One product. Four fronts. One reflex.

Most antivirus products scan and quarantine. Kalkhan runs AV, EDR, ransomware recovery and CTI web defense at the same time — and the verdict is reached inside the native protection engine.

AV

Native scanning: hash, signature, optional YARA, PE heuristics and behavior scoring. Real-time protection plus quick, deep and custom scans.

EDR / EDX

ETW with process, file and network telemetry, the Event Center, containment and threat labels you can actually read — plain sentences, not memory addresses.

Ransomware

Honeypot decoys, process termination, Shelter (AES-256-GCM), VSS rollback and the Ransomware Recovery Center — one package, no separate license.

Web / Phishing

CTI (cti.kalkhan.com.tr), the SGB fallback feed, a brand-impersonation lexicon, a Chrome extension and automatic access cut-off.

We don’t sell protection as something that “runs quietly in the background”. When a threat goes down, the interface says so — THREAT NEUTRALIZED.

Class positioning

Indicative scores against the built-in and global consumer AV classes. These are not independent lab results.

92

Fake-site blocking

Web protection that cuts access

90

Ransomware protection

Honeypot · VSS · Shelter

95

Kalkhan engine

Native verdict + EDR

94

Local intelligence

CTI · SGB · Turkish-language support

How do you get started?

From download to protection — four steps.

  1. Download the installerGet the setup file for Windows 10 / 11.
  2. Get a licence₺150 / year — the key arrives by e-mail.
  3. ActivateThe native protection engine, real-time layer, ransomware and web/CTI layers switch on.
  4. MonitorRead the status from the protection dashboard, Event Center and Ransomware Recovery Centre.

Product interface

Real screenshots. Click to enlarge.

Protection scenarios

How the product responds when a threat appears — the same chain in a demo and in the field.

Ransomware touches a decoy file

The honeypot fires → native kill → a red THREAT NEUTRALIZED. You think the attack has just begun; Kalkhan has already ended it.

Recovery with VSS / Shelter

Files come back through VSS Rollback, with pre-attack AES-256-GCM copies kept in Shelter. The outcome is visible in the Ransomware Recovery Center.

Phishing URL / impersonated brand

A CTI, SGB or lexicon match cuts access; the extension shows blocked.html or the Phishing window. You clicked — Kalkhan closed the door.

Beacon / early C2 traffic

Periodic suspicious connections are scored, with network and containment hints plus a firewall block. A beacon is never silent — Kalkhan hears it.

How it differs from a typical AV

A class comparison based on product capabilities. It is not an independent lab result or a competitor score.

FeatureBuilt-inWindows Security classGlobal paidConsumer AV classKalkhanFour-front endpoint
Native C++ protection service + decision engineVariesKalkhan engine
Ransomware: honeypot + VSS + Shelter recoveryLimitedMostly higher tiersIn the base package
Event Center / containment (EDR-style)Mostly higher tier / separateIncluded
CTI + automatic phishing cut-offGeneric web filterCTI · SGB · extension
Zero-latency “THREAT NEUTRALIZED” UXYes
TR / EN interface + local supportYes
Annual licenseFreeVaries / high₺150

All trademarks belong to their respective owners. No independent lab score has been published. No security product can promise 100% protection.

Capabilities

The layers included in the base package — based on what the codebase actually does.

  • Real-time protectionThe Kalkhan Protection Service plus the Scanner.dll real-time path; it steps in the moment a threat is written to disk
  • Scan centerQuick, deep and custom (folder, streaming) scans; one click from the tray
  • Multi-layered detectionHash, signature, optional YARA, PE heuristics and behavior scoring
  • Ransomware chainHoneypot, process termination, VSS Rollback, Shelter (AES-256-GCM) and the Ransomware Recovery Center
  • Event Center & containmentProcess, file and network events; manual PID isolation; a zero-latency red alert
  • Network threat huntingBeacon / C2 heuristics, RAT indicators, malicious IP and domain blocking
  • Web & CTISync with cti.kalkhan.com.tr, a local CTI cache, the SGB feed, phishing defense and a Chrome MV3 extension
  • Quarantine · Firewall · WSCManaged quarantine, Windows Firewall rules and Windows Security Center registration
  • System healthDiagnostics, health monitoring, PC Tuner / SystemOptimizer
  • MultilingualTurkish, English and Russian interface — containment hints are localized too
System requirements: Windows 10 / 11 (64-bit) · .NET Framework 4.7.2 · Administrator install · Internet access (CTI / updates; the local CTI cache takes over while offline)

Native speed. Modern interface.

The decision is not made in the UI — it is made in the protection service. Zero-latency notification over a named pipe.

  • Kalkhan Anti-Virus (WPF)Protection dashboard · Event Center · Ransomware Recovery · Firewall
  • KalkhanKorumaServisi (C++)Honeypot · VSS · Shelter · ETW · Network · Containment · WSC
  • Kalkhan Scanner.dll (C++20)Hash · Signature · Heuristics · Realtime · Quarantine
  • Browser + CTISGB protection extension ↔ native host · cti.kalkhan.com.tr

Security commitments

Safe neutralization. Data protection. Transparent control.

  • Safe neutralization: Threat processes are terminated or contained in the native layer, with instant visible feedback for the user.
  • Data protection first: A recovery line built on Shelter (AES-256-GCM) and VSS rollback.
  • Network cut-off: Automatic blocking of malicious domains, IPs and phishing pages.
  • User control: Manual containment, restore or delete from quarantine, Shelter management, language and protection settings.
  • The Kalkhan engine: Detection is never outsourced to a third-party label; the product registers in Windows Security Center.
  • Privacy: Data processing is explained in our KVKK privacy notice.

Support and licensing

Post-purchase steps and help channels.

Frequently asked questions

Your Windows endpoint: malware detection through the native engine, real-time protection, an EDR-style Event Center with containment, the ransomware chain (honeypot, VSS, Shelter, Ransomware Recovery Center), CTI-backed web and phishing blocking, the firewall and quarantine.

Most products scan and quarantine. Kalkhan delivers AV, EDR, ransomware recovery and CTI web defense at once; the verdict is reached in the native engine and the UI shows a zero-latency “THREAT NEUTRALIZED” message. This is a class comparison, not an independent lab result.

The annual license covers real-time protection, scanning, the Event Center, the full ransomware chain (there is no separate anti-ransomware license), CTI/SGB web blocking, the browser extension path, the firewall, quarantine, WSC registration and updates. Device and seat counts are agreed when you order.

The product offers a recovery line through VSS Rollback and Shelter (AES-256-GCM protected copies taken before the attack); status and restore are managed from the Ransomware Recovery Center. No product can guarantee full recovery in every scenario.

Use “Buy a license” and fill in the form. The key is sent to you by e-mail. Support: bilgi@kalkhan.com.tr · +90 850 309 5546

The details are on the refund policy and KVKK pages. Requirements: Windows 10 or 11, an administrator install, and internet access for updates and CTI (the local intelligence cache takes over while offline).

See the threat. Neutralize it. Recover.

₺150 / year · AV + EDR + ransomware + CTI web · License by e-mail

Kalkhan Anti-Virüs₺150 / year · Windows