Instant Response
24/7 immediate response to cybersecurity incidents. Minimize damage with our professional instant response service — ex…
ViewDefensive Services
Signatures catch what somebody has already seen. The attacker who is genuinely dangerous to you brings nothing that appears on any list: they sign in with a valid password and carry on using your own tools.
The starting point
A signature describes a file that already existed. Against commodity malware that works and will keep working — against someone who tailors their tooling to your organization it does not. And against someone who brings no tooling at all, there is simply nothing to sign.
Everything after the initial breach can be done with what is already there: PowerShell to execute, WMI to distribute, RDP to move on, a service account to stay. Living off the Land is the name for this, and in MITRE ATT&CK signing in with stolen credentials carries a technique of its own under Valid Accounts. None of it is malware. Every one of these tools is used legitimately in your organization every day — which is why none of them is on a blocklist, and why nobody raises an alarm.
What remains is not the tool but how it is used. An administrator who signs a service account in interactively at three in the morning and then searches the invoice archive is not running suspicious software. They are simply not behaving like themselves.

The approach
NeoI does not start from a list of threats but from your operations. Before anything can count as unusual, what counts as usual has to be established — and that differs in every organization.
Over the first weeks a baseline forms for every account, device and service: which sign-ins are usual, at what times, from where, which systems a machine talks to, how much data volume is ordinary. In a law firm, file access on a Sunday is routine; in a manufacturing plant it would not be. No shipped rule can know that difference.
So the alert is not “PowerShell was executed” but the break with an established pattern: a service account working interactively for the first time. A sign-in outside every previous window, followed by access to shares this account has never touched. A workstation talking to a datacentre server for the first time in months — and then to four of them.
Individually, these anomalies are usually harmless. Their value emerges only in combination: the same sign-in, the same device, the same window across network, endpoint and cloud service. What runs in separate tools — UEBA for account behaviour, NDR for network traffic, EDR for the endpoints — has to come together in one case. Establishing that connection is work no human does at the required speed, and the actual reason a model is doing the computing here.
Behavioural baseline per account, device and service instead of fixed thresholds
Correlation across network, endpoints and cloud services into a single case
Prioritisation by business relevance — the domain controller outweighs the meeting-room machine
Every alert mapped to a technique in MITRE ATT&CK, so triage does not start from zero
which behaviour, measured against which baseline, since when
Feedback — every confirmed false positive sharpens the model for your environment
An alert nobody reads is not protection.
The measure
The most common and entirely fair objection to AI in security is that it produces additional alerts. We measure ourselves by the opposite. An alert should only exist when a human genuinely has something to decide — everything else is work you pay for without becoming safer.
In practice: related events are consolidated into one case rather than queuing up individually. Forty entries over one night become a single case with a timeline. The result is visible in Strider, the monitoring layer of our suite — with the chain that led to the alert, not only its conclusion.
The boundary
Assessing a case and deciding on a countermeasure stay with analysts. We use a model to remove noise — not to shift responsibility. Blurring that line means selling convenience as security.
Where an automatic first response is defensible, such as isolating a single endpoint at four in the morning, Talion takes over — under rules agreed in advance, within narrow limits, and with audit-proof documentation of every action. Anything that could take a datacentre offline is decided by a human, without exception.
Without logs there is nothing to detect.
The honest view
It does not start on day one. Weeks pass before the baseline is dependable, and during that time detection is weaker, not stronger, than a signature-based product. If you need immediate effect, this is not where you will find it.
It also does not replace logs that do not exist. Without sign-in events from the directory service, without process data from endpoints, without logs from cloud applications, any model stays blind. So the first piece of work is regularly not detection but closing the gaps in data collection.
And it does not replace the fundamentals. Missing multi-factor authentication, a flat network without segmentation, updates that were never applied — no detection helps against those, only fixing them does. If we see that at your site, we say so before any engine is discussed.

How it fits together
Detection is a building block, not an operation. It produces cases someone has to assess — around the clock, weekends included. If you cannot or would rather not carry that yourself, combine it with SOC as a Service; if you have your own team and want to relieve it, with SOC Co-Managed.
When a case turns into an emergency, Instant Response takes over. And if you want to see how mature your detection is next to the other domains, you will find it in Sightadel.

In closing
In almost every organization the decisive data is already there — it is simply never brought together. So the first sensible step is not a purchase but an inventory: which events are collected today, how long are they retained, and who looks at them?
We do that inventory with you in an initial conversation. It costs nothing and often ends with a smaller recommendation than the one you expected.
FAQ
It can, and many products do. The difference lies in what you measure: we do not count the anomalies found but the alerts that genuinely require a decision. Related events are bundled into one case, and every confirmed false positive feeds back into the model. In the first weeks there are more alerts, after that considerably fewer.
Two to four weeks until the baseline is dependable. Before that there are alerts, but their assessment is weak — what counts as normal simply is not established yet. That time cannot be shortened, and anyone shortening it for you is selling you shipped rules under a different name.
No, as a rule it builds on it. A SIEM collects and retains, detection assesses. If you already run one, we keep using its data rather than building a second collection point. Where there is no SIEM, we first clarify which events are being collected at all.
Not necessarily. Where regulation or your own policy requires it, the analysis stays on your premises. That is a question of deployment, not a property of the method — and we settle it before the engagement, not after.
Yes, and that is a condition rather than an extra. Every alert states which behaviour stood out, against which baseline it was measured, and which individual events led to it. An alert that cannot be justified is one an analyst cannot assess — and an auditor even less so.
Defensive Services
24/7 immediate response to cybersecurity incidents. Minimize damage with our professional instant response service — ex…
ViewHarvest now, decrypt later already affects data encrypted today. Cryptographic inventory, assessment by lifetime and hy…
ViewFirewall, segmentation and intrusion detection as one architecture — planned, implemented, operated. With Valar as a ha…
ViewContact
Talk to us before somebody else does. The first conversation is free and we reply the same business day.