Vigilante / Platform

Detect, investigate, respond, manage.

Vigilante turns Windows endpoint activity into correlated alerts and gives your team signed, policy-gated ways to act.

Detect

Windows endpoint telemetry, turned into behavioral signals.

Illustrative scenario

A script reaches out

  1. 01A script starts on a workstation.
  2. 02Moments later it opens an outbound connection to a rarely seen address.
  3. 03One correlated alert is raised, with both events attached.
  • Process, network and file activity

    Process starts, network connections, image loads, file and registry changes and DNS queries, read from Sysmon events.

  • Script inspection

    Scripts are checked through the Windows AMSI interface.

  • Signed YARA rules

    File-scanning rules arrive as an Ed25519-signed manifest and reload automatically.

  • DNS analysis

    Entropy and tunnelling heuristics flag generated domains and DNS tunnelling.

  • Honeypots and integrity monitoring

    Canary files, and watchers on the hosts file, boot configuration, Run keys and services.

  • Identity-attack detectors

    Seven detectors cover Kerberoasting, golden and silver tickets, password spray, DCSync, DCShadow and AS-REP roasting.

Good to knowTelemetry comes from Sysmon, which must already be installed on the endpoint. The agent does not install it.

Investigate

One alert, the whole story.

Illustrative scenario

From alert to story

  1. 01An alert arrives with its ATT&CK technique and a confidence value.
  2. 02Open the incident timeline to see the events behind it.
  3. 03Check the device timeline and hunt for the same pattern on other devices.
  • Behavior correlation

    Twelve rules link events per device and per tenant: lateral movement, credential dumping, command-and-control beaconing, ransomware patterns, persistence chains and more.

  • MITRE ATT&CK tagging

    Detections carry ATT&CK technique identifiers, and a coverage view shows the techniques actually observed over the last 90 days.

  • Cases and timelines

    Group alerts into cases, follow an incident timeline and an attack-story view, and review a timeline for each device.

  • Threat hunting

    Search telemetry with saved queries and run retro-hunts over stored history.

  • Forensic triage

    On operator command, collect a signed triage pack: registry, event logs, prefetch, browser artifacts and more.

  • Vulnerability context

    EPSS and CISA KEV data are synchronized every six hours to help you prioritize.

Good to knowAutomatic matching against imported threat-intelligence feeds is not part of the current release.

Respond

Act quickly and stay in command.

Illustrative scenario

Containing a suspected intrusion

  1. 01A ransomware-pattern alert is raised.
  2. 02Policy decides whether the action may run or needs approval.
  3. 03A signed isolate command goes to the agent, and the action is written to the audit log.
  • Isolate a host

    Cut a compromised endpoint off the network, and release it when it is clean.

  • Terminate and quarantine

    Stop a malicious process and quarantine a file, encrypted with AES-256-GCM.

  • Block addresses and USB

    Block a network address or a removable device.

  • Collect evidence

    Forensic collection on demand, and escrow of BitLocker recovery keys.

  • Signed, time-limited commands

    Each command is Ed25519-signed, valid for ten minutes, replay-protected and bound to one device and one tenant. An agent without the public key refuses to act.

  • Policy gates

    Confidence thresholds and autonomy levels decide what may run automatically and what waits for approval.

  • Panic button

    A tenant-wide emergency action protected by one-time-password step-up.

Good to knowA live remote shell is not part of the current release.

Manage

Built for the people who run it.

Illustrative scenario

Onboarding a customer

  1. 01Create a tenant for the customer.
  2. 02Install the MSI with their license key.
  3. 03Give colleagues access for a limited time.
  • Desktop console

    A Windows console with threat lists, cases, hunting, device views, policies and reports, in six languages.

  • Roles and step-up

    Owner, admin, analyst, viewer and auditor roles, with one-time-password step-up on sensitive actions.

  • Customer tenants

    MSPs create, suspend and switch between customer tenants, and delegate access for a limited time.

  • Tamper-evident audit log

    Every sensitive action is written to an HMAC-chained log that can be verified and exported with a signature.

  • SIEM export

    Forward events in CEF, LEEF or JSON over syslog.

  • Simple deployment

    Install with a standard MSI and a license key. Silent installation works with Group Policy and MDM tools.

Good to knowWebhook delivery and chat alert channels are not available yet.

How the pieces fit.

A Windows agent, a set of backend services, and a console that reads from the API.

  1. 01

    Windows agent

    A service that watches the endpoint and carries out verified commands.

  2. 02

    Ingest

    Receives telemetry over HTTPS with a per-device token.

  3. 03

    Correlation

    Applies twelve rules per device and tenant, and tags techniques.

  4. 04

    Policy gate

    Applies confidence thresholds and autonomy levels.

  5. 05

    Signed command

    Returns to the agent, which verifies it before acting.

Requirements and deployment.

Endpoints
Windows. Agents for Linux and macOS are not part of the current release.
Telemetry source
Sysmon, installed on each endpoint.
Installation
A standard MSI and a license key. Silent installation works with Group Policy and MDM tools.
Updates
The agent checks for updates every four hours and verifies their signature before installing.
Connectivity
Outbound access from endpoints to the Vigilante backend.
Backend
Containerized services, deployed with Docker Compose or Helm.

A clearer next move.

See how Vigilante fits your endpoints and your team.

Book a demo