What is KSE?
The Kosmonel Security Ecosystem (KSE) is a modular cybersecurity platform. You deploy only the solutions you need across four layers — Monitor, Assess, Simulate, and Govern — while sharing assets, alerts, and risk context across your entire stack.
Most teams start with one module (often Website Monitoring or WAPT) and expand as their program matures. Each solution has its own workflows and dashboards, but findings flow between modules: monitoring alerts inform vulnerability priorities, pentest results feed compliance evidence, and threat intelligence enriches identity anomalies.
This documentation covers account setup, the KSE workspace, billing, and step-by-step guides for every solution in the catalog.
- Monitor — continuous visibility across websites, exposure, threat intel, assets, and identity
- Assess — structured testing for web applications and network infrastructure
- Simulate — phishing campaigns and security awareness measurement
- Govern — vulnerability backlog, cloud posture, and compliance evidence
Create an account
A Kosmonel account unlocks the KSE workspace, onboarding, billing, and every solution you purchase. Registration is free — you select plans when you are ready to activate paid modules.
-
Start registration
Open /register or choose Get started from any solution page on this site.
-
Enter your details
Provide your full name, work email, and company name. A work email helps with domain verification when you enable Website Monitoring.
-
Create a strong password
Use at least eight characters with mixed case and numbers. Enable multi-factor authentication after your first login.
-
Verify your email
Click the verification link in your inbox within 24 hours. Check spam or promotions if it does not arrive within a few minutes.
-
Build your KSE stack
After verification, the onboarding wizard walks you through selecting solutions, plans, and payment. You can add more modules later from the workspace.
If your company already has a Kosmonel workspace, ask an admin for an invite instead of creating a duplicate account.
Your first login
Once your email is verified, sign in to access the KSE workspace and any modules on your plan.
-
Sign in
Go to kosmonel.com/login, enter your credentials, and open the KSE workspace.
-
Enable MFA (recommended)
Open Settings from the top bar, then Security. Enable two-factor authentication with an authenticator app.
-
Review your dashboard
The workspace dashboard shows your security posture score, analytics, recent alerts, and quick actions for your purchased tools.
-
Add billing when ready
Paid modules activate after checkout in onboarding or under Settings → Billing. You can explore the interface before subscribing.
Workspace overview
The KSE workspace is your command center. Navigation and layout stay consistent so you learn the interface once and reuse it across every module.
The left sidebar lists core workspace areas: Dashboard, Assets, Risk Center, and Reports. All eleven KSE solutions live under the <strong>Tools</strong> dropdown — only modules on your plan appear as active. Support sits directly below Tools.
- Dashboard — posture score, analytics charts, top risks, and executive summary
- Assets — centralized inventory of websites, APIs, IPs, and domains
- Risk Center — prioritized findings with remediation guidance
- Reports — executive and technical exports across solutions
- Tools — quick access to every KSE module you have purchased
- Alerts — notification bell in the top bar for the unified alert stream
- Settings — profile, organization, billing, and integrations (top bar)
-
Open a solution
Expand Tools in the sidebar and select a module, or open All solutions to manage your stack.
-
Search the workspace
Press Ctrl+K or use the search bar in the top navigation to jump to pages and actions.
-
Configure notifications
Under Settings → Notifications, route critical monitoring events to email, Slack, or webhooks.
Plans & subscriptions
KSE modules are purchased individually during onboarding or from the workspace. Website Monitoring and WAPT use monthly tiers with usage limits. Network VAPT and advisory engagements are scoped per project.
-
Compare plans
Browse pricing on the marketing site, open any solution page, or go to Settings → Billing in the workspace.
-
Choose tier and limits
For monitoring, pick a tier based on domain count and check frequency. For WAPT, match Web Assets and monthly Scan Credits to your portfolio. For Network VAPT, submit a scope form.
-
Complete checkout
Enter billing details during onboarding or from Settings. Monthly subscriptions invoice automatically; engagement services bill per statement of work.
-
Activate modules
Purchased tools appear in the sidebar Tools menu within minutes. Complete each module's setup guide below (for example DNS verification for monitoring).
Plan downgrades apply at the next billing cycle. Remove excess assets first if the new tier has lower limits.
Profile & team
Accurate profile and team settings ensure alerts, invoices, and reports reach the right people.
-
Update your profile
Open Settings from the top bar. Update your name, phone, and timezone so scheduled reports display correct timestamps.
-
Manage organization
Under Settings → Organization, invite colleagues and assign roles: Admin (billing and configuration), Analyst (triage and response), or Read-only (dashboards).
-
Tune notifications
Set per-user alert preferences so executives receive weekly summaries while engineers get real-time critical notifications.
Continuous checks for uptime, TLS, headers, DNS, exposure, defacement, and client-side threat behavior.
What it does
-
Multi-module checks
Uptime, SSL/TLS, headers, exposure, DNS, domain expiry, defacement, and client-side UBA.
-
Alerting & recovery
Incident and recovery emails, priority queue on Growth plans, and a full alert timeline.
-
DNS verification
Assets activate only after domain ownership is proven.
-
Executive reporting
Security posture PDFs and fleet summaries for Business-tier customers.
Before you begin
- Active Website Monitoring subscription
- Ownership of the domain you want to monitor
- Access to DNS settings for verification
How to use it
-
Open the workspace
Sign in and go to Assets or open Monitor from the Tools menu.
-
Add a domain
Enter the root domain (for example example.com) and an optional display name.
-
Verify via DNS
Add the TXT record shown in the workspace, then click Verify now.
-
Review monitoring
Once verified, checks run automatically. Open the monitoring console for alerts, drill-down, and PDF reports.
Typical workflow
Add your domain
Verify via DNS TXT
Monitoring activates on Kosmonel
Review dashboard & alerts
Works with
Tips
- Verify the apex domain before adding subdomains as separate assets.
- Keep the DNS TXT record in place — periodic re-checks confirm continued ownership.
View product page
Automated inventory of domains, IPs, cloud resources, and shadow IT from multiple discovery sources. On the monitor roadmap — join the waitlist to be notified when provisioning opens.
What it does
-
Multi-source discovery
DNS brute-force, CT logs, ASN mapping, and cloud API connectors.
-
Ownership tagging
Business unit, owner, environment, and data classification labels.
-
Drift detection
Alert when new subdomains or services appear without approval.
-
Export & API
CMDB sync and JSON/CSV export for GRC workflows.
Before you begin
- Waitlist or enterprise monitor bundle
- DNS domain seeds and/or cloud read-only credentials
How to use it
-
Join the waitlist
Sign up from the Asset Discovery page. You will be notified when your tenant is provisioned.
-
Connect seeds
Provide known domains and optional read-only cloud API keys for AWS, Azure, or GCP.
-
Run initial discovery
The first pass may take several hours. Subdomains, IPs, and cloud resources populate the inventory graph.
-
Tag and classify
Assign business unit, environment, owner, and criticality to each asset.
-
Enable drift alerts
Get notified when new subdomains or services appear without change approval.
-
Export or sync
Download CSV or JSON, or sync to your CMDB to drive monitoring and pentest scope.
Typical workflow
Connect seeds & cloud
Discover & classify
Review inventory
Enable monitoring
Works with
Tips
- Review shadow IT findings with network teams before enabling broad monitoring scans.
View product page
OSINT-driven discovery of leaked credentials, shadow assets, and public sensitive paths. Available in beta — request access to enable continuous exposure monitoring.
What it does
-
Credential leak monitoring
Alert when employee or customer emails appear in breach dumps.
-
Subdomain & cert discovery
Find forgotten hosts and misissued certificates.
-
Sensitive path indexing
Detect publicly reachable admin panels, backups, and config files.
-
Reputation signals
Blacklist and malware reputation checks for your domains.
Before you begin
- Beta access enabled on your account
- Primary domains and brand names to monitor
How to use it
-
Enable beta
Request access from the Exposure Intelligence product card or email contact@kosmonel.com.
-
Seed domains and brands
Add root domains, common subdomains, and brand keywords for typosquat monitoring.
-
Review discoveries
Certificate transparency, DNS changes, paste-site mentions, and indexed sensitive paths appear in the feed.
-
Triage by severity
Prioritize credential leaks and publicly reachable admin panels immediately.
-
Remediate and verify
Take down exposures, rotate credentials, and confirm items stay closed on re-scan.
Typical workflow
Seed domains & brands
Continuous OSINT collection
Correlate & score
Alert & remediate
Works with
Tips
- Pair with Website Monitoring so remediated exposures stay under continuous watch.
View product page
Detection of suspicious logins, MFA bypass attempts, and account takeover patterns from IdP telemetry. Coming soon — register interest for the design partner program.
What it does
-
Login anomaly detection
Geo velocity, device fingerprint, and TOR/VPN signals.
-
MFA health
Coverage gaps and bypass attempt alerting.
-
Privileged session monitoring
Admin actions flagged against baseline behavior.
-
Threat intel correlation
Cross-reference with known malicious IPs from KSE network.
Before you begin
- IdP integration (Azure AD, Okta, or Google Workspace) or auth log export
- Baseline period of 7–14 days for normal login patterns
How to use it
-
Join the waitlist
Register interest to participate in early access.
-
Connect your IdP
OAuth or SIEM log ingestion brings login events into KSE for analysis.
-
Establish baselines
The system learns typical geographies, devices, and times for each user group.
-
Investigate anomalies
Review impossible travel, MFA fatigue, credential stuffing, and privileged session spikes.
-
Respond and harden
Force password resets, revoke sessions, or tighten conditional access policies.
Typical workflow
Connect IdP / logs
Establish baselines
Detect anomalies
Respond & harden
Works with
Tips
- Correlate with Threat Intelligence IP reputation for faster triage.
View product page
Shared attacker profiles, geo correlation, and cross-customer signal fusion from real attack telemetry.
What it does
-
Global actor profiles
IP reputation, attack types, severity history, and target spread.
-
Client-side agent
Embed a lightweight script to catch SQLi, XSS, and scanner behavior in browsers.
-
Geo visualization
Live maps of attack origin and targeted pages.
-
Silent visitor checks
Warn when a known bad actor hits your site — before they exploit.
Before you begin
- Website Monitoring with client-side agent enabled, or standalone Threat Intelligence access
- Permission to embed JavaScript on monitored properties
How to use it
-
Open Threat Intelligence
From the Tools menu, select Threat Intel. Works best alongside Website Monitoring.
-
Deploy the client-side agent
Copy the script from Settings → Agent and add it to your site header or tag manager.
-
Confirm ingestion
Generate a test visit or use the built-in validator. Events should appear in the live feed within minutes.
-
Explore actor profiles
Known attackers accumulate reputation scores across the Kosmonel network with attack history and targeted pages.
-
Use geo visualization
Maps show origin countries and targeted URLs. Filter by time range during investigations.
-
Enable visitor checks
Warn when a known malicious IP visits your site. Export indicators to your WAF or edge firewall.
Typical workflow
Deploy client-side agent
Events ingest to KSE
Network correlates actors
Dashboard & alerts
Works with
Tips
- The agent focuses on attack patterns, not personal user data.
- Cross-reference alerts with Exposure Intelligence for the same actor infrastructure.
View product page
Expert-led external and internal network penetration testing with a phased engagement model.
What it does
-
External perimeter
Internet-facing assets, mail servers, VPN endpoints, and exposed management interfaces.
-
Internal segmentation
Validate VLAN isolation, east-west controls, and privilege boundaries.
-
Wireless assessment
Optional Wi-Fi security review for corporate and guest networks.
-
Compliance mapping
Findings mapped to ISO 27001, SOC 2, and RBI cyber hygiene where applicable.
Before you begin
- Scoped IP ranges or cloud VPC identifiers
- Written authorization from asset owners
- Maintenance window for intrusive internal testing if required
How to use it
-
Define scope
List external IPs, domains, and internal subnets. Document excluded systems in the statement of work.
-
Align inventory
Share your asset list or connect Asset Discovery so testers and your team reference the same hosts.
-
External assessment
Testers enumerate internet-facing services and validate perimeter controls with controlled exploitation.
-
Internal assessment
Via VPN or on-site access, testers validate segmentation and lateral movement paths.
-
Prioritize remediation
Start with unauthenticated perimeter access and paths to domain admin.
-
Retest (optional)
Schedule a retest after remediation to confirm fixes hold.
Typical workflow
Asset inventory alignment
Scanning & service enumeration
Controlled exploitation
Remediation roadmap
Works with
Tips
- Schedule internal tests outside peak hours if legacy systems are scan-sensitive.
- Provide network diagrams to reduce discovery time.
View product page
Self-serve web application penetration testing with OWASP coverage, Scan Credits, and AI remediation guidance.
What it does
-
Scan Credits
Run manual and scheduled scans against your Web Assets using monthly Scan Credits.
-
OWASP Top 10 coverage
Injection, broken access control, SSRF, misconfigurations, and modern API weaknesses.
-
Authentication testing
Basic and advanced authentication support on Growth and Business plans.
-
Actionable reporting
CVSS scoring, CWE mapping, PDF/JSON/CSV exports, and AI remediation suggestions.
Before you begin
- Active WAPT subscription (Basic, Plus, or Advanced)
- Application URL and environment details (staging or production)
- Test credentials for each role when authenticated scanning is enabled
How to use it
-
Confirm your plan
Basic includes 1 Web Asset and 3 Scan Credits per month. Plus and Advanced add more assets, credits, and scheduling options.
-
Register Web Assets
Add each application URL from the WAPT dashboard. Purchase add-on assets if you exceed your plan limit.
-
Configure scans
Choose manual or scheduled scans. Enable passive and active profiles appropriate to your tier.
-
Run and monitor
Each scan consumes one Scan Credit. Track progress from the scan queue.
-
Triage findings
Review CVSS scores, CWE and OWASP mapping, and AI remediation suggestions. Compare scans over time on Plus and Advanced.
-
Export reports
Download PDF reports. Plus and Advanced support JSON; Advanced adds CSV export.
Typical workflow
Choose a plan
Add Web Assets
Run scans
Review findings & export reports
Works with
Tips
- Scan staging environments that mirror production to surface issues with less risk.
- Buy Scan Credit packs before major release windows if you expect extra manual scans.
View product page
Realistic phishing simulations with safe landing pages, metrics, and automated micro-training. Rolling out in phases — request early access to enable this module for your tenant.
What it does
-
Template library
Finance, HR, IT, and vendor impersonation scenarios with regional language support.
-
Safe landing pages
Educational reveals instead of credential harvesting on real systems.
-
Risk scoring
Department and user-level repeat-offender tracking with trend dashboards.
-
Automated training
Trigger awareness modules when users fail a simulation.
Before you begin
- Admin or security-team role in Kosmonel
- Employee email list (CSV or directory sync)
- HR and legal approval for simulation campaigns
How to use it
-
Request access
Use the dashboard banner or contact sales to enable Phishing Simulation.
-
Define audience
Create groups by department. Start with a pilot before company-wide campaigns.
-
Choose a template
Select finance, IT helpdesk, or vendor impersonation scenarios. Customize sender display name and landing branding.
-
Schedule delivery
Set a send window and stagger emails. Safe landing pages show education instead of harvesting credentials.
-
Review metrics
Track open, click, and report rates. Flag repeat offenders for follow-up training.
-
Assign training
Enroll users who fail into micro-learning modules and export results for compliance.
Typical workflow
Define audience & goals
Design campaign
Launch simulation
Report & train
Works with
Tips
- Brief leadership confidentially so IT is not flooded with panic forwards.
- Run quarterly campaigns to measure improvement over time.
View product page
CIS-aligned misconfiguration checks for AWS, Azure, and GCP with drift alerts and remediation playbooks. On the govern roadmap — join the waitlist for connector onboarding docs.
What it does
-
Multi-cloud connectors
Read-only integration with major cloud providers.
-
CIS & custom benchmarks
Pre-built frameworks plus org-specific policy packs.
-
Identity graph
Over-privileged roles and stale access keys surfaced visually.
-
Remediation guides
CLI and console steps for each failed control.
Before you begin
- Cloud provider account with read-only IAM role for Kosmonel
- CIS or custom benchmark selection
How to use it
-
Request provisioning
Join the waitlist to receive CloudFormation or Terraform templates for your provider.
-
Deploy the connector
Grant read-only access to IAM, storage, security groups, and logging configuration.
-
Run baseline assessment
Initial scan maps failures against CIS benchmarks and custom guardrails.
-
Review identity risks
Identify over-privileged roles, stale access keys, and public storage buckets.
-
Remediate with playbooks
Each failed control includes console and CLI steps. Re-scan to verify.
Typical workflow
Connect cloud accounts
Baseline assessment
Continuous monitoring
Remediate & verify
Works with
Tips
- Validate the connector in a non-production account before linking production.
View product page
Framework mapping, automated evidence collection, and auditor-ready export packs. In development — early adopters can map existing PDF reports while automation is built.
What it does
-
Control mapping
Pre-built mappings for common Indian and global frameworks.
-
Evidence automation
Pull reports and logs from other KSE modules automatically.
-
Policy attestations
Track employee acknowledgments and training completion.
-
Auditor export
ZIP bundles with index, timestamps, and integrity hashes.
Before you begin
- Target framework selected (ISO 27001, SOC 2, DPDP, RBI, etc.)
- Other KSE modules producing evidence (monitoring reports, pentests, training)
How to use it
-
Join the waitlist
Register for early access to Compliance Hub.
-
Select your framework
Pre-built control mappings link KSE outputs to auditor questions.
-
Map controls to solutions
Assign which modules satisfy each control — for example Website Monitoring for continuous monitoring evidence.
-
Collect evidence
Automated pulls gather reports, logs, and attestation records on a schedule.
-
Export the audit pack
Generate a ZIP with index, timestamps, and integrity hashes for external auditors.
Typical workflow
Select framework
Map controls to solutions
Collect evidence
Export audit pack
Works with
Tips
- Store policy documents in the workspace so attestations link to versioned PDFs.
View product page
Unified backlog for findings from monitoring, pentests, and scanners with SLA tracking. On the govern roadmap — join the waitlist to ingest KSE findings first.
What it does
-
Unified ingest
Import from KSE solutions and common scanners via API.
-
Risk-based prioritization
CVSS + asset criticality + exploitability scoring.
-
Workflow & SLAs
Ticket sync, due dates, and escalation for overdue criticals.
-
Audit trail
Immutable history of discovery, assignment, and verification.
Before you begin
- Waitlist approval or govern-tier bundle
- At least one finding source (monitoring, WAPT, or scanner export)
How to use it
-
Request access
Join the waitlist from the product page or ask your account manager.
-
Connect sources
Enable native KSE connectors. Upload CSV or configure the import API for third-party scanners when available.
-
Triage the backlog
Deduplicate repeat issues and set severity using CVSS plus asset criticality.
-
Assign owners
Map findings to owners and set SLA due dates by severity.
-
Track to closure
Move items through Open → In progress → Ready for verification → Closed.
-
Export audit history
Generate closure records for ISO, SOC 2, or internal audits.
Typical workflow
Ingest findings
Triage & prioritize
Assign remediation
Verify & close
Works with
Tips
- Align SLA timers with your ITSM tool if you sync tickets.
View product page
Contact support
Need help during setup, a scope quote, or guidance choosing modules? The Kosmonel team is available by email and phone during business hours (IST).
-
Email support
Write to contact@kosmonel.com with your account email, product name, and screenshots if applicable. Critical monitoring outages are prioritized.
-
Phone
Call +91 74986 96144 for urgent production issues during business hours.
-
Sales and demos
Use the contact form for pricing, multi-module rollouts, and live demos.