Skip to Content

Capability

Host-based Detection (EDR/HIDS)

Behavioral analysis, process trust scoring and forensics directly at the endpoint.

Attacks end up on a host. ZephSense knows the normal state of every host and process and detects deviations immediately. Response happens within milliseconds directly at the endpoint.

What is inside

Behavioral baselines

Behavioral baselines per host and process detect deviations from the normal state.

5-layer process trust

Assessment via name/LOLBAS, digital signature, signer, hash baseline and path. Four action levels: ALLOW / WATCH / KILL / CONTAIN.

LOLBin detection

Coverage of 232 LOLBAS binaries, 8 parent-child rules and 21 CLI attack patterns.

Forensics

8 forensic artifact types are available for in-depth analysis.

Response in milliseconds

  • On-endpoint kill: below 100 ms (target value).
  • Host quarantine: below 5 seconds (target value).
  • Forensic capture: below 60 seconds (target value).
  • Fleet scan: below 5 minutes across the entire fleet (target value).
Response in milliseconds