Detect what doesn't fit the norm
orovar learns the normal behavior of an environment — login patterns, data flows, typical application execution, common network paths. Deviations are scored on trained models, not on static thresholds.
Cybersecurity Suite
Autonomous security agent, powered by NeoI (neonotu Intelligence).
Doesn't hide. Hunts.
orovar is the autonomous security agent of the Cybersecurity Suite. Unlike classic detection tools, orovar doesn't just report — it acts. Detected activity can be automatically isolated or redirected to honeypots, while the security team is informed and retains control.
Automatic first response within the time windows where human reaction is too slow.
Honeypot redirection becomes part of daily defense, not a research project.
NeoI scoring replaces the extensive playbook maintenance of classic SOAR platforms.
Every action and override is documented in audit-grade form — ideal for regulated industries.
HOW IT WORKS
orovar unifies detection, isolation, and active deception in one agent — and places that agent under a clear policy and audit regime.
orovar learns the normal behavior of an environment — login patterns, data flows, typical application execution, common network paths. Deviations are scored on trained models, not on static thresholds.
When orovar detects a confirmed anomaly, the affected system can be cut off from critical zones within seconds. Isolation is reversible, fully logged, and overridable.
Detected attacker activity can be routed to a controlled honeypot environment. There, attacker behavior, tooling, and objectives are observed — information that flows back into the detection models.
orovar acts within a policy defined by the organization. Action classes can be configured from suggestion to confirmation-required to fully automatic — by severity, zone, and risk authorization. Every action is documented traceably.
POLICY
The policy engine defines what actions orovar may carry out on its own. An organization can tailor the policy to its maturity, risk appetite, and regulatory pressure.
| Action class | Description | Typical setting |
|---|---|---|
| Suggest | orovar recommends an action without executing it. | Low severity |
| Confirm | Action requires sign-off by a SOC analyst. | Medium severity |
| Auto-execute | Action is executed immediately and logged. | High severity, clear indicators |
| Manual override | Every action is overridable at any time. | Always active |
In comparison
orovar addresses a gap that classic EDR tools and SOAR platforms each only partially close.
| Aspect | EDR alone | SOAR platform | orovar |
|---|---|---|---|
| Detection | Endpoint-centric | Source-agnostic | Behavioral, multi-source |
| Response | Limited | Script-based, high maintenance | Policy-based, NeoI-scored |
| Deception/Honeypot | Not in scope | Only via integration | Native |
| Maintenance effort | Medium | High | Low |
| Audit suitability | Variable | Variable | Design principle |
In practice
How organizations across the European mid-market and the public sector use the module.
On a Saturday at 03:14, orovar observes login behavior on a server that deviates from the learned normal model. Correlated signals from Strider point to a preceding unusual identity sign-in. orovar isolates the affected server, redirects further connection attempts to a honeypot environment, and informs the on-call engineer through the defined escalation path. The situation is contained before the security team could have responded manually.
A mid-sized mechanical engineering firm is repeatedly targeted by clearly intentional attacks on its R&D environment. orovar consistently routes detected attacker activity into honeypot systems modeled after the real R&D zone. Over several weeks, a detailed picture of the tooling and objectives is built up without touching production systems.
A public administration under high regulatory pressure deploys orovar across its critical zones. Mean time to contain — the time between detection and complete containment — drops from a previous 4 hours to under 90 seconds for the defined action classes. Internal and supervisory reporting benefits measurably.
NEXT STEP
orovar shifts the boundary between detection and response to where, in today's threat landscape, it actually needs to sit: into the seconds, with clearly documented and overridable actions. Human and machine do not work against each other but on a jointly defined policy.
orovar is the part of the Cybersecurity Suite that closes the detect-and-response gap. For organizations under elevated response pressure — regulatory, operational, or insurance-related — it is the logical next step.
NIS2, DORA, ISO 27001 and GDPR as preconfigured control catalogues, plus a security score from 0 to 100 across six domains. Dat…
ViewSignals from firewall, endpoint, identity and cloud condensed into incidents instead of alert floods. NeoI correlation instead …
ViewFour graded models on cyanbox hardware secure the perimeter and internal zones — from a single practice to a corporate network,…
ViewVulnerabilities, external attack surface, web applications, cloud and identities in one ranking by real risk. Active scans only…
ViewContact
Talk to us before somebody else does. The first conversation is free and we reply the same business day.