RESEARCH & INCUBATION: SINE, IIT BOMBAY
CIN: U20299MH2025PTC448812
NEXT-GEN ITDR • ZERO-TRUST IDENTITY SECURITY

One Platform.
Total Identity Defense.
A Valid Login Can Hide an Attacker.

Traditional perimeter firewalls and endpoint agents fail when adversaries hold authentic credentials. Chromosight connects behavioral sequences, multi-hop relationship graphs, and controlled containment into one high-velocity SOC workspace.

Explore 5-Step Workflow
22% Breaches initiated by credential abuse (Verizon DBIR 2025)
1k–10k Target Enterprise Identity Estates
SINE Incubated at IIT Bombay, Mumbai
Chromosight Identity Threat Detection and Response SOC monitoring center
ACTIVE ITDR TELEMETRY STREAM
CRITICAL ALERT
SVC
Temporal Anomaly: Unfamiliar ASN → IAM Admin Escalation → Cross-Tenant Storage Query
98.4% RISK
Graph GNN Blast Radius 4 Nodes Contained
Inference Latency <140ms (TensorRT)
Action Recommended Revoke Token
THE ENTERPRISE THREAT VECTOR

When Credentials Are Valid, Conventional Defenses Fail Silently

Adversaries no longer use malware to break in—they log in with stolen session tokens, compromised service accounts, and unmonitored federated credentials.

VERIZON 2025 DBIR BENCHMARK
22%

Initial Attack Vector Across Enterprise Breaches

Credential abuse was confirmed as the initial vector in 22% of breaches reviewed in the landmark 2025 Data Breach Investigations Report (DBIR). Attackers move laterally across cloud and identity providers while masquerading as authorized personnel.

SCATTERED TELEMETRY • SOC DILEMMA

Four Urgent Questions Analysts Cannot Answer in Time

Authentication, device, and cloud SaaS events require analysts to manually reconstruct incidents across multiple disparate silos:

01

Who is actually operating the account?

Is this authorized human delegation, automated scheduled workflow, or an active adversary utilizing an exported bearer token?

02

What permissions mutated post-login?

Were privileged IAM roles, cloud service scopes, or administrative tenant policies quietly escalated behind the scenes?

03

Which concurrent sessions are linked?

Seemingly isolated alerts across Azure AD, Okta, and AWS IAM are frequently parts of the exact same continuous kill-chain.

04

What response containment is justified?

How does the SOC isolate the compromised account without inadvertently disrupting critical production business operations?

Digital authentication code and credential security matrix
UNIFIED ITDR WORKSPACE

Identity Signals Become Actionable Cases

Connect behavioral analysis, access relationship context, and controlled containment in one native platform designed for SOC analysts, IAM architects, and security engineering teams.

PHASE 01

DETECT

Continuously identify unusual login sequences, rapid privilege changes, dormant account reactivations, and atypical machine-to-machine service interactions.

Temporal Sequence Transformers
PHASE 02

INVESTIGATE

Build an automated evidence timeline across affected accounts, endpoint devices, cloud services, and mutated permissions into a single consolidated incident dossier.

Heterogeneous Identity Graphs
PHASE 03

RESPOND

Execute controlled remediation: revoke active OAuth/SAML tokens, enforce biometric step-up challenges, or freeze service credentials with complete role-based audit logs.

Governed Containment Controls
ENTERPRISE SOC SUITE

One Unified Workspace for Comprehensive Identity Defense

01

Identity Inventory

Continuous dynamic discovery of human users, contractors, federated entities, and non-human workload service accounts across multi-cloud identity providers.

  • Automated non-human service mapping
  • Inherited permission tree visibility
02

Threat Detection

Prioritize suspicious activity using contextual behavioral models, sequence transformers, and graph neural network risk clustering in real time.

  • Zero-heuristic machine learning models
  • Contextual behavioral deviation thresholds
03

Investigation Workspace

Combine related events, affected cloud resources, lateral access routes, and analyst annotations into one reviewable, chronological case dossier.

  • End-to-end blast radius visualization
  • One-click forensic event replay and export
04

Response Controls

Execute approved containment actions and retain an immutable audit trail with role-based access governance and native IdP/IAM integrations.

  • Analyst-approved automated mitigation
  • IdP session revocation & IAM policy quarantine
Cybersecurity SOC team using Chromosight unified ITDR workspace
OPERATIONAL EFFICIENCY

Designed for SOC Analysts & IAM Engineering Teams

Rather than jumping between disconnected security consoles, Chromosight unifies identity signals into a coherent attack story. Security teams collapse investigation times from hours down to seconds.

1 Single Case Replaces 15+ disparate alerts
< 3 Mins Mean Time to Investigate (MTTI)
END-TO-END ITDR PIPELINE

Five Steps from Raw Access Event to Controlled Response

A deterministic, auditable workflow turns high-volume streaming authentication logs into high-confidence, reviewable investigations.

01
DATA INGESTION Zero-Disruption Read Feeds

Connect Authentication & Audit Feeds

Stream real-time authentication events, directory changes, federated token exchanges, and API gateway logs from Microsoft Entra, Okta, Ping Identity, and cloud IAM audit trails.

02
SCHEMA RESOLUTION Normalized Graph Schema

Normalize Identities, Devices & Permissions

Standardize heterogeneous attributes into a unified identity graph. Resolve human identities, automated service accounts, device certificates, and nested security group hierarchies.

03
AI INFERENCE Parallel Domain Models

Analyze Behavior & Access Relationships

Execute four parallel domain models: evaluate temporal event sequences, graph relationship risk weights, and account-specific variational baselines to calculate compromise probability.

04
CASE SYNTHESIS Unified Incident Timeline

Investigate Related Signals in One Case

Synthesize disparate alerts across sessions into a unified chronological case file. Present analysts with the complete attack path, affected resources, and lateral blast radius.

05
GOVERNED ACTION Immutable Audit Trail

Respond with Governed Analyst Approval

Recommend proportional containment (revoke session, enforce MFA, or restrict service account). Security personnel review the evidence and trigger remediation with a single click.

ILLUSTRATIVE INVESTIGATION CASE

Service-Account Privilege Abuse & Lateral Access Contained

STEP 1
Anomalous Authentication: A production service account logs in from an unfamiliar hosting ASN outside its historical 180-day baseline subnet.
STEP 2
Privilege Escalation: Within 120 seconds, the account receives elevated tenant-level storage read rights without an associated Jira/ServiceNow change ticket.
STEP 3
Out-of-Profile Access: The account queries an internal production database it has never previously accessed.
⚡
Chromosight Defense Output: Chromosight links the multi-system sequence into a single case, flags the anomaly with 98.4% confidence, and prompts the analyst to immediately revoke the active bearer token and quarantine the service key.
PROPRIETARY MACHINE LEARNING ARCHITECTURE

Four Domain Models, One Unified Detection Pipeline

Chromosight replaces rigid heuristic correlation rules with four specialized machine learning models purpose-built for enterprise identity graphs and temporal sequences.

GRAPH ML

IdentityGraph

Heterogeneous Graph Neural Network (GNN)

Captures complex, multi-hop relationship graphs between accounts, devices, roles, and permissions to uncover high-risk privilege clusters and lateral attack paths.

Focus: Risky account, device, and permission relationships
TEMPORAL TRANSFORMER

AccessSequence

Temporal Transformer Architecture

Evaluates chronological order and inter-event duration in authentication sequences, recognizing suspicious bursts and rapid privilege mutation patterns.

Focus: Anomalous authentication sequences & rapid escalation
DEEP GENERATIVE

BehaviorTrace

Temporal Convolutional VAE (TCN-VAE)

Constructs continuous, role-specific behavioral embeddings to detect subtle, out-of-distribution drift without generating high false-positive alert volumes.

Focus: Account-specific behavioral deviations & dormant drift
SIMILARITY LEARNING

SessionLink

Siamese Similarity Network

Calculates behavioral similarity across distinct sessions and identity boundaries to reveal adversaries rotating credentials and leaping between accounts.

Focus: Correlating suspicious sessions across multiple identities

Planned Production Architecture

  • • Engine: Python, PyTorch, CUDA Accelerated Training
  • • Streaming Data: Distributed Event Ingestion & Analytical Graph Storage
  • • Inference Engine: ONNX Runtime / TensorRT for sub-second scoring

Validation Data Target

Targeting 10 million permissioned and simulated access events with task-specific weights trained from random initialization and benchmarked against standard heuristics across independent customer timeframes.

R&D at SINE, IIT Bombay • Rigorous statistical evaluation
TARGET AUDIENCE & COMMERCIAL MODEL

Built for Complex Enterprise Identity Estates

Initial deployment profile targets organizations managing between 1,000 and 10,000 identities with an established identity provider and dedicated SOC defense personnel.

SECTOR 01

Financial Services & FinTech

High-value transaction systems, strict regulatory mandates (RBI, SOX), and zero tolerance for lateral identity privilege escalation.

SECTOR 02

SaaS & Cloud Platforms

Distributed microservices architectures managing thousands of automated tokens and workload identities vulnerable to credential exposure.

SECTOR 03

Manufacturing Groups

Complex hybrid environments combining legacy on-prem Active Directory forests with contemporary cloud identity providers.

SECTOR 04

Service-Account-Heavy Estates

Organizations where non-human machine-to-machine integrations outnumber human employees 3:1, requiring continuous relationship tracing.

TRANSPARENT SUBSCRIPTION MODEL

Predictable Pricing That Scales With Protected Identities

Transparent recurring software model engineered for enterprise identity defense.

₹24 Lakh Illustrative Annual Contract Value
Annual Platform License ₹6,00,000 / yr Includes ingestion pipeline, core model inference, and role-based incident workspaces.
+
Per Protected Identity ₹100 / identity / mo Full continuous profiling for human accounts, contractors, and workload service accounts.
=
Representative (1,500 Identities) ₹24,00,000 / yr ₹6L base + (1,500 × ₹100 × 12 mo = ₹18L) with defined event retention tiers.
₹2,400 Cr Broader Addressable Market (10,000 Organizations × ₹24L ACV)
₹240 Cr Initial Serviceable Market (1,000 Target Indian Enterprises)
₹12 Cr ARR Three-Year Scenario (50 Enterprise Customers @ 75% Gross Margin)
ENTERPRISE VALIDATION PROGRAM

6–8-Week Design Partner Pilots

Chromosight is actively partnering with select enterprise security teams to benchmark model precision, quantify investigation time reduction, and streamline deployment.

COHORT SPECIFICATIONS

Design Partner Cohort Goals

  • ✔
    3 Dedicated Design Partners: Direct collaboration with our senior ML and platform engineering team at SINE, IIT Bombay.
  • ✔
    6–8-Week Structured Pilot: Non-intrusive read-only telemetry ingestion with zero disruption to active business operations.
  • ✔
    Adversary Simulation Testing: Test account takeover vectors, stealth privilege escalation, and lateral service-account hijacking.
  • ✔
    Measurable KPI Validation: Prove precision, detection coverage, Mean Time to Investigate (MTTI), and effortless deployment overhead.
COMPETITIVE BENCHMARKING

How Chromosight Proves Incremental Value

A specialized product must demonstrate distinct, measurable value over legacy and bundle options:

vs. Microsoft Entra & Defender Integrated Suite
The Chromosight Test: Does our cross-cloud graph and unified investigation case reduce tier-2 escalation overhead compared to native alerts?
vs. CrowdStrike Falcon Identity Endpoint Platform
The Chromosight Test: Can an identity-first, standalone deployment deliver faster time-to-value for complex non-human and service-account estates?
vs. Existing SIEM Rules Configured Correlation
The Chromosight Test: Can machine learning-driven relationship linking eliminate manual event aggregation and reduce alert fatigue?
EXECUTION ROADMAP

Twelve Months from Prototype to Paid Deployment

MONTHS 1–3

Foundation

First identity integration; ingestion and identity resolution; investigation timelines; rules baselines and attack datasets.

MONTHS 4–6

Pilot Phase

Prototype AccessSequence and BehaviorTrace; start 3 design-partner pilots; measure alert quality and investigation effort.

MONTHS 7–9

Expand

Prototype IdentityGraph and SessionLink; add a second integration; introduce approved response actions and access controls.

MONTHS 10–12

Commercialize

Target 2 pilot conversions and 5 total customers; benchmark inference cost and latency; independent security assessment.

FOUNDATION & GOVERNANCE

Anchored in Research & Enterprise Execution

Headquartered in Mumbai, India, Chromosight Technologies combines rigorous artificial intelligence research with scalable distributed systems engineering.

IIT Bombay campus and premier technology ecosystem
SINE, IIT BOMBAY

"Advancing deep graph neural networks for enterprise identity defense."

Entity Name Chromosight Technologies Private Limited
Corporate ID (CIN) U20299MH2025PTC448812
Incorporation Date May 20, 2025 • Active
Registered Address 5th Floor, Seat No. 10, SINE, RBTIC, IIT Bombay, Powai, Mumbai, Maharashtra 400076, India
BOARD & LEADERSHIP

Leadership Supported by Security & ML Execution

Engineering-driven leadership dedicated to advancing deep learning in production cybersecurity:

BK

Babar Ali Khan

Director

Security engineering integrations, threat research, and machine learning models for behavioral identity distributions.

MN

Madhu Nayak

Director

Platform engineering, high-throughput multi-tenant telemetry ingestion, tenant isolation, and enterprise adoption.

Priority Capabilities

Threat Research GNN & Transformer ML Tenant Isolation Design Partner Execution
COHORT PILOT INTAKE

Let’s Validate Identity Defense Together

Chromosight is seeking enterprise security teams for its first design-partner pilots. Define a limited pilot, determine required telemetry feeds, and measure tangible reduction in identity risk.

✔ Direct collaboration with senior engineers at SINE, IIT Bombay
✔ Custom behavioral profiling tailored to your unique service-account footprint
✔ Design partner preferred commercial terms and roadmap governance
Email Engineering Team

Registered Office & Contact

Chromosight Technologies Private Limited

5th Floor, Seat No. 10, SINE, RBTIC,
IIT Bombay, Powai, Mumbai,
Maharashtra 400076, India
CIN: U20299MH2025PTC448812
Directors: Babar Ali Khan • Madhu Nayak
Pilot Cohort: 3 Enterprise Seats (Open)