ClearSkies Endpoint Threat Monitoring and Response

Behavior-based, not signature-based

  • Full behavior

    Process, file, network, user and entity

  • Mapped to ATT&CK

    An explicit technique identifier on every detection

  • Detection and hardening

    Patches ranked by exploitability in the same agent

What the agent watches

It recognizes known-bad artifacts, detects the behavioral tells of fileless and living-off-the-land attacks, watches user and entity behavior, and responds inline.

  1. Process and lineage monitoring

    Every process is tracked with its parent, its children and its command line, so a trusted application spawning something it never should, such as a document launching PowerShell, stands out immediately. Lineage is preserved as evidence, so root cause is recorded rather than reconstructed.

  2. File and integrity monitoring

    Critical files, directories and registry keys are watched for the unauthorized change that signals persistence, tampering or ransomware in progress. Rapid-modification patterns are caught before the encryption run finishes.

  3. Host network analysis

    Connections are inspected at the host itself, so beaconing, tunneling and command-and-control callbacks are surfaced even when the traffic never passes a proxy and the device is working from home. Network evidence is tied to the responsible process.

  4. User and entity behavior analytics

    Each user and device is baselined, and deviations such as an unusual logon or sudden access to sensitive files are flagged. Account takeover is caught even when the credentials are valid, and the risk score contributes to the confidence band.

How it decides
what is bad

  • Real-time threat detection

    Signature, heuristic and anomaly detection run together against live activity at execution time rather than on a scheduled scan, so a known malware family and a never-before-seen behavioral pattern are both caught as they run.

  • YARA rule matching

    Files, processes and in-memory content are scanned against curated ClearSkies rule sets and your own custom rules, so tooling is caught even when renamed, repacked or moved off disk, and a newly characterized threat is blocked the same day without a vendor release.

  • Threat intelligence and indicator matching

    Endpoint activity and artifacts are continuously matched against external intelligence feeds and indicators of compromise. The engine correlates an indicator hit with a behavioral tell, which is what produces a high-confidence incident rather than a lone match.

  • Endpoint hardening

    Missing patches and risky configurations are surfaced per endpoint and ranked by exploitability, distinguishing security updates from recommended ones, so the owner gets a short, prioritized list rather than an undifferentiated backlog.

How correlation works

MITRE ATT&CK alignment

Endpoint activity is where the ATT&CK framework was born, so ETMR detections map onto it cleanly. Every detection carries an explicit technique identifier, attached the moment it fires, so the security operation sees endpoint activity organized the way an adversary would approach it.

  • Initial Access
  • Execution
  • Persistence
  • Defense Evasion
  • Credential Access
  • Discovery
  • Lateral Movement
  • Command and Control
  • Impact

Nine capabilities map to the techniques they detect. Endpoint hardening is included separately, because it mitigates a technique rather than detecting it.

The technique mapping
CapabilityATT&CK tacticHow ETMR helps
Process and lineage monitoringExecutionDetects malicious command and scripting execution, T1059, by exposing anomalous parent-child process chains as they run.
Living-off-the-land detectionDefense EvasionFlags abuse of trusted system binaries, T1218, that leave no malicious file for a signature engine to catch.
YARA rule matchingDefense EvasionIdentifies obfuscated, packed or repacked payloads and known attacker tooling, T1027, by matching file and memory content.
File and integrity monitoringPersistenceCatches unauthorized changes to files, registry and startup locations, T1547, used to survive reboot.
Credential-access detectionCredential AccessIdentifies credential dumping and theft, T1003, from process memory and sensitive stores.
Host network analysisCommand and ControlSurfaces endpoint-level beaconing and callbacks, T1071, that never traverse an inspecting proxy.
Ransomware behavior detectionImpactRecognizes rapid, systematic file encryption, T1486, and contains it inline.
Lateral-movement detectionLateral MovementDetects remote-service and administrative-tool abuse, T1021, as an attacker pivots between hosts.
User and entity behavior analyticsDiscoveryBaselines normal behavior and flags reconnaissance and account discovery, T1087, that deviates from it.
Endpoint hardening (mitigation)Initial AccessSurfaces missing and recommended patches, mitigating exploitation of public-facing and client applications, T1190 and T1203.

Mapping is scope, not an assurance of detection. Techniques exercised in a purple-team run or against MITRE Engenuity ATT&CK Evaluations are reported as demonstrated, and reporting states which applies. Coverage exports as an ATT&CK Navigator layer for prioritizing detection-engineering work.

Data protection and privacy

Endpoint monitoring collects sensitive data, so how that data is handled matters as much as what it catches. ETMR encrypts collected data in transit, applies privacy controls aligned to GDPR and comparable regimes, and allows retention and scope to be configured per tier and per tenant.

Storage, residency and the controls that govern them follow the platform’s data sovereignty controls.

Data sovereignty on ClearSkies iISOC
ETMR data privacy and sovereignty

See the whole endpoint, not just the malware.

Request a Demo