Isolate
Provision a disposable sandbox and launch a controlled browser session.
KRAXX SECURITY RESEARCH
Execute suspicious webpages inside isolated research environments. Observe the agent, browser, network and system — then reconstruct the evidence.
A clearer view of hostile behavior
A page is only one part of the story. KraxxDeceit connects an agent’s browser actions with network activity and sandbox observations, preserving where each finding came from.
Start with a URLRESEARCH INSTRUMENTS
Each layer answers a different question. The result is a richer record of what the investigation actually observed.
A repeatable research loop
Provision a disposable sandbox and launch a controlled browser session.
Record browser activity alongside available network and system telemetry.
Compare phases and connect events while preserving source and timing.
Review the evidence graph, hypotheses, timeline, and portable case.
EXAMPLE RESEARCH CASE · STAGE 1.8
A recorded synthetic prompt-injection experiment checked whether an agent would change its task after reading hostile page content. The visible result is limited to actions and telemetry the run actually recorded.
Run your own investigationSelect a layer to inspect the example’s observation boundaries.
WHY KRAXXDECEIT
KraxxDeceit records what the environment observed, so a research case can be reviewed against its evidence.
See browser behavior and available system activity in a single case.
Compare baseline and agent behavior with source, timing, and attribution intact.
Review evidence-supported hypotheses alongside missing observations and uncertainty.
RESEARCH DOMAINS
RESEARCH QUESTIONS
Controlled experiments record the page content an agent encounters, the browser tools it requests, and the policy decisions those requests receive. Outcomes reflect observed actions, including ignored instructions and blocked requests.
Playwright records browser navigation and network activity. The attribution and differential engines compare baseline and agent phases so provisioning, pre-action, and ambient events are not treated as agent-caused evidence.
Procfs and socket providers sample process and connection activity inside the disposable sandbox. Recorded PID, executable, timing, and destination fields provide system context; missing observations remain visible as limitations.
The deterministic hypothesis engine evaluates recorded events and linked evidence. Findings can be supported or have insufficient evidence; the case preserves the source events and limitations for review.
OPEN RESEARCH TOOLING
Explore the code, review the evidence model, and run the console locally. Cases can be exported for review and reproducibility.
Explore KraxxDeceit on GitHub Read the case formatTHE INVESTIGATION CONSOLE
Submit a target to create a controlled browser investigation and generate an inspectable research case.
MAKE THE NEXT QUESTION OBSERVABLE
Run a controlled experiment with KraxxDeceit.