Understand before you act.
Practical starting points for evaluating endpoint detection and response.
Guides
EDR and existing protection
EDR brings investigation and response context alongside existing endpoint protection. Assess how the agent, policies, and current tools fit your environment.
Prepare your evaluation
List your Windows endpoints, current security tools, responsible operators, and deployment constraints. Use a demo to review the workflows that matter to your team.
Prepare a response workflow
Define who reviews evidence, who can authorize containment, and how the team records a decision. Review these responsibilities before enabling response actions.
Deploy to a pilot group
Choose ten to twenty-five representative Windows endpoints, confirm Sysmon is installed, install the MSI with your license key, and review alerts for a week before enabling response actions.
Read an alert
Start with the technique and the confidence value, open the events behind it, check the device timeline, then search for the same pattern on other devices before you decide.
Glossary
The terms behind endpoint security.
- EDR
- Endpoint detection and response: software on each device that records behavior, raises alerts and lets you respond.
- MDR
- Managed detection and response: a provider's analysts monitor your telemetry and respond for you.
- MITRE ATT&CK
- A public catalogue of attacker tactics and techniques, used to describe and compare detections.
- IOC
- Indicator of compromise: an artifact such as a file hash, address or domain that suggests an intrusion.
- YARA
- A rule language for matching patterns in files and memory.
- Sysmon
- A free Microsoft tool that logs detailed process, network and file activity on Windows.
- AMSI
- The Windows Antimalware Scan Interface, which lets security software inspect scripts before they run.
- Playbook
- A predefined sequence of response steps that starts when a condition is met.
- Tenant
- A separate customer environment inside one platform, with its own data and access rules.
- Lateral movement
- When an attacker moves from one compromised device to others.
Evaluation checklist
Questions worth asking any EDR vendor, including us.
- Which operating systems are supported in production today, and which are only planned?
- What does the agent collect, where does it go, and how long is it kept?
- Can I see the events behind every alert?
- Who can trigger a response action, and how is it approved and recorded?
- How are commands and updates authenticated?
- What happens if the agent loses connectivity?
- How are customer environments kept apart?
- What does it take to deploy to a pilot group?
- Which parts of the product are generally available, and which are beta?
- What evidence can you show me, instead of claims?
Questions worth asking
Which endpoints does Vigilante support?
Windows. Agents for Linux and macOS are not part of the current release. Confirm operating-system versions and requirements during the evaluation.
Does it replace my antivirus?
Vigilante adds behavioral detection, investigation and response alongside existing protection. The right configuration depends on your environment.
Can I manage multiple customers?
Yes. MSPs create customer tenants, switch between them and delegate access for a limited time. Review the access boundaries and workflows for your customer environments with us.
What leaves the endpoint?
Telemetry events go to your backend. Forensic packs and BitLocker keys move only when you ask for them or enable escrow. The security page lists the details.
Does it use AI?
AI-assisted triage is optional and starts in monitor-only mode. When enabled, alert context is sent to the configured model provider.
How is it deployed?
Install the MSI with a license key. Silent installation works with Group Policy and MDM tools.
Is there a public price list?
Pricing is on request. Your proposal reflects your endpoints, operating model, and agreed scope.
How do I start?
Contact Altovar to arrange a demo and discuss your environment. We define the next steps together.
A clearer next move.
See how Vigilante fits your endpoints and your team.