Skip to content
Critical Vulnerability CVE-2026-40493 in SAIL Library: A Deep DiveRead

Detection & Response

Response Actions

Isolate hosts, kill processes and block IPs with approval.

Available as a standalone module · Add to my package
Response ActionsLive
12Open incidents
41,208Events / sec
27Auto-contained
  • Host isolation and process killActive
  • IP and domain blockingActive
  • Approval queue for high-impact actionsActive
  • Full action history and rollbackActive
Illustrative view of the Awiron console

What it does

Analysts and automation request containment actions on endpoints and network devices. High-impact actions wait for approval, and every step is logged and reversible where possible.

Host isolation and process kill

IP and domain blocking

Approval queue for high-impact actions

Full action history and rollback

How it worksin three steps.

  1. Collect

    Events from agents, syslog and connectors are normalised into one schema.

  2. Detect

    SIGMA, YARA and IOC matches run in real time and are correlated into incidents.

  3. Respond

    Contain the threat from the console, with approval for high-impact actions.

Ready to see it on your own data?

A 30-minute walkthrough with an engineer, tailored to your environment.