1. Detect
Microsoft Defender realtime and ASR surface Operational threats. Local ransomware canaries and integrity alarms add offline-capable signals the cloud never sees first.
How it works
One protect loop: Defender feeds signals, the Guard agent acts at the desk, and operators see evidence in the console — not a hunt theater.
Microsoft Defender realtime and ASR surface Operational threats. Local ransomware canaries and integrity alarms add offline-capable signals the cloud never sees first.
The agent kills or blocks the path, quarantines samples, isolates the host with management allow-lists, and can desk-contain with USB deny + lock when severity warrants it.
Console stats, recent events, and a live protect score show coverage. Mark false positives, restore from quarantine, and release isolate when the desk is clean.
The pieces
Three planes, one SKU. No independent Falcon-class sensor — Defender is the detection engine by design.
Runs alongside Defender. Enforces kill, quarantine, canaries, isolate, USB deny seams, and tampers-resistant Guard registry hardening.
NGAV prevent and ASR stay on Microsoft’s sensor. Guard does not pretend to own Threat Graph or elite hunt — it owns response and proof.
Same protect plane at /console/ — score, events, quarantine inventory, isolate, and restore.
Full capability matrix — no claim inflation.