AV
Native scanning: hash, signature, optional YARA, PE heuristics and behavior scoring. Real-time protection plus quick, deep and custom scans.
Windows 10 / 11 · Native protection engine
Kalkhan brings classic antivirus, real-time EDR, ransomware defense and CTI-backed web protection together on a single Windows endpoint. The native engine kills the threat — and the interface reacts visibly at the same moment. Every ransomware layer is included. ₺150 a year.
Your license key arrives by e-mail once the order is placed. Refunds · Support · Privacy

Most antivirus products scan and quarantine. Kalkhan runs AV, EDR, ransomware recovery and CTI web defense at the same time — and the verdict is reached inside the native protection engine.
Native scanning: hash, signature, optional YARA, PE heuristics and behavior scoring. Real-time protection plus quick, deep and custom scans.
ETW with process, file and network telemetry, the Event Center, containment and threat labels you can actually read — plain sentences, not memory addresses.
Honeypot decoys, process termination, Shelter (AES-256-GCM), VSS rollback and the Ransomware Recovery Center — one package, no separate license.
CTI (cti.kalkhan.com.tr), the SGB fallback feed, a brand-impersonation lexicon, a Chrome extension and automatic access cut-off.
We don’t sell protection as something that “runs quietly in the background”. When a threat goes down, the interface says so — THREAT NEUTRALIZED.
Indicative scores against the built-in and global consumer AV classes. These are not independent lab results.
Web protection that cuts access
Honeypot · VSS · Shelter
Native verdict + EDR
CTI · SGB · Turkish-language support
From download to protection — four steps.
How the product responds when a threat appears — the same chain in a demo and in the field.
The honeypot fires → native kill → a red THREAT NEUTRALIZED. You think the attack has just begun; Kalkhan has already ended it.
Files come back through VSS Rollback, with pre-attack AES-256-GCM copies kept in Shelter. The outcome is visible in the Ransomware Recovery Center.
A CTI, SGB or lexicon match cuts access; the extension shows blocked.html or the Phishing window. You clicked — Kalkhan closed the door.
Periodic suspicious connections are scored, with network and containment hints plus a firewall block. A beacon is never silent — Kalkhan hears it.
A class comparison based on product capabilities. It is not an independent lab result or a competitor score.
| Feature | Built-inWindows Security class | Global paidConsumer AV class | KalkhanFour-front endpoint |
|---|---|---|---|
| Native C++ protection service + decision engine | − | Varies | Kalkhan engine |
| Ransomware: honeypot + VSS + Shelter recovery | Limited | Mostly higher tiers | In the base package |
| Event Center / containment (EDR-style) | − | Mostly higher tier / separate | Included |
| CTI + automatic phishing cut-off | − | Generic web filter | CTI · SGB · extension |
| Zero-latency “THREAT NEUTRALIZED” UX | − | − | Yes |
| TR / EN interface + local support | − | − | Yes |
| Annual license | Free | Varies / high | ₺150 |
All trademarks belong to their respective owners. No independent lab score has been published. No security product can promise 100% protection.
The layers included in the base package — based on what the codebase actually does.
The decision is not made in the UI — it is made in the protection service. Zero-latency notification over a named pipe.
Safe neutralization. Data protection. Transparent control.
Post-purchase steps and help channels.
Your Windows endpoint: malware detection through the native engine, real-time protection, an EDR-style Event Center with containment, the ransomware chain (honeypot, VSS, Shelter, Ransomware Recovery Center), CTI-backed web and phishing blocking, the firewall and quarantine.
Most products scan and quarantine. Kalkhan delivers AV, EDR, ransomware recovery and CTI web defense at once; the verdict is reached in the native engine and the UI shows a zero-latency “THREAT NEUTRALIZED” message. This is a class comparison, not an independent lab result.
The annual license covers real-time protection, scanning, the Event Center, the full ransomware chain (there is no separate anti-ransomware license), CTI/SGB web blocking, the browser extension path, the firewall, quarantine, WSC registration and updates. Device and seat counts are agreed when you order.
The product offers a recovery line through VSS Rollback and Shelter (AES-256-GCM protected copies taken before the attack); status and restore are managed from the Ransomware Recovery Center. No product can guarantee full recovery in every scenario.
Use “Buy a license” and fill in the form. The key is sent to you by e-mail. Support: bilgi@kalkhan.com.tr · +90 850 309 5546
The details are on the refund policy and KVKK pages. Requirements: Windows 10 or 11, an administrator install, and internet access for updates and CTI (the local intelligence cache takes over while offline).
₺150 / year · AV + EDR + ransomware + CTI web · License by e-mail
