MetisShield
MenuClose

Endpoints

The laptops, the file server, and someone who will call.

Managed EDR is endpoint detection and response that we operate. Software on each work computer and server reports what it sees. We tune that noise down, and a person on our team calls when something should not wait for the monthly letter.

Bundles
Essentials, Pro, and Complete
Coverage
Continuous automated monitoring, with on-call response
Price status
Proposed — pending validation of hosting and staffing cost

What we watch

  • Processes, persistence, and logons that do not look like the firm’s normal week: new scheduled tasks, new services, unusual parent processes.
  • File activity that looks like ransomware, where the agent can see the disk. Seeing it is not the same as stopping every sample.
  • A specific question across the fleet when we need one: is this binary present, is this task everywhere, did this user run this command.

What runs it

  • A Wazuh agent on each computer and server in the order. Vector carries other logs into the same OpenSearch-based index.
  • Microsoft Defender on Windows, which we manage. It is the blocking antivirus. It is not open source, and we do not substitute an open-source AV for it.
  • Sigma and YARA-X detections on that telemetry, after we have tested them.
  • Velociraptor when a case needs investigation or response on a specific machine.

What a person does

  • Reviews alerts during the published hours.
  • Answers the on-call phone for critical alerts outside those hours, best effort.
  • Recommends containment. Isolates a host only when the responsibility matrix says we may.

What you decide

  • Approve the agent, and a way to remove it.
  • Name a person who will answer when we call about a critical alert.
  • Decide, in writing, whether we may isolate a machine that a lawyer, accountant, or clinician is using.

Limits

  • A machine that is off, asleep for weeks, or stripped of the agent is not monitored.
  • Phones and tablets are not part of this service unless an order adds them.
  • We do not claim this prevents every intrusion. Defender blocks what Defender blocks. We claim monitored detection and a human response on the hours we publish.
  • We are not the help desk for printers, practice-management software, or password resets.

We are not affiliated with or endorsed by the open-source projects named on this page.

The other services

Tell us how the firm is set up.

An assessment is a conversation and a short written note. It is not a penetration test, and it is not a contract. Nothing on this site takes payment.

Book an assessment