ClearSkies Endpoint Threat Monitoring and Response
How the agent reaches a verdict
Detection accuracy is what separates a high-signal endpoint program from a noise machine.
Several detection sources
Evaluated in parallel and combined into a single verdict
Four confidence bands
Confirmed, Likely, Suspicious and Benign
Inline containment
Action gated by confidence band
Multi-signal verification
ETMR turns the endpoint from passive plumbing into an active detection and response control point. It continuously records process, file, user and network behavior, evaluates that behavior against threat intelligence and behavioral models rather than signatures alone, contains threats automatically when confidence is high, and preserves the full record of the activity.
A single false-positive kill of a business-critical process erodes trust faster than ten true containments build it. So rather than acting on any one signal, ETMR evaluates endpoint behavior across several independent detection sources in parallel and combines their weighted contributions into a single verdict.

What the agent observes, how the verdict is banded, and the exchange with the TDIR engine.
The confidence bands
The band a verdict falls into decides what the agent is permitted to do about it. Enforcement is proportionate by design: the higher the certainty, the more the agent acts without waiting.
| Confidence band | Action | What happens |
|---|---|---|
| Confirmed | Contained inline | The process is killed or the host is isolated, an alert fires, and the event is reported to the TDIR engine and to your own SIEM where one is connected. |
| Likely | Contained or flagged | Contained or flagged according to tenant policy, and surfaced for analyst confirmation. |
| Suspicious | Alert only | Logged and alerted for review by default. No enforcement unless policy escalates it. |
| Benign | Allowed | Allowed to run, and logged for traceability and behavioral baselining. |
How accuracy improves
Analyst verdicts are fed back into the detection engine. A behavior confirmed as malicious in one tenant is distributed to every agent as detection content, never as customer data. A false-positive mark suppresses recurring noise, and behavioral baselines retrain on each tenant’s own endpoints.
Accuracy improves with every analyst decision, without manual tuning.
Automated response and containment
Detection only matters if something happens next. ETMR acts inline, so a threat is stopped at machine speed rather than waiting in a queue for an available analyst.
Features
- Inline process termination, file quarantine and host isolation.
- Action gated by confidence band.
- Every action logged with its full sequence for audit.
Benefits
- Threats are contained in seconds, not at the next shift handover.
- Blast radius is limited to the first endpoint.
- Containment is auditable for the board and for regulators.
In action: from a trusted process to a contained incident
The sequence below is illustrative. It shows how the agent and the platform work together, and is not an account of a specific customer incident.
- 01
On the endpoint
A user opens a macro-enabled attachment.
Word spawns PowerShell, which writes an executable to a temporary path and begins encrypting files.
No known-bad signature is involved.
- 02
The agent acts
ETMR recognizes the process lineage, the anomalous child process and the rapid file-modification pattern together, classifies the behavior as ransomware, and kills the process and isolates the host inline.
- 03
In the platform
The verdict reaches the TDIR engine, where it meets the phishing context from Identity Threat Protection and the newly registered domain verdict from DNS Shield, correlating into one high-fidelity incident.
The engine drives Active Defense, and a playbook contains the incident in seconds, with the full sequence recorded for audit.
Two further cases
A stolen session token
A process uses a stolen token to enumerate network shares and attempt remote execution against a domain controller, with no malware file involved. ETMR classifies the behavior, kills the process and isolates the host. Identity Threat Protection has already reported the same user’s credentials in a fresh information-stealer log, and the engine correlates the two into one account-compromise incident.
A living-off-the-land script
A scheduled task launches an obfuscated PowerShell script that uses only trusted, signed Windows tools to stage data for exfiltration. ETMR recognizes the anomalous command-line patterns and the parent-child process chain, bands the verdict as high confidence and contains the host. The engine correlates it with the DNS Shield verdict on the destination domain.
Getting to protective coverage
Onboarding and scoping
Authorizing endpoint scopes, rolling out the agent, and setting the baseline detection and exclusion policy before enforcement is turned up.
Integration
Connecting ETMR to the TDIR engine and to your own SIEM, SOAR and collaboration tools for alerting and response.
Enablement and training
Role-based tracks on policy management, the confidence-band model and the containment and reporting workflow.
Ongoing optimization
Periodic review of policy effectiveness, false-positive rates and service-level performance as the estate changes.

ETMR is delivered with a professional-services wrap, so you reach policy-governed coverage quickly rather than being handed an agent to configure.
Technical Questions
What does ETMR see that a signature-first product does not?
Behavior. Fileless and living-off-the-land activity that never drops a recognizable file, credential theft from process memory, beaconing from an unexpected process, and rapid file modification characteristic of ransomware.
What stops the two agents from interfering with each other?
Onboarding establishes the baseline detection and exclusion policy for both agents before ETMR enforcement is turned up, which is part of the professional-services wrap above.
Does ETMR act on what the other add-ons find?
Not directly. The add-ons do not exchange intelligence with one another. Every signal routes through the TDIR engine, which correlates it and returns the resulting detection outcomes to ETMR, so the agent acts on a correlated picture rather than on another product’s raw finding.
See the whole endpoint, not just the malware.
No single signal produces a confirmed-malicious verdict by itself.
Request a Demo
