Aegis Guard

Defender detect. Guard responds at the desk.

Kill, quarantine, isolate, and prove coverage — Falcon Go–class controls without Threat Graph theater.

What ships

Prevent · Detect · Respond · Harden

Every control below is in the product. Marketing claims live here; the operator console runs the same protect plane.

Detect and respond console atmosphere

Detect → kill → alert

Defender Operational threats feed the Guard loop. Operators see detect, kill, and contain signals with a live score.

  • NGAV / malware prevent (Defender realtime + ASR)
  • Detect + alert console with 24h stats
  • Kill / block suspicious process path
  • False-positive mark workflow with audit trail
Quarantine inventory console

Quarantine + restore

Contained files land in inventory. Restore from the console when a sample is a false positive — not a ticket black hole.

  • Quarantine folder on the endpoint
  • Console inventory API + restore command
  • Operator-visible evidence, not silent drop
Host network isolate concept

Host network isolate

Cut lateral movement while keeping management paths alive — DNS and Guard/API hosts stay on the allow-list.

  • Network isolate + release
  • Desk contain: isolate + USB deny + workstation lock
  • Cloud contain on high-severity detect / canary / piracy
Ransomware canary decoys

Ransomware canaries

Local decoys trip before encryption runs wild — including offline desks where cloud hunting never sees the first write.

  • Offline-capable canaries
  • Kill + isolate response path
  • Local process watch + blocklist seam
USB mass storage deny

USB & attack surface

Removable storage deny pairs with Defender ASR for script and Office macro control — desk lockdown when risk appears.

  • USB / mass-storage deny (Aegis One MDM plane when licensed)
  • Script / macro control via Defender ASR
  • Sensor tamper resist (TamperProtect + Guard registry)
On-demand Defender scan

Scan · integrity · prove

On-demand Defender scan from the console. Software integrity alarms for crack tools and unsigned installers from Downloads/Temp/Desktop — full path on the threat row.

  • ProtectScanNow → Defender quick scan
  • Piracy-tool block + unsigned installer alarms
  • Live protect score (evidence-based, target 9.5/10)

Full list

Security capabilities

Compact map of what buyers ask for. Deep table on the features page.

NGAV / malware prevent

Defender realtime protection + Attack Surface Reduction.

Ransomware response

Canaries · kill · isolate — including offline desks.

Detect + alert console

Guard portal stats, recent events, live score.

Kill process

Agent kill path for suspicious processes.

Quarantine + restore

Inventory API and restore command in console.

Host network isolate

Allow-list DNS + management HTTPS while cut off.

On-demand scan

Defender-backed quick scan from the operator desk.

USB / device control

Mass-storage deny via Aegis One MDM when licensed.

Script / macro control

Defender ASR policy evidence and enforcement.

Sensor tamper resist

TamperProtect + Guard registry hardening.

False-positive workflow

Mark FP in console with audit trail.

Software integrity

Crack/keygen block; unsigned installer path alarms.

Honest scope

What we claim — and what we don’t

Falcon Go–class desk controls. Defender is the detection engine. No Threat Graph theater.

Run the protect console

Same SKU. Same API. Operator desk at /console/.

Open console All features