Endpoint security, connected
Every signal.Under control.
Connect endpoint activity, investigate suspicious behavior, and coordinate a response your team controls.
For IT teams and MSPs. Built around Windows endpoints.
- Windows endpoints
- Your team
- Signed command
What is in the box.
- 12Behavior-correlation rules
Lateral movement, credential dumping, command-and-control, ransomware patterns and more.
- 7Identity-attack detectors
Kerberoasting, golden and silver tickets, password spray, DCSync, DCShadow and AS-REP roasting.
- 6Console languages
English, Italian, Spanish, French, German and Portuguese.
- Ed25519Signature on every command
Each response command is signed, time-limited and bound to one device and one tenant.
Protection starts with understanding.
- 01
Detect behavior
Review activity on Windows endpoints with behavioral signals, file monitoring, and detection rules.
- 02
Connect evidence
Event correlation and MITRE ATT&CK context help you relate individual observations to attack techniques.
- 03
Control the response
Role-based permissions, playbooks, and signed commands support controlled containment on managed endpoints.
Detect. Investigate. Respond. Manage.
Everything an endpoint team needs, in one console.
-
Detect
Behavioral monitoring of processes, scripts, files, network and DNS on Windows endpoints.
Learn more -
Investigate
Correlated alerts, incident timelines and threat hunting, tagged with MITRE ATT&CK.
Learn more -
Respond
Isolate, terminate and quarantine through signed, policy-gated commands.
Learn more -
Identity attacks
Detectors for Kerberos abuse, password spraying and directory replication attacks.
Learn more -
Endpoint control
USB, application, script and DNS policies enforced by the agent.
Learn more -
Manage
Roles, customer tenants, an audit log and SIEM export for IT teams and MSPs.
Learn more
From endpoint to decision.
Every step is visible, signed or logged.
- 01
Observe
The Windows agent watches processes, scripts, files, network and DNS activity.
- 02
Correlate
The backend links events into attack patterns and tags them with MITRE ATT&CK techniques.
- 03
Decide
Confidence thresholds and autonomy levels decide what may run automatically and what waits for a person.
- 04
Act
Approved actions return to the agent as signed commands, and each one is written to the audit log.
Trust is built in.
Controls you can read about, check and export.
Security and trust-
Signed commands and updates
Ed25519 signatures, short validity and replay protection.
-
Tenant isolation
API queries are filtered by the tenant in the signed-in identity.
-
Tamper-evident audit log
An HMAC-chained record you can verify and export.
-
Least privilege
Fine-grained roles and one-time-password step-up on sensitive actions.
A clearer next move.
See how Vigilante fits your endpoints and your team.