CHRONOLITH · CAPABILITY BRIEFS

What it does, and what it cannot see.

Eleven briefs, one per capability. Each describes the mechanism rather than the feature, states the figures measured from the shipping build, and says plainly where the product is blind.

01

Who Can, Who Did

File access & permissions

File access auditing and NTFS permission monitoring for firms without a security team. See who has access to every shared folder, who actually touched it, what they changed, and where a file went — from one on-premises appliance.

02

Will Your AI Touch My Estate?

Remediation authority

The first question every security leader asks about AI in the security stack. Chronolith can act on endpoints. The AI inside it cannot — and that is a property of the architecture, not a setting somebody could switch on.

03

Can You Prove That Control?

Control evidence & insurance

Cyber insurance renewals and compliance reports ask yes-or-no questions about your security controls. Most firms answer from memory. Chronolith grades every answer by the evidence behind it — and will not let itself claim more than it can show.

04

What Does It Actually Detect?

Detection & correlation

A question most SIEM vendors answer with a number. Here is the rule count, the technique coverage, how the rules get onto your appliance safely — and which of them your estate can actually run.

05

Did the Fix Actually Work?

Cases & remediation verification

Most incident tooling closes a case when somebody ticks a box. Chronolith watches for the log events the fix should have produced — and marks the case verified only when it sees them.

06

How Do You Get the Logs?

Ingest & collection

Collection is the part of a SIEM deployment that actually fails. What installs, what happens when it is installed everywhere or twice, and how a collector that falls behind is stopped from losing data quietly.

07

The Problems Nobody Alerted On

Operations intelligence

A firm without an IT department does not need more alerts. It needs a short, calm list of things worth fixing this week — the credential nobody retired, the server that stopped reporting, the disk heading for a wall.

08

Do You Know Every Certificate?

Certificate lifecycle

Certificate outages are almost always caused by the certificate nobody wrote down. Chronolith finds them by looking, tracks what is expiring, and — the part most tools skip — proves a replacement actually took effect.

09

Where Does the Threat Data Come From?

Threat intelligence & indicators

Public and government feeds, matched against your own events, with a review workflow that stops a match being either ignored or over-read. Named sources, no mystery “proprietary intelligence”.

10

Whose Rules Are These?

Estate, identity & access

Most access-boundary detection ships somebody else's org chart as a rule and reports your firm for not matching it. Chronolith learns what your estate actually does, and tells you when that changes.

11

Who Watches the Watchers?

Investigation & evidence custody

A security product holds a complete record of what everyone in the firm did. That is exactly as dangerous as it is useful — so deep access takes two people, every use is recorded, and the record itself is built to show if anyone edited it.

A longer technical edition of each brief exists for an engineering review — the same ground covered at implementation depth. Ask at hello@aperlock.com and we will send it.