Sees suspicious activity
CloudCastle follows programs, files, network connections and sign-in activity so it can spot an attack while it is happening.
CloudCastle Advanced EDR
CloudCastle watches what programs do, not just what they are called. When behavior looks dangerous, it gathers the evidence and can safely stop or isolate the threat under rules you control.
Behavior-first protection
The short version
It watches each computer, recognizes attack behavior and responds without handing unlimited control to AI.
CloudCastle follows programs, files, network connections and sign-in activity so it can spot an attack while it is happening.
It combines trusted security rules with behavior and threat intelligence, helping it catch both known malware and new attacks.
Approved policies can stop a malicious process, quarantine a file or isolate a computer. Every action is recorded and protected by safety controls.
Endpoint trust and recovery
Each layer reports what is active, what still needs proof and what remains in the lab. AI can rank evidence, but it cannot skip policy or turn a missing signal into a clean result.
TPM identity, Secure Boot state and Linux MOK enrollment are planned attestation inputs. The production backend does not yet collect or verify this evidence, so no hardware-attestation result is available today.
Binding boot and agent trust to signed artifacts remains planned. Missing TPM, disabled Secure Boot and untrusted MOK are not yet reported as production findings.
Native OS paths collect the signals each platform can prove. Active sensor tiers and lower-privilege fallbacks are reported, so reduced coverage never looks complete.
Sigma, YARA-X, IOC matches, process ancestry, ransomware canaries and tamper checks create human-readable evidence. Advisory scoring may rank the queue only after policy decides.
Allowlist, kill-switch, dry-run and authorization checks run before containment. The action and its outcome are written back to evidence.
Recovery contracts bind a response plan to known evidence. Signed recovery is promoted only after the target operating-system matrix proves the full path; it is not described as automatic today.
Managed-host recovery is a prototype path. It is not presented as a deployed production fleet until host, artifact and restore evidence passes rollout gates.
Physical DMA capture stays in an isolated research lab. It is optional, separate from endpoint protection and never implied to be installed at customer sites.
Native operating-system security
One portable detection core sits above native collection paths. If a privileged sensor is unavailable, the agent degrades visibly rather than pretending coverage exists.
Available: Event Tracing for Windows collects process execution, network connections and DNS queries from Kernel-Process, Kernel-Network and DNS-Client providers.
Evidence-gated: complete file and registry ETW coverage, native product registration and a production Windows driver are not claimed today.
CloudCastle reads Windows Security Center’s public product list to understand the antivirus, antispyware and firewall products already present.
Coexistence is deliberate: CloudCastle never directly disables Microsoft Defender or Tamper Protection. Native WSC product registration requires Microsoft Virus Initiative membership.
Apple’s Endpoint Security Framework provides real-time process-execution telemetry through the same system API used by commercial endpoint products.
Where entitlement, root or TCC approval is unavailable, a libproc process-table poller provides a lower-privilege fallback so new executables remain visible.
The agent reports which tier is active; fallback coverage is never mislabeled as full Endpoint Security coverage.
An eBPF sensor attaches to the process-exec tracepoint and, where supported, BPF-LSM file-open and socket-connect hooks. Network collection can fall back to a TCP-connect kprobe.
Ring-buffer events are normalized without blocking the kernel path. On-demand memory inspection uses /proc/<pid>/maps and /proc/<pid>/mem.
Unavailable kernel features fail open and report their degraded state rather than stopping the machine or the agent.
Measured coverage
Coverage is based on evidence the active sensor can emit. Unsupported, denied or degraded paths stay visible instead of becoming a clean verdict.
Portable Sigma detections map normalized endpoint events to ATT&CK-tagged techniques. Offline checks reject rules that ask for fields the active sensor contract cannot emit.
Owned and vendor YARA packs inspect events that contain file evidence. Broken packs report a failure and do not stop the rest of the pipeline.
Write-intent touches of protected honeyfiles create high-signal alerts. Multiple distinct trips inside a short window escalate to a critical active-ransomware verdict.
Hash, IP, domain and path indicators can be loaded or hot-swapped without restarting the agent. Matches are indexed for constant-time lookup and recorded as explicit evidence.
Platform readers support bounded process-memory scans and return explicit unsupported or denied states. The scanner does not hide a privilege failure behind a clean verdict.
Bounded ancestry links the suspicious child to the shell, document reader, installer or parent process that launched it, preserving the path from initial execution to detection.
Protected agent paths and allowed process IDs make modification attempts visible. The same bounded telemetry store exposes recent tamper activity to the management plane.
Normalized CISA Known Exploited Vulnerabilities and NVD data is matched against installed-package inventory, separating actively exploited exposure from ordinary backlog.
Attach detection adds removable-device context to the endpoint record, helping technicians investigate the physical path behind a suspicious file or process.
AI with boundaries
CloudCastle separates evidence, ranking and enforcement so a model failure cannot silently become an endpoint action.
Response safety
The same gate order applies to every endpoint action, including actions triggered through a partner or management workflow.
Start with a single computer, inspect the evidence and policy decisions, then expand with the same cross-platform control plane.
Simple pricing: a monthly minimum plus per endpoint — see pricing.