Skip to content
Client Focus

Client Focus solution

C'ROC security operations center

C'ROC is the Client Focus blockchain security operations center. It monitors Ethereum, Solana, BNB Chain, Avalanche, Polygon, Arbitrum, Optimism, Base and Sonic (formerly Fantom) continuously, validates every alert with a trained analyst, and notifies named client contacts on a published clock.

Nine public blockchains, including Ethereum, Solana and Base

Every alert confirmed by a Watch Officer before it reaches the client

Within 10 minutes of detection for critical events, under the client's service agreement

From chain data to a named person

Settlement on a public blockchain is final, so C'ROC is built around the interval between an event and a decision. Detection is automated; the decision to notify rests with a Watch Officer.

C'ROC operating flowFive steps from left to right: chain data from nodes and RPC providers, detection by Chain Monitor, enrichment with history and exposure, validation by a Watch Officer, and notification to named client contacts. Every step is recorded in an evidence store with hop-by-hop timestamps.Chain dataNodes and RPCChain MonitorDetection engineEnrichmentHistory, exposureWatch OfficerValidates alertsNotificationNamed contactsEvidence storeDetection, validation, notification and escalation, timestamped hop by hop with named owners

Monitoring rights, never custody

Client Focus does not take custody of client assets and does not hold client signing keys. It operates with monitoring and alerting rights and, where contracted, proposes actions that the client's authorized approvers execute.

Delivered into the client's stack

Integrations are available to client SIEM, ticketing and paging tools, including Splunk, Microsoft Sentinel, ServiceNow and PagerDuty, so alerts arrive where the client's teams already work.

Validation

No alert reaches a client without a Watch Officer confirming it.

What Chain Monitor looks for

Chain Monitor is the C'ROC detection engine. Detection runs continuously across the monitored networks and is tuned to client policy.

  • CAT-01

    Exploit-related fund movement

    Outflows matching known exploit signatures and abnormal contract drains.

  • CAT-02

    Laundering and mixer interactions

    Exposure to mixers, chain hopping and structured layering patterns.

  • CAT-03

    Sanctions and high-risk venue exposure

    Counterparties on sanctions lists and deposits to high-risk exchanges.

  • CAT-04

    Rug pulls and scam patterns

    Liquidity removal, privileged mint activity and honeypot behavior.

  • CAT-05

    Suspicious wallet behavior

    Dormant wallet reactivation, approval abuse and anomalous transaction velocity.

C'ROC Threat Intelligence Map showing an S1 critical alert, the related wallets and contracts, and runbook guidance

How Chain Monitor works

Chain Monitor is operated as a controlled service rather than a set of standing alerts.

Step 1

Data ingestion

Chain data is ingested from full nodes operated by Client Focus and from RPC providers across the monitored networks.

Step 2

Versioned policy

Detection rules are expressed as versioned, change-controlled policy per client, so every change to what is watched has an author, a date and an approver.

Step 3

Behavioral baselines

Baselines are held per wallet, contract and counterparty, so deviation from established activity is measurable rather than assumed.

Step 4

Alert enrichment

Each alert is enriched with address history, counterparty context, sanctions and high-risk venue exposure before an officer reviews it.

Step 5

Validation queue

Enriched alerts enter a Watch Officer validation queue. No alert reaches a client without an officer confirming it.

Step 6

Evidence store

Detection, validation, notification and escalation are recorded with hop-by-hop timestamps and named owners.

Four layers before a decision

The engine that classifies each event is operated by Client Focus inside an agreed boundary. Every event passes four layers of analysis before an officer determines what it is.

  1. Layer 1

    Blockchain data

    Live transaction data checked against security rules and client-specific operational policy.

  2. Layer 2

    Behavioral analysis

    Baselines of normal activity per wallet, contract and counterparty, so deviation is measurable.

  3. Layer 3

    Risk intelligence

    Known-bad addresses, mixers, sanctioned entities and high-risk exchange exposure.

  4. Layer 4

    Rule-based detection

    Privileged actions such as role grants and configuration flag changes, plus threshold and timing rules.

The engine is hosted within Client Focus infrastructure or the client's designated environment, and no client data leaves the agreed boundary. It uses open-weight models fine-tuned on labeled exploit patterns, malware corpora, identity attack signatures and MITRE ATT&CK techniques, with alert classification at sub-second latency under production load.

When an event involves a smart contract, the engine reads the contract code in the evidence map it builds for that event and evaluates it against known vulnerability and exploit patterns, across EVM chains and non-EVM networks including Solana. The same detection lineage powers pre-deployment contract analysis in Smart Contract Guard 360.

Each detection is paired with a generated standard operating procedure for analyst response, escalation and client notification. Model lineage is versioned and available for technical review under non-disclosure agreement.

Three tiers, one published clock

Severity decides the notification path. The clock starts at detection and every hop is timestamped.

S1 Critical

Activity that is new, unfamiliar or unexplained, and privileged actions such as role grants or configuration flag changes.

Notification within 10 minutes of detection. Escalation continues up the chain if client acknowledgment does not follow within 15 minutes (targets stated in the client's service agreement).

S2 High

Known event types occurring outside the established daily pattern, or at unusual volume or timing.

Notified within the published service window and tracked to closure.

S3 Informational

Routine expected operational activity, recognized wallets, and standard issuance and transfer flows.

Logged and summarized in the daily report.

Detection and notification timelineA single line with five points: detection at T0, validation at T plus five minutes, notification at T plus ten minutes, client acknowledgment at T plus fifteen minutes, and escalation from L1 to L4 with each hop timestamped.T0Detection

Automated analysis raises an event

T+5Validation

Watch Officer confirms and assigns severity

T+10Notification

Client contacts notified on the published clock

T+15Acknowledgment

Named client contact confirms receipt

ThenEscalation

L1 to L4, each hop timestamped

Named accountability from L1 to L4

Each level has a defined responsibility and a named individual on duty, recorded with hop-by-hop timestamps.

L1

Watch Officer

Monitors the queue, validates alerts and discards false positives.

L2

Senior analyst

Investigates confirmed indicators, traces flows and opens the incident.

L3

Incident manager

Owns containment, client communication and the response timeline.

L4

Operations lead

Holds named accountability, regulator-facing reporting and post-incident review.

Escalation ladderFour escalation steps: L1 Watch Officer, L2 Shift Lead, L3 Operations Manager, L4 Director. Each step has a named owner.L1Watch Officer

Validates, classifies and notifies

L2Shift Lead

Coordinates response across the watch

L3Operations Manager

Owns the incident and client updates

L4Director

Accountable for outcome and review

Continuous on-chain security operations for a Tier-1 global bank

Client Focus operates the public blockchain security operations function for a Tier-1 global bank. The engagement covers multi-chain coverage across Layer 1 and Layer 2 networks including Ethereum and Base, continuous transaction monitoring, smart contract runtime security and invariant alerting, custody and treasury wallet surveillance, sanctions screening and Travel Rule integration, bridge and cross-chain monitoring, and regulatory reporting feeds with forensic case support. Alerts are delivered into the bank's existing security stack under banking service levels, 24/7/365.

Client identity is withheld under confidentiality. References are available under non-disclosure agreement.

Illustrative values, not contractual
S1Critical: new, unexplained or privileged actionNotification within 10 minutes of detection, escalation continues without acknowledgment within 15 minutes24/7/365
S2High: known event outside the daily patternPublished service window24/7/365
S3Informational: routine expected activityDaily report24/7/365 monitoring
IRIncident response engagement1 hour to incident manager24/7/365

Illustrative values shown. Final severity definitions and response targets are agreed for each engagement.

Part of the Secure practice

C'ROC is delivered through the Client Focus Secure practice, alongside security assessments, incident response and Smart Contract Guard 360 for contract assurance before deployment.

Continue reading

Secure

Security across the lifecycle: assessments, contract assurance, security operations and incident response.

Smart Contract Guard 360

Automated contract analysis and continuous compliance monitoring inside the client environment.

Support

Instructions for existing clients reporting an active incident, with direct phone and email channels.

Put your assets under watch.

Discuss continuous security operations for your on-chain activity with the team that runs the C'ROC. Every request is reviewed by a principal of the firm.