The Product
Chain Monitor Online Transaction Monitoring
Chain Monitor is our purpose-built OTM platform: it analyzes blockchain transactions in real time, fusing four signal layers, Blockchain Data, Behavioral Analysis, Risk Intelligence, and Rule-Based Detection, into one workspace that cuts manual review effort while raising detection quality.
Blockchain Data
Live transaction, event, and contract data streamed from monitored networks
Behavioral Analysis
Historical baselines that reveal when activity breaks its normal pattern
Risk Intelligence
Flagged addresses, mixers, sanctions and known threat associations
Rule-Based Detection
Security rules and client-specific operational policies (runbooks)
Product Spec 01
Alert Detection Engine
Alerts fire when on-chain events match one or more of three detection layers: security rules, operational policies, or behavioral baselines.
Three-layer matching
Security rules
Pre-defined checks for risky actions
Operational policies
Client-approved rules, limits and allow-lists
Behavioral baselines
Historical patterns that expose unusual activity
Each alert ships with the transaction hash, involved addresses, triggered rule, severity classification (S1 Critical / S2 High / S3 Low), and AI-generated context.
Core detection categories
Token Mint Detection
Flags unusual issuance, excessive volume or mints from unexpected wallets
Ownership Change Detection
Watches admin and ownership changes that can signal contract compromise
Large Transfer Detection
Catches treasury draining, insider movement, and laundering patterns
Suspicious Wallet Behavior
Rapid transfers, mixer usage, and links to previously flagged addresses
Product Spec 02
AI-Powered Behavioral Analysis
Detection rules are deliberately broad, firing on every match and mixing genuine threats with routine events. Chain Monitor's AI layer tells analysts which fired alerts actually deserve attention first.
Behavioral Context Evaluation
Every alert is read in context, not isolation, wallet history, counterparties, timing, and whether the pattern matches known legitimate workflows.
Alert Triage Scoring
Each alert receives a priority score so analysts work the queue by real risk, not arrival order.
False Positive Reduction
Recurring benign patterns are learned and down-weighted, shrinking noise without silencing rules.
Continuous Model Training
Analyst dispositions feed back into the model, it keeps learning what 'normal' looks like for each environment.
Product Spec 03
Structured Alert Lifecycle
Every alert follows the same five-stage sequence, Alert Generation, Assignment, Acknowledgement, Investigation, Final Disposition, so nothing is missed, every finding is documented, and every decision is made with full context.
Alert Generation
Engine auto-creates the alert with severity, rule, and AI analysis
Assignment
Team lead assigns by severity, workload, and expertise
Acknowledgement
Analyst reviews details and records initial observations
Investigation
Deep-dive on wallets, contracts, transactions & relationships
Final Disposition
True Positive / False Positive / Informational, with evidence
Threat Intelligence Map
Opening any alert surfaces a visual relationship graph of every connected entity, networks, smart contracts, transaction clusters, wallets, and related open alerts, as color-coded nodes, alongside runbook guidance, AI analysis, and transaction metadata: everything an analyst needs to complete an investigation from a single view.
Product Spec 04
Audit Trail, SLA Analytics & Reporting
Every alert is timestamped hop by hop, from receipt, through notification, to client acknowledgement. We measure ourselves against hard SLA targets, publish the results, and flag every breach with a named owner and corrective action.
Tamper-Proof Audit Trail
Every action is permanently recorded with user, timestamp, and IP address, and can never be edited or deleted, so investigation decisions stay traceable to a specific analyst, disposition changes are always logged with context, and compliance documentation writes itself.
Built-in SLA targets
< 15 min
S1 Critical
< 60 min
S2 High
< 240 min
S3 Low
Executive dashboards track alerts per day, MTTR, and alert breakdown by runbook.
Seven report types: 24h to 90-day ranges
Analyst Performance
Workload, acknowledgements, SLA & FP counts per analyst
SLA Compliance
Target vs actual response times and breach percentage
Disposition Outcomes
TP / FP breakdown by runbook and analyst
Incident Log
Escalated alerts with references and time-to-escalate
Chain Activity
On-chain activity by event type, network, and top contracts
Runbook Effectiveness
FP rate, MTTR, and volume per detection rule
Full Alert Detail
Complete export for audits and detailed review
Security operations
around the world.
No matter where your team or your customers are, someone at CROC is already watching.
Talk to the CROC team