CloudCastle Advanced EDR

See the behavior. Stop the attack.

CloudCastle watches what programs do, not just what they are called. When behavior looks dangerous, it gathers the evidence and can safely stop or isolate the threat under rules you control.

Behavior-first protection

The short version

What Advanced EDR does for you

It watches each computer, recognizes attack behavior and responds without handing unlimited control to AI.

Watch

Sees suspicious activity

CloudCastle follows programs, files, network connections and sign-in activity so it can spot an attack while it is happening.

Decide

Checks more than a name

It combines trusted security rules with behavior and threat intelligence, helping it catch both known malware and new attacks.

Respond

Stops damage safely

Approved policies can stop a malicious process, quarantine a file or isolate a computer. Every action is recorded and protected by safety controls.

Endpoint trust and recovery

Trust starts before detection. Evidence controls every step.

Each layer reports what is active, what still needs proof and what remains in the lab. AI can rank evidence, but it cannot skip policy or turn a missing signal into a clean result.

  1. Planned — not available

    Hardware trust

    TPM identity, Secure Boot state and Linux MOK enrollment are planned attestation inputs. The production backend does not yet collect or verify this evidence, so no hardware-attestation result is available today.

  2. Planned — not available

    Signed boot

    Binding boot and agent trust to signed artifacts remains planned. Missing TPM, disabled Secure Boot and untrusted MOK are not yet reported as production findings.

  3. Available

    Native sensors

    Native OS paths collect the signals each platform can prove. Active sensor tiers and lower-privilege fallbacks are reported, so reduced coverage never looks complete.

  4. Available

    Deterministic detection

    Sigma, YARA-X, IOC matches, process ancestry, ransomware canaries and tamper checks create human-readable evidence. Advisory scoring may rank the queue only after policy decides.

  5. Available

    Gated response

    Allowlist, kill-switch, dry-run and authorization checks run before containment. The action and its outcome are written back to evidence.

  6. Evidence-gated

    Recovery readiness

    Recovery contracts bind a response plan to known evidence. Signed recovery is promoted only after the target operating-system matrix proves the full path; it is not described as automatic today.

Evidence-gated

Managed-host prototype

Managed-host recovery is a prototype path. It is not presented as a deployed production fleet until host, artifact and restore evidence passes rollout gates.

Lab only

Isolated DMA research

Physical DMA capture stays in an isolated research lab. It is optional, separate from endpoint protection and never implied to be installed at customer sites.

Native operating-system security

Use the telemetry the OS already knows best

One portable detection core sits above native collection paths. If a privileged sensor is unavailable, the agent degrades visibly rather than pretending coverage exists.

Windows

ETW and Security Center awareness

Available: Event Tracing for Windows collects process execution, network connections and DNS queries from Kernel-Process, Kernel-Network and DNS-Client providers.

Evidence-gated: complete file and registry ETW coverage, native product registration and a production Windows driver are not claimed today.

CloudCastle reads Windows Security Center’s public product list to understand the antivirus, antispyware and firewall products already present.

Coexistence is deliberate: CloudCastle never directly disables Microsoft Defender or Tamper Protection. Native WSC product registration requires Microsoft Virus Initiative membership.

macOS

Endpoint Security Framework

Apple’s Endpoint Security Framework provides real-time process-execution telemetry through the same system API used by commercial endpoint products.

Where entitlement, root or TCC approval is unavailable, a libproc process-table poller provides a lower-privilege fallback so new executables remain visible.

The agent reports which tier is active; fallback coverage is never mislabeled as full Endpoint Security coverage.

Linux

eBPF, tracepoints and LSM

An eBPF sensor attaches to the process-exec tracepoint and, where supported, BPF-LSM file-open and socket-connect hooks. Network collection can fall back to a TCP-connect kprobe.

Ring-buffer events are normalized without blocking the kernel path. On-demand memory inspection uses /proc/<pid>/maps and /proc/<pid>/mem.

Unavailable kernel features fail open and report their degraded state rather than stopping the machine or the agent.

Measured coverage

Signals that cover different failure modes

Coverage is based on evidence the active sensor can emit. Unsupported, denied or degraded paths stay visible instead of becoming a clean verdict.

Available

Sigma behavior rules

Portable Sigma detections map normalized endpoint events to ATT&CK-tagged techniques. Offline checks reject rules that ask for fields the active sensor contract cannot emit.

Available

YARA-X content inspection

Owned and vendor YARA packs inspect events that contain file evidence. Broken packs report a failure and do not stop the rest of the pipeline.

Ransomware

Canaries and burst behavior

Write-intent touches of protected honeyfiles create high-signal alerts. Multiple distinct trips inside a short window escalate to a critical active-ransomware verdict.

Threat intel

Live IOC matching

Hash, IP, domain and path indicators can be loaded or hot-swapped without restarting the agent. Matches are indexed for constant-time lookup and recorded as explicit evidence.

Memory

On-demand process scanning

Platform readers support bounded process-memory scans and return explicit unsupported or denied states. The scanner does not hide a privilege failure behind a clean verdict.

Provenance

Process-tree context

Bounded ancestry links the suspicious child to the shell, document reader, installer or parent process that launched it, preserving the path from initial execution to detection.

Tamper

Agent self-protection

Protected agent paths and allowed process IDs make modification attempts visible. The same bounded telemetry store exposes recent tamper activity to the management plane.

Vulnerabilities

CISA KEV and NVD

Normalized CISA Known Exploited Vulnerabilities and NVD data is matched against installed-package inventory, separating actively exploited exposure from ordinary backlog.

Removable media

USB awareness

Attach detection adds removable-device context to the endpoint record, helping technicians investigate the physical path behind a suspicious file or process.

AI with boundaries

Faster judgment without unbounded autonomy

CloudCastle separates evidence, ranking and enforcement so a model failure cannot silently become an endpoint action.

  • Stable features: the same named signals feed the local advisory scorer and the out-of-process model boundary, preventing training and runtime extraction from drifting apart.
  • Post-decision scoring: risk is computed after the response dispatcher returns; the dispatcher has no score parameter and cannot read it.
  • AI technician escalation: high-confidence incidents can be summarized and planned in the control plane, while every proposed playbook still passes an allowlisted deterministic gate.
  • Human-readable evidence: rule, ancestry, IOC, canary, action and outcome remain available even when AI services are unavailable.
A clear record of endpoint detections, decisions and response actions

Response safety

Automated response should be hard to misuse

The same gate order applies to every endpoint action, including actions triggered through a partner or management workflow.

Unchecked automation

  • A confidence score becomes permission
  • One false positive kills a trusted process
  • No global stop control
  • An alert says what was detected, not what changed

CloudCastle response path

  • Trusted path or hash allowlists short-circuit first
  • A local kill-switch stops all enforcement
  • Dry-run remains the safe default until policy enables action
  • Kill, containment and quarantine outcomes are written to telemetry

Put behavior-first protection on one endpoint

Start with a single computer, inspect the evidence and policy decisions, then expand with the same cross-platform control plane.

Simple pricing: a monthly minimum plus per endpoint — see pricing.