Solutions / EDR & XDR

Centeye Ironwatch™ — managed endpoint detection & response, with the whole attack story attached.

Centeye’s agent watches every Windows and macOS machine for attacker behavior, mapped to MITRE ATT&CK. Because it’s XDR, the endpoint is never judged alone: the phishing email that opened the attack and the sign-in that enabled it are correlated into the same incident, on one timeline.

WindowsmacOSDeployed via your RMM in minutes
This surface’s chapter of the attack
Canary file tripped4:51:02 PM · tripwire
Encoded PowerShell4:51:04 PM · behavior match
Host isolated4:51:09 PM · automatic
Chain tracedemail + login + host · one incident
Verified cleanbackup fired · restore point safe
What your clients get

Detection that reads behavior. Response that verifies itself.

Behavior-based detection, mapped to MITRE ATT&CK

Modern intrusions arrive as behavior — an encoded PowerShell command, a credential store being read, persistence quietly established, the built-in antivirus switched off. Centeye’s detection engineering is behavior-first, so the technique is caught even when the tooling is novel.

  • Ransomware canaries — tripwire files no legitimate process should touch; first modification starts containment.
  • Behavioral rules — obfuscated script execution, credential access, persistence via scheduled tasks, services and run-keys, and security-tool tampering, each mapped to its ATT&CK technique.
  • Malware verdicts — YARA rules, hash reputation, and sandbox-detonation analysis on suspicious files.
  • File integrity & Defender health monitoring — critical-path change detection, and an alert the moment built-in Windows protection is disabled (routinely an attacker’s first move).
  • Learned-benign suppression — the platform learns each client’s legitimate admin tooling and suppresses it from the queue, with a human approving every suppression. False-positive volume is a managed number, not an accident.

behavior-based · ATT&CK-mapped · tuning is a documented process

XDR correlation: one incident per attack

The endpoint alert is usually step three: a phishing email harvested credentials, the credentials opened a session, then the payload ran. Point tools file three tickets in three consoles. Centeye keys every signal to the same user and device and correlates them into one incident with one timeline — your analyst reads one record and approves one response.

cross-surface correlation · endpoint + identity + email

Containment you can defend in a post-incident review

Every response action is policy-scoped, reversible where the platform allows, written to a tamper-evident audit log, and re-checked against actual machine state after execution — “done” means verified, not assumed.

  • Automated host isolation — contains a device the moment behavior confirms, in seconds; release is one click when it’s clean.
  • Process termination · file quarantine & restore · persistence removal — the attacker’s footholds removed, reversibly.
  • Forensic collection — memory capture and a one-click investigation package from the live host, preserved for review.
  • Pre-emptive backup trigger — on ransomware behavior, Centeye fires the client’s own backup product for a clean restore point before encryption spreads.
  • Guardrails — destructive actions default to approval; newly enrolled endpoints carry a cool-off period during which destructive steps park to manual.

post-action verification · reversible · audited

How it works

Live on a client’s fleet the same morning.

Deploy the agent

Push the light, code-signed Centeye agent to Windows and macOS through your RMM — ConnectWise, Autotask, or NinjaOne. Agents refuse unsigned updates.

Start in watch-only

The platform observes, baselines the client’s normal, and reports what it would have done — findings you can score against your incumbent EDR.

Set the response mode, per client

Watch → recommend → approve → auto-contain, configured per action class. The cautious client and the pre-authorized client both fit the same console.

Kavach · on this surface

Reads the process chain, decides contain vs. watch, executes the isolate/kill/quarantine play within policy — and documents what it did, why, and what it verified.

Argus · for the client

Translates “persistence removed on FINANCE-PC” into reporting the client’s stakeholders can act on — impact, action taken, cost avoided — in the monthly digest.

Common questions

What MSPs ask us first

Is Microsoft Defender enough for our clients?

Defender is a capable prevention layer, and Centeye monitors its health rather than fighting it. What Defender does not do is correlate an endpoint event with the email and sign-in that preceded it, run 24/7 triage, or execute governed cross-surface response. Most clients keep Defender on and add Centeye above it.

EDR vs MDR vs XDR — which is this?

All three layers, honestly labeled: an EDR agent for telemetry and containment, XDR correlation across endpoint, identity, and email, and 24/7 managed detection and response — the triage automated, your team in command of policy and approvals.

Does this replace our current EDR?

It can, or it can run alongside during evaluation. Watch-only mode produces a findings report you can score against your incumbent before any client-facing change.

What happens when a machine is isolated by mistake?

Release is one click, the action is fully logged, and the triggering tool can be designated learned-benign — approved by a human — so the false positive does not repeat.

Can this run co-managed with a client’s internal IT or SOC?

Yes — engagement modes are per action and per tenant. Pre-authorize containment for clear threat classes, route approvals to the client’s team for the rest, and give their analysts the same evidence view yours have.

How heavy is the agent?

Light enough to push through your RMM in minutes; no reboot required for install.

Put it on ten machines. Score it against your incumbent.

Watch-only mode, your policy, remove anytime — you keep the findings report either way.