Observe
Kernel and user-space components monitor system state and behavior, providing signals that can inform response decisions.
RegenX · Windows resilience research
RegenX is an experimental Windows resilience platform exploring how an operating environment can detect signs of compromise, contain affected components, preserve trusted state, and recover toward a known-good condition.
The problem
Detection and prevention are essential, but they do not address everything that happens after a compromise occurs.
Endpoint security is typically designed to prevent malicious activity, detect it, or remove it after detection. RegenX investigates the next operational problem: how a Windows environment might respond when those first lines of defense are no longer sufficient.
That response calls for more than another alert. A resilient system needs a way to understand its current state, constrain affected components, protect a trusted reference point, and coordinate a path toward recovery.
The RegenX approach
Four functional areas frame how the prototype investigates system resilience.
Kernel and user-space components monitor system state and behavior, providing signals that can inform response decisions.
Isolation and sandboxing mechanisms are being developed to constrain affected components while keeping the wider environment manageable.
Recovery components are designed to return selected system state toward a defined trusted baseline rather than treating threat removal as the final step.
Measured-state and attestation research examines how the platform could determine whether recovered state should be trusted.
System architecture
The architecture connects Windows monitoring and user-space coordination to three related response paths.
Applications, services, files, and platform state
Low-level state and integrity observations
Coordination across prototype components
Limit affected components
Return selected state toward a known-good condition
Evaluate whether recovered state should be trusted
Current development state
The current implementation establishes a meaningful systems foundation while deployment and runtime behavior remain active validation work.
RegenX remains an engineering prototype. Deployment, containment, recovery, hardware-backed trust, and performance behavior remain active validation areas.
Why RegenX
Traditional endpoint security primarily focuses on preventing, detecting, and removing malicious activity. RegenX explores a complementary question: can an operating environment remain containable, recoverable, and trustworthy after compromise occurs?
The aim is not to add another detection layer. It is to investigate how monitoring, isolation, recovery, and measured trust can work as one coordinated resilience architecture.
Work with Korelis Labs
Korelis Labs welcomes conversations around technical collaboration, research partnerships, government programs, and related work.