Detection & Response
Response Actions
Isolate hosts, kill processes and block IPs with approval.
Available as a standalone module · Add to my package12Open incidents
41,208Events / sec
27Auto-contained
- Host isolation and process killActive
- IP and domain blockingActive
- Approval queue for high-impact actionsActive
- Full action history and rollbackActive
What it does
Analysts and automation request containment actions on endpoints and network devices. High-impact actions wait for approval, and every step is logged and reversible where possible.
Host isolation and process kill
IP and domain blocking
Approval queue for high-impact actions
Full action history and rollback
How it worksin three steps.
Collect
Events from agents, syslog and connectors are normalised into one schema.
Detect
SIGMA, YARA and IOC matches run in real time and are correlated into incidents.
Respond
Contain the threat from the console, with approval for high-impact actions.
Works best withthese modules.
See all 30 modules
Endpoint Security
Agents
Signed lightweight agents for Windows, Linux and macOS.
Learn more Threat IntelligenceThreat Intelligence Feeds
IOC feeds matched against every event.
Learn more Automation & AISOC Automation
Visual flows from detection to response.
Learn moreAlso in Detection & Response
Ready to see it on your own data?
A 30-minute walkthrough with an engineer, tailored to your environment.