Detect, investigate, respond, manage.
Vigilante turns Windows endpoint activity into correlated alerts and gives your team signed, policy-gated ways to act.
Detect
Windows endpoint telemetry, turned into behavioral signals.
Illustrative scenario
A script reaches out
- 01A script starts on a workstation.
- 02Moments later it opens an outbound connection to a rarely seen address.
- 03One correlated alert is raised, with both events attached.
Process, network and file activity
Process starts, network connections, image loads, file and registry changes and DNS queries, read from Sysmon events.
Script inspection
Scripts are checked through the Windows AMSI interface.
Signed YARA rules
File-scanning rules arrive as an Ed25519-signed manifest and reload automatically.
DNS analysis
Entropy and tunnelling heuristics flag generated domains and DNS tunnelling.
Honeypots and integrity monitoring
Canary files, and watchers on the hosts file, boot configuration, Run keys and services.
Identity-attack detectors
Seven detectors cover Kerberoasting, golden and silver tickets, password spray, DCSync, DCShadow and AS-REP roasting.
Good to knowTelemetry comes from Sysmon, which must already be installed on the endpoint. The agent does not install it.
Investigate
One alert, the whole story.
Illustrative scenario
From alert to story
- 01An alert arrives with its ATT&CK technique and a confidence value.
- 02Open the incident timeline to see the events behind it.
- 03Check the device timeline and hunt for the same pattern on other devices.
Behavior correlation
Twelve rules link events per device and per tenant: lateral movement, credential dumping, command-and-control beaconing, ransomware patterns, persistence chains and more.
MITRE ATT&CK tagging
Detections carry ATT&CK technique identifiers, and a coverage view shows the techniques actually observed over the last 90 days.
Cases and timelines
Group alerts into cases, follow an incident timeline and an attack-story view, and review a timeline for each device.
Threat hunting
Search telemetry with saved queries and run retro-hunts over stored history.
Forensic triage
On operator command, collect a signed triage pack: registry, event logs, prefetch, browser artifacts and more.
Vulnerability context
EPSS and CISA KEV data are synchronized every six hours to help you prioritize.
Good to knowAutomatic matching against imported threat-intelligence feeds is not part of the current release.
Respond
Act quickly and stay in command.
Illustrative scenario
Containing a suspected intrusion
- 01A ransomware-pattern alert is raised.
- 02Policy decides whether the action may run or needs approval.
- 03A signed isolate command goes to the agent, and the action is written to the audit log.
Isolate a host
Cut a compromised endpoint off the network, and release it when it is clean.
Terminate and quarantine
Stop a malicious process and quarantine a file, encrypted with AES-256-GCM.
Block addresses and USB
Block a network address or a removable device.
Collect evidence
Forensic collection on demand, and escrow of BitLocker recovery keys.
Signed, time-limited commands
Each command is Ed25519-signed, valid for ten minutes, replay-protected and bound to one device and one tenant. An agent without the public key refuses to act.
Policy gates
Confidence thresholds and autonomy levels decide what may run automatically and what waits for approval.
Panic button
A tenant-wide emergency action protected by one-time-password step-up.
Good to knowA live remote shell is not part of the current release.
Manage
Built for the people who run it.
Illustrative scenario
Onboarding a customer
- 01Create a tenant for the customer.
- 02Install the MSI with their license key.
- 03Give colleagues access for a limited time.
Desktop console
A Windows console with threat lists, cases, hunting, device views, policies and reports, in six languages.
Roles and step-up
Owner, admin, analyst, viewer and auditor roles, with one-time-password step-up on sensitive actions.
Customer tenants
MSPs create, suspend and switch between customer tenants, and delegate access for a limited time.
Tamper-evident audit log
Every sensitive action is written to an HMAC-chained log that can be verified and exported with a signature.
SIEM export
Forward events in CEF, LEEF or JSON over syslog.
Simple deployment
Install with a standard MSI and a license key. Silent installation works with Group Policy and MDM tools.
Good to knowWebhook delivery and chat alert channels are not available yet.
How the pieces fit.
A Windows agent, a set of backend services, and a console that reads from the API.
- 01
Windows agent
A service that watches the endpoint and carries out verified commands.
- 02
Ingest
Receives telemetry over HTTPS with a per-device token.
- 03
Correlation
Applies twelve rules per device and tenant, and tags techniques.
- 04
Policy gate
Applies confidence thresholds and autonomy levels.
- 05
Signed command
Returns to the agent, which verifies it before acting.
Requirements and deployment.
- Endpoints
- Windows. Agents for Linux and macOS are not part of the current release.
- Telemetry source
- Sysmon, installed on each endpoint.
- Installation
- A standard MSI and a license key. Silent installation works with Group Policy and MDM tools.
- Updates
- The agent checks for updates every four hours and verifies their signature before installing.
- Connectivity
- Outbound access from endpoints to the Vigilante backend.
- Backend
- Containerized services, deployed with Docker Compose or Helm.
A clearer next move.
See how Vigilante fits your endpoints and your team.