Threat detection & response
Endpoint detection built on the open SigmaHQ ruleset — the same community detection standard the industry uses — plus live malicious-IP/URL/hash threat intelligence and on-demand antivirus.
- 1,200+ detection rules across execution, persistence, defence-evasion, and network behaviour.
- Live threat intel — known-bad infrastructure and malware hashes, refreshed continuously.
- Response that needs a human — isolate a device or kill a process, behind an approval gate and a tamper-evident audit log.