LYNX operates as the network intelligence frontline of the PHALANX ecosystem. Wire-speed packet analysis is fused with multi-layered ML models that resist adversarial evasion, JA4 TLS fingerprinting for encrypted traffic classification, and a TinyLlama-powered false-positive reduction layer that keeps analyst workloads manageable at scale. Deployable on Linux x86, Windows, macOS, and embedded MIPS with graceful four-level degradation — LYNX never crashes under load. No endpoint agents required. No payload decryption.
LYNX operates as a fully integrated node within the PHALANX unified intelligence fabric. All telemetry flows bidirectionally through the PHALANX CORE event bus, enabling real-time correlation across all seven applications without data silos or integration overhead.
LYNX supports all four PHALANX deployment models. Select the configuration that matches your infrastructure requirements and regulatory constraints.
LYNX is configured via YAML policy files deployed through the PHALANX CLI or management API. Configuration changes apply within 30 seconds without restart.
All configuration changes are logged immutably. Use phalanx config diff to preview changes before applying to production environments.
The LYNX REST API provides programmatic access to all module capabilities. All endpoints require Bearer token authentication using a PHALANX API key.
LYNX integrates with 18+ external platforms across 5 categories. All integrations are configured through the PHALANX management console or API.