RiskProfiler has introduced KnyX Autonomous Investigations, a new capability aimed at automating how security teams investigate, validate and respond to external online threats. The company said the product is being shown at Black Hat USA 2026 and will also be demonstrated at DEF CON 34 in Las Vegas.
KnyX Autonomous Investigations addresses this challenge through a continuous workflow of Alert → Investigate → Verdict → Remediate. AI agents gather the same evidence a human analyst would, generate confidence-scored verdicts and, where customer-defined policies allow, execute or initiate remediation actions.
“Security teams do not lack detection tools. What they are increasingly drowning in is triage, with the same manual investigations being repeated thousands of times every week,” said Setu Parimi, Co-Founder and CTO of RiskProfiler. “KnyX Autonomous Investigations performs that work the way a senior analyst would and then takes the next step by acting where policy allows. Every step is governed by customer-defined controls and backed by evidence, enabling CISOs to adopt autonomous response without losing oversight.”
According to RiskProfiler, each investigation keeps a full audit trail, including inputs, outputs, evidence, execution history and the versions of the agents and skills used. In security operations, that kind of traceability is often the difference between a useful automation layer and a system analysts cannot trust.
[ALSO READ: Netskope Introduces DataSec Command Center for Enterprise Data Security ]
Security teams already receive alerts from detection tools, but the hard part is often deciding what is real, what is noisy and what needs action. RiskProfiler states the workload includes look-alike and typosquatted domains, leaked credentials, vendor-breach signals, live phishing pages and threat-intelligence feeds, and that validating each one is still a manual process that slows response and remediation.
RiskProfiler is trying to compress the time between detection and action. It is targeting the investigation layer, which is where many security teams lose time and analyst capacity.
RiskProfiler describes KnyX Autonomous Investigations as part of its wider external threat and digital risk platform. The company says the platform unifies external attack surface management, brand protection, dark web monitoring, cyber threat intelligence, vulnerability management and third-party risk management into a single intelligence layer. It also says KnyX correlates threat signals, validates evidence and prioritizes remediation using attack-path context.
At launch, the company mentions KnyX includes autonomous agents for five main workflows: leaked credential investigation and password resets, look-alike and typosquatted domain investigation, live phishing-page analysis, vendor-breach validation and exposure assessment, and threat-intelligence filtering and prioritization.
[ALSO READ: IBM and Red Hat Expand Free Access to Lightwell for Universities, NGOs and Think Tanks ]
The system is designed to keep automation under customer control. Organizations can decide whether a response must run automatically, go to approval or remain disabled. Credential validation is limited to verified customer-owned domains and authorized identity providers, while vendor-breach claims are cross-checked across trusted sources before any response begins.
RiskProfiler’s approach is closer to an automated analyst workflow than a chat layer on top of alerts. Its focus on deterministic steps, audit trails and policy-gated remediation is also notable because it addresses the trust problem that usually limits autonomous security tools.
Compared with traditional threat-intelligence and digital risk platforms, KnyX is trying to reduce the handoff between “we found something” and “we proved it matters.” That is where many teams still burn time today. The product’s emphasis on evidence collection, breach validation and remediation policy suggests RiskProfiler is aiming at the operational middle of the security stack, not just the discovery layer.
RiskProfiler is saying that the volume of external threat alerts has outgrown manual triage, and that the response layer now needs machine-speed investigation with human-defined guardrails.
If KnyX can consistently produce usable verdicts, preserve a clean audit trail and avoid false automation on real customer data, it will have a practical case in the market. If not, it will join a long list of security tools that looked stronger in a product launch than in day-to-day operations.




















