Capability matrix

Every Guard security control

Feature parity categories buyers expect from a modern protect SKU — delivered with Defender as the engine and Guard as the response plane.

Capability Aegis Guard delivery
NGAV / malware prevent Microsoft Defender realtime + Attack Surface Reduction (ASR)
Ransomware response Local canaries · kill · isolate (offline-capable)
Detect + alert console Guard portal stats, recent events, live protect score
Kill process Agent kill / block path for suspicious processes
Quarantine + restore UX Endpoint quarantine + console inventory + restore command
Host network isolate Isolate with DNS + Guard/API management allow-list; release
Desk contain (strong) Network isolate + USB mass-storage deny + workstation lock
On-demand scan ProtectScanNow → Defender quick scan
USB / device control Removable storage deny via Aegis One MDM plane (when licensed)
Script / macro control Defender ASR policy evidence and enforcement
Sensor tamper resist TamperProtect + Guard registry hardening
Offline protect Local canaries + Defender offline path
False-positive workflow Mark FP in console with audit trail
Software integrity Piracy tooling (crack/keygen/activator) block; unsigned installer alarms from Downloads/Temp/Desktop with full path
Cloud contain Lock + revoke trusts on high-severity detect / canary / piracy
External EDR bridge Optional connector webhooks into Guard ingest
Unified standalone console guard.securegentools.com/console/
Threat Graph / elite hunt Out of scope by design (Falcon wins that category)
Mobile NGAV Out of scope (current)
Independent Falcon-class sensor No — Defender is the detection engine
License-server “is Adobe licensed?” No — not a copyright court
Open console Back to home