How it works

Detect → respond → prove

One protect loop: Defender feeds signals, the Guard agent acts at the desk, and operators see evidence in the console — not a hunt theater.

1. Detect

Microsoft Defender realtime and ASR surface Operational threats. Local ransomware canaries and integrity alarms add offline-capable signals the cloud never sees first.

2. Respond

The agent kills or blocks the path, quarantines samples, isolates the host with management allow-lists, and can desk-contain with USB deny + lock when severity warrants it.

3. Prove

Console stats, recent events, and a live protect score show coverage. Mark false positives, restore from quarantine, and release isolate when the desk is clean.

The pieces

Agent · Defender · Console

Three planes, one SKU. No independent Falcon-class sensor — Defender is the detection engine by design.

Detect and respond console

Windows agent at the desk

Runs alongside Defender. Enforces kill, quarantine, canaries, isolate, USB deny seams, and tampers-resistant Guard registry hardening.

  • Protect scan → Defender quick scan
  • Canary decoys for ransomware write paths
  • Cloud contain on high-severity detect / canary / piracy
Host isolate concept

Defender as the engine

NGAV prevent and ASR stay on Microsoft’s sensor. Guard does not pretend to own Threat Graph or elite hunt — it owns response and proof.

  • Realtime + ASR policy evidence
  • Offline Defender path still protects
  • Optional external EDR webhook ingest
Quarantine inventory

Operator console

Same protect plane at /console/ — score, events, quarantine inventory, isolate, and restore.

  • Live protect score + 24h stats
  • False-positive mark with audit trail
  • Restore when a sample is clean

See every control

Full capability matrix — no claim inflation.

Features Open console