter controls with controlled exploitation.

  4. Internal assessment

    Via VPN or on-site access, testers validate segmentation and lateral movement paths.

  5. Prioritize remediation

    Start with unauthenticated perimeter access and paths to domain admin.

  6. Retest (optional)

    Schedule a retest after remediation to confirm fixes hold.

Typical workflow

Asset inventory alignment Scanning & service enumeration Controlled exploitation Remediation roadmap

Works with

Tips

  • Schedule internal tests outside peak hours if legacy systems are scan-sensitive.
  • Provide network diagrams to reduce discovery time.
Assess Available

Web Application Penetration Testing

Continuous WAPT for modern web applications.

Self-serve web application penetration testing with OWASP coverage, Scan Credits, and scan comparison. Coming soon - this guide describes the planned flow so you can prepare before the module launches.

What it does

  • Scan Credits Run manual and scheduled scans against your Web Assets using monthly Scan Credits.
  • OWASP Top 10 coverage Injection, broken access control, SSRF, misconfigurations, and modern API weaknesses.
  • Authentication testing Basic and advanced authentication support on Growth and Business plans.
  • Actionable reporting CVSS scoring, CWE mapping, technical and executive reports, and scan comparison.

Before you begin

  • Active WAPT subscription (Starter, Growth, Business, or Enterprise)
  • Application URL and environment details (staging or production)
  • Test credentials for each role when authenticated scanning is enabled

How to use it

  1. Confirm your plan

    Starter includes 1 Web Asset and 3 Scan Credits per month. Growth includes 3 assets and 15 credits. Business includes 10 assets and 50 credits. Enterprise is sales-scoped.

  2. Register Web Assets

    Add each application URL from the WAPT dashboard. Purchase add-on assets if you exceed your plan limit.

  3. Configure scans

    Choose manual or scheduled scans. Enable passive and active profiles appropriate to your tier.

  4. Run and monitor

    Each scan consumes one Scan Credit. Track progress from the scan queue.

  5. Triage findings

    Review CVSS scores, CWE and OWASP mapping, and technical reports. Compare scans over time on Growth and Business.

  6. Export reports

    Download PDF reports. Growth adds JSON export; Business adds CSV as well.

Typical workflow

Choose a plan Add Web Assets Run scans Review findings & export reports

Works with

Tips

  • Scan staging environments that mirror production to surface issues with less risk.
  • Buy Scan Credit packs before major release windows if you expect extra manual scans.
Simulate Coming soon

Phishing Simulation & Awareness

Train humans with realistic attacks - safely.

Realistic phishing simulations with safe landing pages, metrics, and automated micro-training. Coming soon - request early access to be notified when this module launches for your tenant.

What it does

  • Template library Finance, HR, IT, and vendor impersonation scenarios with regional language support.
  • Safe landing pages Educational reveals instead of credential harvesting on real systems.
  • Risk scoring Department and user-level repeat-offender tracking with trend dashboards.
  • Automated training Trigger awareness modules when users fail a simulation.

Before you begin

  • Owner or Admin role in your KSE organization
  • Employee email list (CSV or directory sync)
  • HR and legal approval for simulation campaigns

How to use it

  1. Request access

    Use the product card / waitlist path or contact support to join early access for Phishing Campaigns.

  2. Define audience

    Create groups by department. Start with a pilot before company-wide campaigns.

  3. Choose a template

    Select finance, IT helpdesk, or vendor impersonation scenarios. Customize sender display name and landing branding.

  4. Schedule delivery

    Set a send window and stagger emails. Safe landing pages show education instead of harvesting credentials.

  5. Review metrics

    Track open, click, and report rates. Flag repeat offenders for follow-up training.

  6. Assign training

    Enroll users who fail into micro-learning modules and export results for compliance.

Typical workflow

Define audience & goals Design campaign Launch simulation Report & train

Works with

Tips

  • Brief leadership confidentially so IT is not flooded with panic forwards.
  • Run quarterly campaigns to measure improvement over time.
Govern Coming soon

Cloud Security Posture

Continuous compliance for cloud control planes.

CIS-aligned misconfiguration checks for AWS, Azure, and GCP with drift alerts and remediation playbooks. Coming soon - join the waitlist for connector onboarding docs when Govern launches.

What it does

  • Multi-cloud connectors Read-only integration with major cloud providers.
  • CIS & custom benchmarks Pre-built frameworks plus org-specific policy packs.
  • Identity graph Over-privileged roles and stale access keys surfaced visually.
  • Remediation guides CLI and console steps for each failed control.

Before you begin

  • Cloud provider account with a read-only IAM role for Kosmonel
  • CIS or custom benchmark selection

How to use it

  1. Request provisioning

    Join the waitlist to receive CloudFormation or Terraform templates for your provider.

  2. Deploy the connector

    Grant read-only access to IAM, storage, security groups, and logging configuration.

  3. Run baseline assessment

    Initial scan maps failures against CIS benchmarks and custom guardrails.

  4. Review identity risks

    Identify over-privileged roles, stale access keys, and public storage buckets.

  5. Remediate with playbooks

    Each failed control includes console and CLI steps. Re-scan to verify.

Typical workflow

Connect cloud accounts Baseline assessment Continuous monitoring Remediate & verify

Works with

Tips

  • Validate the connector in a non-production account before linking production.
Govern Coming soon

Compliance & Audit Hub

Turn security work into audit-ready proof.

Framework mapping, automated evidence collection, and auditor-ready export packs. Coming soon - early adopters can map existing PDF reports while automation is built.

What it does

  • Control mapping Pre-built mappings for common Indian and global frameworks.
  • Evidence automation Pull reports and logs from other KSE modules automatically.
  • Policy attestations Track employee acknowledgments and training completion.
  • Auditor export ZIP bundles with index, timestamps, and integrity hashes.

Before you begin

  • Target framework selected (ISO 27001, SOC 2, DPDP, RBI, etc.)
  • Other KSE modules producing evidence (monitoring reports, pentests, training)

How to use it

  1. Join the waitlist

    Register for early access to Compliance Hub.

  2. Select your framework

    Pre-built control mappings link KSE outputs to auditor questions.

  3. Map controls to solutions

    Assign which modules satisfy each control - for example Website Monitoring for continuous monitoring evidence.

  4. Collect evidence

    Automated pulls gather reports, logs, and attestation records on a schedule.

  5. Export the audit pack

    Generate a ZIP with index, timestamps, and integrity hashes for external auditors.

Typical workflow

Select framework Map controls to solutions Collect evidence Export audit pack

Works with

Tips

  • Store policy documents in the workspace so attestations link to versioned PDFs.
Govern Coming soon

Vulnerability Management

One backlog for every finding - prioritized, owned, and closed.

Unified backlog for findings from monitoring, pentests, and scanners with SLA tracking. Coming soon - join the waitlist to ingest KSE findings first when Govern modules launch.

What it does

  • Unified ingest Import from KSE solutions and common scanners via API.
  • Risk-based prioritization CVSS + asset criticality + exploitability scoring.
  • Workflow & SLAs Ticket sync, due dates, and escalation for overdue criticals.
  • Audit trail Immutable history of discovery, assignment, and verification.

Before you begin

  • Waitlist approval or a govern-tier bundle
  • At least one finding source (monitoring, WAPT, or scanner export)

How to use it

  1. Request access

    Join the waitlist from the product page or ask your account manager.

  2. Connect sources

    Enable native KSE connectors. Upload CSV or configure the import API for third-party scanners when available.

  3. Triage the backlog

    Deduplicate repeat issues and set severity using CVSS plus asset criticality.

  4. Assign owners

    Map findings to owners and set SLA due dates by severity.

  5. Track to closure

    Move items through Open → In progress → Ready for verification → Closed.

  6. Export audit history

    Generate closure records for ISO, SOC 2, or internal audits.

Typical workflow

Ingest findings Triage & prioritize Assign remediation Verify & close

Works with

Tips

  • Align SLA timers with your ITSM tool if you sync tickets.

Contact support

Need help during setup, a scope quote, or guidance choosing modules? The Kosmonel team is available by email and phone during business hours (IST).

  1. Raise a ticket in KSE

    Open Support from the workspace sidebar or Settings, then choose Raise a ticket. Describe the issue, pick a category, and submit. You will get an email confirmation, and our desk is notified with your account context. Owners and admins can see all organization tickets.

  2. Email support

    Write to support@kosmonel.com with your account email, product name, and screenshots if applicable. Critical monitoring outages are prioritized.

  3. Phone

    Call +91 74986 96144 for urgent production issues during business hours.

  4. Sales and demos

    Use the contact form for pricing, multi-module rollouts, and live demos.