CloudCastle Advanced EDR

See the behavior. Review the evidence.

Code-verified: behavior analysis and policy-gated response mechanisms. Unmeasured: installed-artifact detection, safe containment and recovery outcomes. No prevention guarantee or OS parity is claimed.

macOS Beta: Developer ID signing, notarization and Gatekeeper acceptance are not verified for a customer artifact. Physical Intel, Apple Silicon and Rosetta capability checks and user-approved permissions remain required. Launch approval is pending. Capability disclosures.

Behavior-first protection

The short version

What Advanced EDR does for you

The following describes implementation mechanisms, not measured customer protection. Observe-only/dry-run evaluation does not prove enforcement works.

Code-verified

Collects activity signals

Platform-specific sensors provide available process, file and network evidence. Signal coverage depends on the active sensor and permissions.

Code-verified

Checks more than a name

Rules, behavior and threat-intelligence mechanisms contribute detection evidence; real-world efficacy is unmeasured.

Code-verified

Gates response actions

Process stop, quarantine and isolation paths have policy and safety checks. Safe containment and complete action reporting still require field proof.

Endpoint trust and recovery

Trust starts before detection. Evidence controls every step.

Each layer reports what is active, what still needs proof and what remains in the lab. AI can rank evidence, but it cannot skip policy or turn a missing signal into a clean result.

  1. Planned — not available

    Hardware trust

    TPM identity, Secure Boot state and Linux MOK enrollment are planned attestation inputs. The production backend does not yet collect or verify this evidence, so no hardware-attestation result is available today.

  2. Planned — not available

    Signed boot

    Binding boot and agent trust to signed artifacts remains planned. Missing TPM, disabled Secure Boot and untrusted MOK are not yet reported as production findings.

  3. Code-verified

    Native sensors

    Native collection paths report active tiers and lower-privilege fallbacks. Installed-artifact coverage is unmeasured.

  4. Code-verified

    Deterministic detection

    Sigma, YARA-X, IOC, process ancestry, canary and tamper mechanisms produce evidence. This is not a measured detection-rate claim.

  5. Code-verified

    Gated response

    Allowlist, kill-switch, dry-run and authorization mechanisms precede containment. Field safety and outcome reporting remain unmeasured.

  6. Unmeasured

    Recovery readiness

    Recovery contracts exist in source, but signed recovery has no complete target-OS field proof and is not offered as automatic recovery.

Planned

Managed-host prototype

A managed-host recovery prototype is not a customer capability. Host, artifact and restore evidence must pass rollout gates before availability.

Planned

Isolated DMA research

DMA research is separate from endpoint protection and is not offered as an installed customer capability.

Native operating-system security

Use the telemetry the OS already knows best

One portable detection core sits above native collection paths. If a privileged sensor is unavailable, the agent degrades visibly rather than pretending coverage exists.

Windows

ETW and Security Center awareness

Code-verified: ETW process collection and public Windows Security Center product-list reads.

Unmeasured: exact Windows artifact compatibility and field coverage.

Planned: general real-time file, registry, network and DNS sensor coverage is not claimed for the current Defender wiring. Native product registration and a production Windows driver are not launch capabilities.

Coexistence policy prohibits directly disabling Microsoft Defender or Tamper Protection. This policy is not a measured coexistence outcome. Windows enforcement is excluded pending sustained installed-artifact enforcement and recovery proof.

macOS Beta

Endpoint Security Framework

Code-verified: Endpoint Security process-execution notification and lower-privilege libproc collection paths report their active tier.

Unmeasured: physical Intel, Apple Silicon and Rosetta behavior. Entitlements, root access and TCC permissions constrain telemetry; polling can miss short-lived processes.

macOS file/network/DNS sensing and native ransomware/tamper coverage are not available launch capabilities; memory reads return unsupported. Automatic process response is disabled for launch. No verified Developer ID/notarized artifact or clean-host Gatekeeper acceptance is claimed; users must approve required permissions.

Linux

eBPF, tracepoints and LSM

Code-verified: process-exec eBPF tracepoint, supported BPF-LSM hooks and TCP-connect fallback paths; bounded memory readers use /proc/<pid>/maps and /proc/<pid>/mem.

Unmeasured: installed-artifact coverage across kernels and distributions. Missing kernel features and permissions reduce coverage.

Degraded-state reporting is a code mechanism, not evidence of uninterrupted operation on every host.

Code-verified mechanisms

Signals for different failure modes

These are source-level mechanisms, not measured field coverage. Platform support, privileges and active sensors limit the evidence available.

Code-verified

Sigma behavior rules

Sigma rules map normalized events to ATT&CK-tagged techniques. Offline checks compare rule fields with sensor contracts; this does not prove field detection.

Code-verified

YARA-X content inspection

YARA packs inspect available file evidence and expose load failures. Content coverage depends on the rules, files and scanner available.

Code-verified

Canaries and burst behavior

Canary trips and burst thresholds can produce ransomware-labelled alerts. Neither a label nor a canary trip proves prevention or recovery.

Threat intel

Live IOC matching

Hash, IP, domain and path indicators can be loaded or hot-swapped without restarting the agent. Matches are indexed for constant-time lookup and recorded as explicit evidence.

Code-verified

On-demand process scanning

Windows and Linux have bounded memory-reader mechanisms, subject to permissions and configuration. macOS memory reads return unsupported. Installed-artifact scan efficacy is unmeasured.

Provenance

Process-tree context

Bounded ancestry links the suspicious child to the shell, document reader, installer or parent process that launched it, preserving the path from initial execution to detection.

Tamper

Agent self-protection

Protected agent paths and allowed process IDs make modification attempts visible. The same bounded telemetry store exposes recent tamper activity to the management plane.

Vulnerabilities

CISA KEV and NVD

Normalized CISA Known Exploited Vulnerabilities and NVD data is matched against installed-package inventory, separating actively exploited exposure from ordinary backlog.

Removable media

USB awareness

Attach detection adds removable-device context to the endpoint record, helping technicians investigate the physical path behind a suspicious file or process.

AI with boundaries

Advisory ranking with bounded authority

CloudCastle separates evidence, ranking and enforcement so a model failure cannot silently become an endpoint action.

  • Stable features: the same named signals feed the local advisory scorer and the out-of-process model boundary, preventing training and runtime extraction from drifting apart.
  • Post-decision scoring: risk is computed after the response dispatcher returns; the dispatcher has no score parameter and cannot read it.
  • AI technician escalation: high-confidence incidents can be summarized and planned in the control plane, while every proposed playbook still passes an allowlisted deterministic gate.
  • Human-readable evidence: rule, ancestry, IOC, canary, action and outcome remain available even when AI services are unavailable.
A clear record of endpoint detections, decisions and response actions

Response safety

Automated response should be hard to misuse

The same gate order applies to every endpoint action, including actions triggered through a partner or management workflow.

Unchecked automation

  • A confidence score becomes permission
  • One false positive kills a trusted process
  • No global stop control
  • An alert says what was detected, not what changed

CloudCastle response path

  • Trusted path or hash allowlists short-circuit first
  • A local kill-switch stops all enforcement
  • Dry-run remains the safe default until policy enables action
  • Kill, containment and quarantine outcomes are written to telemetry

Discuss an evidence-bound endpoint evaluation

Define the exact artifact, OS, consent, observe-only policy and rollback requirements before deployment. Expansion requires field acceptance, not just a working control plane.

Simple pricing: a monthly minimum plus per endpoint — see pricing.