LYNX delivers wire-speed intrusion detection through adversarial-resistant ML, JA4 TLS fingerprinting, QUIC/IPv6 normalisation, and TinyLlama false-positive reduction — no endpoint agents, no payload decryption.
LYNX operates as the network intelligence frontline of the PHALANX ecosystem. Wire-speed packet analysis is fused with multi-layered ML models that resist adversarial evasion, JA4 TLS fingerprinting for encrypted traffic classification, and a TinyLlama-powered false-positive reduction layer that keeps analyst workloads manageable at scale. Deployable on Linux x86, Windows, macOS, and embedded MIPS with graceful four-level degradation — LYNX never crashes under load. No endpoint agents required. No payload decryption.
Multi-layered detection models hardened against evasion techniques including adversarial perturbation and polymorphic payloads.
Encrypted traffic classification via JA4 fingerprinting — identifies threat actors without decrypting payload.
Full protocol support for QUIC, IPv6, and modern transport layers with complete normalisation pipeline.
TinyLlama LLM layer reviews candidate alerts before surfacing to analysts, reducing false positives by 94%.
Privacy-preserving federated learning across deployed LYNX nodes — shared detection insights without raw telemetry exposure.
Four-level degradation mode ensures LYNX continues operating under extreme load or partial hardware failure — never crashes.
Wire-speed packet capture from all configured sensors. QUIC and IPv6 traffic normalised before analysis.
L2–L7 protocol dissection with JA4 TLS fingerprinting for encrypted flow classification.
Adversarial-resistant ML models score each flow against threat signatures and behavioural baselines.
TinyLlama LLM layer evaluates candidate alerts. Only high-confidence detections surface to analysts.
AUGUR enriches detections with federated threat intelligence and adversary attribution.
Confirmed alerts dispatched to CIPHER for encrypted archival and to the PHALANX CORE for correlation.
LYNX shares real-time telemetry, threat intelligence, and response actions with every other application in the PHALANX ecosystem through the unified intelligence fabric.
Full-spectrum modular pen test framework — Rust TUI core, C++ probes, MITRE ATT&CK mapped.
Continuous misconfiguration detection across AWS, GCP, and Azure with automated remediation.
Threat feed aggregation, log correlation, and SOAR playbook automation in a streamlined platform.
CVE tracking and patch prioritisation by exploitability and business impact with full asset visibility.
Proprietary federated threat intelligence from all PHALANX nodes using privacy-preserving AI.