What is inside
Behavioral baselines
Behavioral baselines per host and process detect deviations from the normal state.
5-layer process trust
Assessment via name/LOLBAS, digital signature, signer, hash baseline and path. Four action levels: ALLOW / WATCH / KILL / CONTAIN.
LOLBin detection
Coverage of 232 LOLBAS binaries, 8 parent-child rules and 21 CLI attack patterns.
Forensics
8 forensic artifact types are available for in-depth analysis.
Response in milliseconds
- On-endpoint kill: below 100 ms (target value).
- Host quarantine: below 5 seconds (target value).
- Forensic capture: below 60 seconds (target value).
- Fleet scan: below 5 minutes across the entire fleet (target value).