Full behavior
Process, file, network, user and entity
Mapped to ATT&CK
An explicit technique identifier on every detection
Detection and hardening
Patches ranked by exploitability in the same agent
What the agent watches
It recognizes known-bad artifacts, detects the behavioral tells of fileless and living-off-the-land attacks, watches user and entity behavior, and responds inline.
Process and lineage monitoring
Every process is tracked with its parent, its children and its command line, so a trusted application spawning something it never should, such as a document launching PowerShell, stands out immediately. Lineage is preserved as evidence, so root cause is recorded rather than reconstructed.
File and integrity monitoring
Critical files, directories and registry keys are watched for the unauthorized change that signals persistence, tampering or ransomware in progress. Rapid-modification patterns are caught before the encryption run finishes.
Host network analysis
Connections are inspected at the host itself, so beaconing, tunneling and command-and-control callbacks are surfaced even when the traffic never passes a proxy and the device is working from home. Network evidence is tied to the responsible process.
User and entity behavior analytics
Each user and device is baselined, and deviations such as an unusual logon or sudden access to sensitive files are flagged. Account takeover is caught even when the credentials are valid, and the risk score contributes to the confidence band.
How it decides
what is bad
MITRE ATT&CK alignment
Endpoint activity is where the ATT&CK framework was born, so ETMR detections map onto it cleanly. Every detection carries an explicit technique identifier, attached the moment it fires, so the security operation sees endpoint activity organized the way an adversary would approach it.
- Initial Access
- Execution
- Persistence
- Defense Evasion
- Credential Access
- Discovery
- Lateral Movement
- Command and Control
- Impact
Nine capabilities map to the techniques they detect. Endpoint hardening is included separately, because it mitigates a technique rather than detecting it.
The technique mapping
| Capability | ATT&CK tactic | How ETMR helps |
|---|---|---|
| Process and lineage monitoring | Execution | Detects malicious command and scripting execution, T1059, by exposing anomalous parent-child process chains as they run. |
| Living-off-the-land detection | Defense Evasion | Flags abuse of trusted system binaries, T1218, that leave no malicious file for a signature engine to catch. |
| YARA rule matching | Defense Evasion | Identifies obfuscated, packed or repacked payloads and known attacker tooling, T1027, by matching file and memory content. |
| File and integrity monitoring | Persistence | Catches unauthorized changes to files, registry and startup locations, T1547, used to survive reboot. |
| Credential-access detection | Credential Access | Identifies credential dumping and theft, T1003, from process memory and sensitive stores. |
| Host network analysis | Command and Control | Surfaces endpoint-level beaconing and callbacks, T1071, that never traverse an inspecting proxy. |
| Ransomware behavior detection | Impact | Recognizes rapid, systematic file encryption, T1486, and contains it inline. |
| Lateral-movement detection | Lateral Movement | Detects remote-service and administrative-tool abuse, T1021, as an attacker pivots between hosts. |
| User and entity behavior analytics | Discovery | Baselines normal behavior and flags reconnaissance and account discovery, T1087, that deviates from it. |
| Endpoint hardening (mitigation) | Initial Access | Surfaces missing and recommended patches, mitigating exploitation of public-facing and client applications, T1190 and T1203. |
Mapping is scope, not an assurance of detection. Techniques exercised in a purple-team run or against MITRE Engenuity ATT&CK Evaluations are reported as demonstrated, and reporting states which applies. Coverage exports as an ATT&CK Navigator layer for prioritizing detection-engineering work.
Data protection and privacy
Endpoint monitoring collects sensitive data, so how that data is handled matters as much as what it catches. ETMR encrypts collected data in transit, applies privacy controls aligned to GDPR and comparable regimes, and allows retention and scope to be configured per tier and per tenant.
Storage, residency and the controls that govern them follow the platform’s data sovereignty controls.
Data sovereignty on ClearSkies iISOC
