endpoint

Endpoint Protection

Complete endpoint
detection & response.

A lightweight agent that monitors, detects and responds to threats on every workstation and server in your organization.

93%Anomaly accuracy
<3sApp kill time
24/7Monitoring
Win+LinPlatforms
Endpoint capabilities

Protection for every device.

From workstations to servers, one agent covering the network path, the file system, the process tree and the user behind them.

Micro-segmentation

TCP-level blocking with first-match rules, IP/CIDR/port filtering and direction-aware policies for granular network control.

Lateral movement prevention

Block SMB, RDP, WinRM and NetBIOS lateral paths, detect port scans and contain a breach before it spreads.

Application & process control

A three-second watchdog kills unauthorized apps, blocks remote access tools and crypto miners, and terminates entire child process trees.

DNS control

Hosts-file level blocking by category — malware, social media, streaming, gambling — with automatic DNS cache flushing.

Anomaly & insider threat detection

Threshold-based rules catch bulk exfiltration, large transfers, off-hours activity and suspicious time-window patterns.

File & network monitoring

FileSystemWatcher with ETW kernel tracing, TCP tracking every two seconds, 30+ suspicious extensions and USB device monitoring.

Remote isolation & response

Auto-isolation triggers disable network adapters instantly, and one-click restore reconnects the endpoint after remediation.

Multi-channel alerting

Email, Teams and Slack webhooks with per-rule configuration, severity levels and a 15-minute cooldown to keep the noise down.

How it works

A heartbeat loop, every five minutes.

The agent stays light because it does the same four things on a cycle — check in, sync policy, collect events, run commands.

Step 01

Heartbeat

The agent checks in with the server every five minutes.

Step 02

Policy sync

The server responds with the latest policies and any pending commands.

Step 03

Event collection

Network, file, process and browser events are collected on the host.

Step 04

Command execution

Isolate, restore, kill a process or update policy — on demand.

Policy management

Granular control, centrally managed.

Every security domain gets its own configuration surface, synced to the fleet on the next heartbeat.

Configuration

13 policy tabs

Each endpoint policy is split into thirteen dedicated configuration tabs, giving you fine-grained control over one security domain at a time.

  • Per-group policy assignment
  • Version control and rollback
  • Real-time sync on next heartbeat
  • Import and export configurations
Policy tabs 13 domains
GeneralDNSApp ControlProcess NetworkMonitoringEvent FilterAuto-Isolation AlertsAnomalySyslogAD Intel Adaptive Learning
Detection

Anomaly detection engine

Five pre-built anomaly rule types with configurable thresholds and time-window analysis surface insider threats and unusual data movement.

  • Bulk file exfiltration detection
  • Large transfer volume alerts
  • Off-hours activity monitoring
  • Custom threshold and time-window rules
Rule: bulk file copy Active
Type
file_count_threshold
Threshold
50 files
Window
10 minutes
Severity
High
Action
Alert + auto-isolate
Response

Auto-isolation engine

When a critical threat fires, the agent isolates the endpoint by disabling its network adapters — stopping lateral movement where it stands.

  • Configurable isolation triggers
  • Network adapter disable and enable
  • One-click restore from the dashboard
  • Full isolation event audit trail
Isolation sequence Automatic
  • 1Threat detected — anomaly or rule trigger fires
  • 2Agent disables all network adapters instantly
  • 3Alert sent to the SOC via Email / Teams / Slack
  • 4Analyst reviews and clicks Restore to reconnect
Integrations

SIEM and integration ready.

Standard Syslog through to CEF format, forwarded to the leading SIEM platforms and customizable per policy.

CEF / Syslog forwarding Splunk IBM QRadar Microsoft Sentinel Wazuh REST API

Ready to protect
every endpoint?

See ReviveSec Endpoint Protection in action. Schedule a personalized demo with our security experts.

Schedule a demo