Collects activity signals
Platform-specific sensors provide available process, file and network evidence. Signal coverage depends on the active sensor and permissions.
CloudCastle Advanced EDR
Code-verified: behavior analysis and policy-gated response mechanisms. Unmeasured: installed-artifact detection, safe containment and recovery outcomes. No prevention guarantee or OS parity is claimed.
macOS Beta: Developer ID signing, notarization and Gatekeeper acceptance are not verified for a customer artifact. Physical Intel, Apple Silicon and Rosetta capability checks and user-approved permissions remain required. Launch approval is pending. Capability disclosures.
Behavior-first protection
The short version
The following describes implementation mechanisms, not measured customer protection. Observe-only/dry-run evaluation does not prove enforcement works.
Platform-specific sensors provide available process, file and network evidence. Signal coverage depends on the active sensor and permissions.
Rules, behavior and threat-intelligence mechanisms contribute detection evidence; real-world efficacy is unmeasured.
Process stop, quarantine and isolation paths have policy and safety checks. Safe containment and complete action reporting still require field proof.
Endpoint trust and recovery
Each layer reports what is active, what still needs proof and what remains in the lab. AI can rank evidence, but it cannot skip policy or turn a missing signal into a clean result.
TPM identity, Secure Boot state and Linux MOK enrollment are planned attestation inputs. The production backend does not yet collect or verify this evidence, so no hardware-attestation result is available today.
Binding boot and agent trust to signed artifacts remains planned. Missing TPM, disabled Secure Boot and untrusted MOK are not yet reported as production findings.
Native collection paths report active tiers and lower-privilege fallbacks. Installed-artifact coverage is unmeasured.
Sigma, YARA-X, IOC, process ancestry, canary and tamper mechanisms produce evidence. This is not a measured detection-rate claim.
Allowlist, kill-switch, dry-run and authorization mechanisms precede containment. Field safety and outcome reporting remain unmeasured.
Recovery contracts exist in source, but signed recovery has no complete target-OS field proof and is not offered as automatic recovery.
A managed-host recovery prototype is not a customer capability. Host, artifact and restore evidence must pass rollout gates before availability.
DMA research is separate from endpoint protection and is not offered as an installed customer capability.
Native operating-system security
One portable detection core sits above native collection paths. If a privileged sensor is unavailable, the agent degrades visibly rather than pretending coverage exists.
Code-verified: ETW process collection and public Windows Security Center product-list reads.
Unmeasured: exact Windows artifact compatibility and field coverage.
Planned: general real-time file, registry, network and DNS sensor coverage is not claimed for the current Defender wiring. Native product registration and a production Windows driver are not launch capabilities.
Coexistence policy prohibits directly disabling Microsoft Defender or Tamper Protection. This policy is not a measured coexistence outcome. Windows enforcement is excluded pending sustained installed-artifact enforcement and recovery proof.
Code-verified: Endpoint Security process-execution notification and lower-privilege libproc collection paths report their active tier.
Unmeasured: physical Intel, Apple Silicon and Rosetta behavior. Entitlements, root access and TCC permissions constrain telemetry; polling can miss short-lived processes.
macOS file/network/DNS sensing and native ransomware/tamper coverage are not available launch capabilities; memory reads return unsupported. Automatic process response is disabled for launch. No verified Developer ID/notarized artifact or clean-host Gatekeeper acceptance is claimed; users must approve required permissions.
Code-verified: process-exec eBPF tracepoint, supported BPF-LSM hooks and TCP-connect fallback paths; bounded memory readers use /proc/<pid>/maps and /proc/<pid>/mem.
Unmeasured: installed-artifact coverage across kernels and distributions. Missing kernel features and permissions reduce coverage.
Degraded-state reporting is a code mechanism, not evidence of uninterrupted operation on every host.
Code-verified mechanisms
These are source-level mechanisms, not measured field coverage. Platform support, privileges and active sensors limit the evidence available.
Sigma rules map normalized events to ATT&CK-tagged techniques. Offline checks compare rule fields with sensor contracts; this does not prove field detection.
YARA packs inspect available file evidence and expose load failures. Content coverage depends on the rules, files and scanner available.
Canary trips and burst thresholds can produce ransomware-labelled alerts. Neither a label nor a canary trip proves prevention or recovery.
Hash, IP, domain and path indicators can be loaded or hot-swapped without restarting the agent. Matches are indexed for constant-time lookup and recorded as explicit evidence.
Windows and Linux have bounded memory-reader mechanisms, subject to permissions and configuration. macOS memory reads return unsupported. Installed-artifact scan efficacy is unmeasured.
Bounded ancestry links the suspicious child to the shell, document reader, installer or parent process that launched it, preserving the path from initial execution to detection.
Protected agent paths and allowed process IDs make modification attempts visible. The same bounded telemetry store exposes recent tamper activity to the management plane.
Normalized CISA Known Exploited Vulnerabilities and NVD data is matched against installed-package inventory, separating actively exploited exposure from ordinary backlog.
Attach detection adds removable-device context to the endpoint record, helping technicians investigate the physical path behind a suspicious file or process.
AI with boundaries
CloudCastle separates evidence, ranking and enforcement so a model failure cannot silently become an endpoint action.
Response safety
The same gate order applies to every endpoint action, including actions triggered through a partner or management workflow.
Define the exact artifact, OS, consent, observe-only policy and rollback requirements before deployment. Expansion requires field acceptance, not just a working control plane.
Simple pricing: a monthly minimum plus per endpoint — see pricing.