kimo
[DI]//Feature tour

Every capability,mission-ready.

Connect, model, visualize, ask, alert, share and govern. Here is everything Kimo Defense Intelligence does, each shown on simulated data, with the editions it ships in.

07
Groups
19
Capabilities
46
Connectors
03
Deployment modes
01
Connect
3 features

Every feed, one ingest plane.

Stream sensor topics, pull SIEM detections and monitor open sources without writing glue code. On the high side, import signed bundles across the gap.

01.1 // CONNECT

Streaming ingest

Kafka topics, AIS and ADS-B feeds land in Kimo within seconds, normalized to a common event schema.

  • Back-pressure aware, exactly-once into the event store
  • Per-feed latency, gap and schema-drift monitoring
  • Replay any window for after-action review
Ingest // live feeds5 / 18
Feed / topicev/slag
Apache Kafka
sensors.radar.n4
1,9580.4s
AIS Maritime
ais.positions
3,2851.8s
ADS-B Air Traffic
adsb.tracks
2,3870.9s
Splunk
splunk.notable
3712.6s
Telegram Channels
osint.channels
916.2s
4 healthy1 schema driftexactly-once · replay 30d
01.2 // CONNECT

Security & OSINT connectors

Splunk, Elastic, EDR, Datadog, GitHub audit logs, Telegram channels, Reddit and curated news feeds, ready to switch on.

  • Credentials held in your vault, never in Kimo config
  • Translation and geotagging for open sources
  • Rate limits and source terms respected by default
Connectors // catalog46 available
› search 46 connectors
Splunk
Elastic Security
EDR Telemetry
Datadog
GitHub
Apache Kafka
AIS Maritime
ADS-B Air Traffic
OSINT Feeds
Telegram Channels
Reddit
OpenStreetMap
01.3 // CONNECT

Cross-domain import

Move data into an air-gapped enclave as signed, hash-verified bundles through your data diode or approved media.

  • Ed25519-signed manifests, verified before ingest
  • Quarantine and content inspection hooks
  • Full provenance kept for every imported record
Cross-domain // importenclave-a
HIGH SIDE·one-way transfer · no return path
$ kimo-import verify /media/diode/bundle-20261010.kbx
manifest.sig ed25519VALID
chunks 128/128 sha256MATCH
content inspection 3 rulesCLEAN
provenance attachedOK
→ imported 1,204,551 records into enclave-a
02
Model
3 features

From raw events to scored incidents.

Kimo resolves entities across sources, applies your correlation logic and keeps the lineage of every conclusion it draws.

02.1 // MODEL

Entity resolution

One vessel, one host, one persona, even when every feed spells it differently.

  • Deterministic keys (IMO, MMSI, IP, hash) plus fuzzy matching
  • Analyst-confirmed merges are reversible and audited
  • Watchlists match on resolved entities, not strings
Model // entity resolution4 → 1
MMSI 257 0x4 410
“Nordic Dawn” tanker
Port call · N. DAWN
@nordicdawn_crew
Entity · Vessel
NORDIC DAWN
IMO 94xxxx1 · demo
match0.97
02.2 // MODEL

Incident fusion & scoring

Correlation rules combine OSINT, SIEM and sensor evidence into one incident with a transparent confidence score.

  • Rules as readable YAML, versioned and peer-reviewed
  • Score breakdown shows exactly which evidence counted
  • Suppression windows to keep repeat noise out of the queue
Fusion // score breakdownrule v4
rule: cable-loiter-v4
when:
  - ais.gap ≥ 6h
  - zone = cable
boost:
  - osint.geo ≤ 5km
  - adsb.gnss degraded
suppress: 12h
route: cell/maritime
INC-4833High
AIS gap ≥ 6h+0.34
Within 2 nm of cable corridor+0.22
Open-source report, geolocated+0.18
GNSS degradation, same sector+0.17
Confidence0.91
02.3 // MODEL

Lineage & provenance

Every number traces back to the raw record, the time it was ingested and each transformation applied.

  • Click-through from incident to source event
  • Transformation history stored with the data
  • Exportable evidence chain for legal review
Lineage // INC-48335 hops
  1. RAW
    kafka · ais.positions · offset 88 214 019
    03:12:44Z
  2. NORMALIZED
    schema event.v7 · mmsi → entity
    03:12:45Z
  3. ENRICHED
    zone: cable-corridor-B (osm)
    03:12:45Z
  4. MATCHED
    rule cable-loiter-v4 @ r12
    09:24:10Z
  5. INCIDENT
    INC-4833 · confirmed by k.rao
    09:31:52Z
03
Visualize
3 features

A common operating picture.

Maps, timelines and matrices built for watch floors: dense, legible and fast on a 4K wall or a laptop in the field.

03.1 // VISUALIZE

Situation map

Tracks, incidents and infrastructure layers on one map, with offline tiles for disconnected sites.

  • OpenStreetMap infrastructure layers, served locally
  • Track history with gap highlighting
  • Zones of interest with entry/exit rules
COP // Baltic & North Seasimulated
INC-4833
Vessel trackAircraft trackCable corridoroffline tiles · OSM
03.2 // VISUALIZE

Multi-source timeline

Line up cyber, maritime, air and OSINT events on one Zulu timeline to see what happened first.

  • Swimlanes per source family
  • Brush to filter every panel at once
  • Pin events to an incident in one click
Timeline // 06:00Z–10:00Z28 events
Cyber
Maritime
Air
OSINT
06:00Z07:00Z08:00Z09:00Z10:00Z
Brush 08:42Z → 09:36Z · 11 events · 4 sourcesfirst signal: AIS 08:51Z
03.3 // VISUALIZE

MITRE ATT&CK coverage

See detections by tactic and technique, spot coverage gaps and pivot straight into the alerts behind each cell.

  • Mapped automatically from Splunk & Elastic rules
  • Heat by volume or by confirmed incidents
  • Coverage report for your next audit
SOC // ATT&CK coverage7 days
Recon
Access
Exec
Persist
Priv
Evade
Creds
Lateral
C2
Exfil
Init. access · T1017
96 detections · 7d
04
Ask
2 features

Ask in plain language. Get cited answers.

Ask Kimo runs on models you host. Every answer cites the records it used, and it only sees what the analyst is cleared to see.

04.1 // ASK

Ask Kimo, on your GPUs

Natural-language questions over your models, answered with charts, tables and citations.

  • Runs on local open-weight models, no external API
  • Answers respect the asker’s clearances
  • Every generated query is shown and auditable
Ask Kimo // local modelcited
Which vessels went dark near cable corridor B in the last 24h?

Three vessels went dark within 5 nm of cable corridor B in the last 24h. NORDIC DAWN (demo) is the only one that also loitered > 2h; it is linked to INC-4833.

Gap duration, hours
NORDIC DAWN
6.2
MV ALDER (demo)
1.4
KESTREL 7 (demo)
0.9
[1]AIS · 3 tracks[2]OSM · cable-B[3]OSINT · 2 reports
local open-weight model · 4× GPU · no external API
04.2 // ASK

Shift briefs in one click

Draft the morning brief from the last 12 hours of incidents, with markings applied per paragraph.

  • Templates per audience and releasability
  • Analyst review before anything is shared
  • Paragraph-level classification markings
Briefs // morningdraft
MORNING BRIEF · WATCH B
Baltic & North Sea, 10 OCT 2026
Draft
(U)Key judgement
(U)Maritime
(U//REL)Cyber
(U)Outlook, next 12h
sources: 37 incidents · 12hreview: lead.m.dubois
05
Alert
3 features

Detect what changed, not everything.

Behavioural baselines and purpose-built detectors flag the anomalies that matter and route them to the right cell.

05.1 // ALERT

Dark-vessel detection

Flags AIS gaps, spoofed positions and loitering near sensitive infrastructure, then scores them against context.

  • Gap, jump and speed-plausibility detectors
  • Corridor and zone context (cables, ports, EEZ)
  • Fused with ADS-B and OSINT for confidence
Detector // AIS gapMAR
CABLE-BAIS GAP 6h12mNORDIC DAWN (demo) · 11.4 kn
DETECTOR · ais-gapHigh
Gap overlaps cable corridor for 41 min. Loiter on reappearance.
05.2 // ALERT

Supplier risk watch

Monitor suppliers and parts for sanctions hits, cyber exposure, financial stress and single-source dependencies.

  • Risk score per supplier with driver breakdown
  • Alerts when a tier-2 supplier changes ownership
  • Lead-time and stock coverage from your ERP
Logistics // supplier risk312 suppliers
Supplier · partStatus
Halvard Optics · IR sensor lens
Ownership changeSingle source
High
Kestrel Composites · Radome panels
Financial stress
Medium
Marlow Microsystems · FPGA boards
Cyber exposure
Low
Tidewater Castings · Housings
—
Clear
ERP stock coverage · lead times · sanctions lists (offline)
05.3 // ALERT

Routing & escalation

Send each incident to the right watch cell with SLAs, on-call rotations and escalation tiers.

  • Rules by type, zone, severity and compartment
  • Acknowledge, hand over or escalate from anywhere
  • Webhook and syslog out to your ticketing
Routing // escalationrota B
INC-4833AIS gap near cable corridorHigh
route: type=maritime · zone=baltic · compartment=MAR
  1. T+0
    Maritime cell
    ack ≤ 5 min
    Acked 02:14
  2. T+15
    Watch lead
    if unresolved
    Standby
  3. T+45
    Duty officer
    if severity ≥ high
    —
webhook → ticketingsyslog → SIEMon-call rota B
06
Share
2 features

Share up, down and across. Safely.

Watch handovers, mission workspaces and releasable exports, all governed by the same markings and access rules.

06.1 // SHARE

Mission workspaces & handover

Each cell gets a workspace with its incidents, notes and dashboards. Shift handover is a single, signed record.

  • Open items, decisions and owners in one view
  • Comments and annotations kept with the incident
  • Read receipts for the incoming watch
Workspace // handovercell MAR
HANDOVERWatch BWatch C18:00Z
  • INC-4833 confirmed, track watch until 14:00Z
  • Phishing wave T1566: 2 clicks contained
  • Verify eyewitness thread, OSINT-2291
  • Brief ministry liaison at 08:30Z
signed lead.m.dubois · sha256 7f3a…c91e · read by 3/3
06.2 // SHARE

Releasable exports

Export briefs and data with markings, redactions and releasability applied automatically.

  • Redaction of fields above the recipient’s level
  • Watermarked PDF, CSV and GeoJSON
  • Every export logged with its recipient
Export // releasability3 items
FORMAT
PDFCSVGEOJSON
RELEASABLE TO
PARTNER-A (demo)
REDACT
sources
analyst names
INC-4833NORDIC DAWNMAR
INC-4844Narrative spikeOSINT
INC-4850VPN brute forceCYB
watermark · export loggedExport
07
Govern
3 features

Sovereign by design.

Need-to-know access, tamper-evident audit and deployments that never phone home. Built to pass accreditation, not just demos.

07.1 // GOVERN

Need-to-know access (ABAC)

Policies evaluate clearance, compartment, nationality and mission at query time, down to individual rows.

  • Classification labels on rows, columns and files
  • Policies as code, tested before they ship
  • Explain mode: why access was allowed or denied
Access // policy evaluationABAC
SUBJECT → OBJECT
analyst.k.rao → incident/INC-4833
ALLOW
AttributeSubjectRequired
clearanceL3≥ L3
compartmentMARMAR
nationNATION-ANATION-A
missionBALTICBALTIC
policy maritime-need-to-know@v12 · evaluated in 0.4 ms · logged
07.2 // GOVERN

Hash-chained audit trail

Every view, query and export is written to an append-only, hash-chained log you can forward to your SIEM.

  • Tamper-evident: any edit breaks the chain
  • Syslog / CEF forwarding to Splunk or Elastic
  • Retention rules per compartment
Audit // append-onlychain ok
TimeActorResult
09:45:18Zanalyst.k.rao EXPORTdeny
09:44:37Zanalyst.t.berg ANNOTATEallow
09:43:56Zadmin.s.novak ROLE_CHANGEallow
09:43:15Zcontractor.p.lee VIEWdeny
09:42:34Zanalyst.j.ortega QUERYallow
09:41:53Zlead.m.dubois EXPORTallow
chain verified · forwarding CEF → SIEM
07.3 // GOVERN

Cloud, on-prem or air-gapped

The same product in a sovereign cloud, your data center or a classified enclave, with keys in your HSM.

  • Offline installer and signed update bundles
  • No telemetry, no licence call-home
  • Customer-managed keys, rotate or revoke any time
Deploy // topologyany
Sovereign cloud
Single-tenant · in-country
On-premise
K8s / bare metal · your HSM
Air-gapped
Offline · signed bundles
LOW SIDEfeeds, updatesDIODE ▶ENCLAVEKimo + local LLMegress: 0 B · no call-home
08
Compare

Kimo vs spreadsheets vs legacy BI.

What most intelligence cells run on today, and what changes when fusion, access control and audit are built in.

Capability comparison between Kimo Defense Intelligence, spreadsheets and legacy BI tools
CapabilityKimo DISpreadsheetsLegacy BI
Real-time fusion of OSINT, SIEM and sensorsLegacy BI refreshes on schedules, not streams.YesNoPartial
Entity resolution across sourcesYesNoNo
Transparent incident scoringYesPartialNo
MITRE ATT&CK mappingYesNoNo
Situation map with track historyYesNoPartial
Plain-language questions with citationsMost assistants call external APIs.YesNoPartial
Row-level ABAC & classification labelsYesNoPartial
Hash-chained audit trailYesNoNo
Air-gapped deployment, no call-homeSpreadsheets are offline, and unaudited.YesYesPartial
Live in under two weeksYesYesNo

Typical capabilities, for illustration. Your mileage with a given vendor may vary.

[END]//Next step

See it on your feeds. Not ours.

Bring two or three sources to a 45-minute working session and leave with scored incidents, or open the live demo now. All demo data is simulated.