Skip to content

The Product

Chain Monitor Online Transaction Monitoring

Chain Monitor is our purpose-built OTM platform: it analyzes blockchain transactions in real time, fusing four signal layers, Blockchain Data, Behavioral Analysis, Risk Intelligence, and Rule-Based Detection, into one workspace that cuts manual review effort while raising detection quality.

Blockchain Data

Live transaction, event, and contract data streamed from monitored networks

Behavioral Analysis

Historical baselines that reveal when activity breaks its normal pattern

Risk Intelligence

Flagged addresses, mixers, sanctions and known threat associations

Rule-Based Detection

Security rules and client-specific operational policies (runbooks)

Product Spec 01

Alert Detection Engine

Alerts fire when on-chain events match one or more of three detection layers: security rules, operational policies, or behavioral baselines.

Three-layer matching

1

Security rules

Pre-defined checks for risky actions

2

Operational policies

Client-approved rules, limits and allow-lists

3

Behavioral baselines

Historical patterns that expose unusual activity

Each alert ships with the transaction hash, involved addresses, triggered rule, severity classification (S1 Critical / S2 High / S3 Low), and AI-generated context.

Core detection categories

Token Mint Detection

Flags unusual issuance, excessive volume or mints from unexpected wallets

Ownership Change Detection

Watches admin and ownership changes that can signal contract compromise

Large Transfer Detection

Catches treasury draining, insider movement, and laundering patterns

Suspicious Wallet Behavior

Rapid transfers, mixer usage, and links to previously flagged addresses

Product Spec 02

AI-Powered Behavioral Analysis

Detection rules are deliberately broad, firing on every match and mixing genuine threats with routine events. Chain Monitor's AI layer tells analysts which fired alerts actually deserve attention first.

Behavioral Context Evaluation

Every alert is read in context, not isolation, wallet history, counterparties, timing, and whether the pattern matches known legitimate workflows.

Alert Triage Scoring

Each alert receives a priority score so analysts work the queue by real risk, not arrival order.

False Positive Reduction

Recurring benign patterns are learned and down-weighted, shrinking noise without silencing rules.

Continuous Model Training

Analyst dispositions feed back into the model, it keeps learning what 'normal' looks like for each environment.

Product Spec 03

Structured Alert Lifecycle

Every alert follows the same five-stage sequence, Alert Generation, Assignment, Acknowledgement, Investigation, Final Disposition, so nothing is missed, every finding is documented, and every decision is made with full context.

1

Alert Generation

Engine auto-creates the alert with severity, rule, and AI analysis

2

Assignment

Team lead assigns by severity, workload, and expertise

3

Acknowledgement

Analyst reviews details and records initial observations

4

Investigation

Deep-dive on wallets, contracts, transactions & relationships

5

Final Disposition

True Positive / False Positive / Informational, with evidence

Threat Intelligence Map

Opening any alert surfaces a visual relationship graph of every connected entity, networks, smart contracts, transaction clusters, wallets, and related open alerts, as color-coded nodes, alongside runbook guidance, AI analysis, and transaction metadata: everything an analyst needs to complete an investigation from a single view.

Product Spec 04

Audit Trail, SLA Analytics & Reporting

Every alert is timestamped hop by hop, from receipt, through notification, to client acknowledgement. We measure ourselves against hard SLA targets, publish the results, and flag every breach with a named owner and corrective action.

Tamper-Proof Audit Trail

Every action is permanently recorded with user, timestamp, and IP address, and can never be edited or deleted, so investigation decisions stay traceable to a specific analyst, disposition changes are always logged with context, and compliance documentation writes itself.

Built-in SLA targets

< 15 min

S1 Critical

< 60 min

S2 High

< 240 min

S3 Low

Executive dashboards track alerts per day, MTTR, and alert breakdown by runbook.

Seven report types: 24h to 90-day ranges

Analyst Performance

Workload, acknowledgements, SLA & FP counts per analyst

SLA Compliance

Target vs actual response times and breach percentage

Disposition Outcomes

TP / FP breakdown by runbook and analyst

Incident Log

Escalated alerts with references and time-to-escalate

Chain Activity

On-chain activity by event type, network, and top contracts

Runbook Effectiveness

FP rate, MTTR, and volume per detection rule

Full Alert Detail

Complete export for audits and detailed review

Around-the-clock global coverage

Security operations around the world.

No matter where your team or your customers are, someone at CROC is already watching.

Talk to the CROC team