RegenX · Windows resilience research

RegenX — Cyber resilience after prevention fails.

RegenX is an experimental Windows resilience platform exploring how an operating environment can detect signs of compromise, contain affected components, preserve trusted state, and recover toward a known-good condition.

Engineering prototype — validation requiredExplore the approach
RegenX RX shield and Autonomous Cyber Resilience wordmark

The problem

Prevention isn't enough.

Detection and prevention are essential, but they do not address everything that happens after a compromise occurs.

Endpoint security is typically designed to prevent malicious activity, detect it, or remove it after detection. RegenX investigates the next operational problem: how a Windows environment might respond when those first lines of defense are no longer sufficient.

That response calls for more than another alert. A resilient system needs a way to understand its current state, constrain affected components, protect a trusted reference point, and coordinate a path toward recovery.

The RegenX approach

A coordinated response after compromise.

Four functional areas frame how the prototype investigates system resilience.

System awareness

Observe

Kernel and user-space components monitor system state and behavior, providing signals that can inform response decisions.

Damage limitation

Contain

Isolation and sandboxing mechanisms are being developed to constrain affected components while keeping the wider environment manageable.

Trusted restoration

Recover

Recovery components are designed to return selected system state toward a defined trusted baseline rather than treating threat removal as the final step.

Integrity assessment

Verify

Measured-state and attestation research examines how the platform could determine whether recovered state should be trusted.

System architecture

How the major areas fit together.

The architecture connects Windows monitoring and user-space coordination to three related response paths.

High-level architecture

From system signals to a coordinated response

Operating environment

Windows system

Applications, services, files, and platform state

Kernel layer

Kernel monitoring

Low-level state and integrity observations

User space

Rust services and IPC

Coordination across prototype components

Boundary

Containment

Limit affected components

Recovery path

Trusted baseline

Return selected state toward a known-good condition

Integrity state

Measurement & verification

Evaluate whether recovered state should be trusted

High-level view of the RegenX architecture. Security-sensitive implementation details are intentionally omitted.

Current development state

A multi-module engineering prototype.

The current implementation establishes a meaningful systems foundation while deployment and runtime behavior remain active validation work.

Present in the prototype

Implemented system areas

  • Windows kernel components
  • Rust user-space services
  • IPC and component coordination
  • Desktop control interface
  • Recovery components
  • Containment and sandbox scaffolding
  • Measured-state and attestation research
Active development and validation

Active validation and development

  • Reproducible deployment
  • Driver installation and signing
  • Hardware-backed trust behavior
  • Containment effectiveness
  • Recovery behavior
  • Performance impact
Engineering prototype — validation required

RegenX remains an engineering prototype. Deployment, containment, recovery, hardware-backed trust, and performance behavior remain active validation areas.

Why RegenX

Designed around survivability, not only prevention.

Traditional endpoint security primarily focuses on preventing, detecting, and removing malicious activity. RegenX explores a complementary question: can an operating environment remain containable, recoverable, and trustworthy after compromise occurs?

The aim is not to add another detection layer. It is to investigate how monitoring, isolation, recovery, and measured trust can work as one coordinated resilience architecture.

Work with Korelis Labs

Interested in resilient-computing research?

Korelis Labs welcomes conversations around technical collaboration, research partnerships, government programs, and related work.

Discuss RegenX