Live demonstrations  ·  Operations

What ran on that machine, and what it touched.

An agent on every endpoint recording processes, files, network and DNS — so when something happens you can answer what it did rather than guess, and stop it from the same screen.

ColoCommerce/ColoShield A drawing of the real screen
48
Endpoints
1
Isolated now
2.1 s
Detect to contain
0
Agents offline

WKS-14 — this morning

The chain, not the alert: what started it, what it tried, what was done.
11:42:07
WKS-14
A macro in an Office document started PowerShell
Blocked
11:42:07
WKS-14
PowerShell tried to reach 45.9.148.x
Blocked
11:42:09
WKS-14
Machine isolated from the network
Automatic
09:16:44
SRV-DB1
New service installed outside a maintenance window
Flagged
08:03:12
WKS-07
USB storage device connected
Allowed
07:58:20
WKS-03
Somebody signed in from a country you do not trade in
Blocked
06:31:05
SRV-FILE
Scheduled task created at 3am by a local account
Flagged
Yesterday
WKS-11
Agent updated itself to 1.8.0
Routine
Drawn, not run: the real screen needs your data and a login. The shape, the styling and the figures are all the real thing's.

The timeline, not the alert

An alert says something happened. The timeline says what started it, what it wrote, and where it called.

Respond from here

Isolate the machine, kill the process, block the address. The agent does it whether or not anybody can reach the desk.

Windows and Linux alike

One console, the same detections, proven by a test suite rather than asserted in a brochure.

Next: Dashboard & themes

Every module feeds one screen. Twenty ways to look at it.