ClearSkies Endpoint Threat Monitoring and Response

How the agent reaches a verdict

Detection accuracy is what separates a high-signal endpoint program from a noise machine.

  • Several detection sources

    Evaluated in parallel and combined into a single verdict

  • Four confidence bands

    Confirmed, Likely, Suspicious and Benign

  • Inline containment

    Action gated by confidence band

Multi-signal verification

ETMR turns the endpoint from passive plumbing into an active detection and response control point. It continuously records process, file, user and network behavior, evaluates that behavior against threat intelligence and behavioral models rather than signatures alone, contains threats automatically when confidence is high, and preserves the full record of the activity.

A single false-positive kill of a business-critical process erodes trust faster than ten true containments build it. So rather than acting on any one signal, ETMR evaluates endpoint behavior across several independent detection sources in parallel and combines their weighted contributions into a single verdict.

ETMR signals converging into a weighted verdict, confidence band and reporting to the TDIR engine.

What the agent observes, how the verdict is banded, and the exchange with the TDIR engine.

The confidence bands

The band a verdict falls into decides what the agent is permitted to do about it. Enforcement is proportionate by design: the higher the certainty, the more the agent acts without waiting.

Confidence bandActionWhat happens
ConfirmedContained inlineThe process is killed or the host is isolated, an alert fires, and the event is reported to the TDIR engine and to your own SIEM where one is connected.
LikelyContained or flaggedContained or flagged according to tenant policy, and surfaced for analyst confirmation.
SuspiciousAlert onlyLogged and alerted for review by default. No enforcement unless policy escalates it.
BenignAllowedAllowed to run, and logged for traceability and behavioral baselining.

How accuracy improves

Analyst verdicts are fed back into the detection engine. A behavior confirmed as malicious in one tenant is distributed to every agent as detection content, never as customer data. A false-positive mark suppresses recurring noise, and behavioral baselines retrain on each tenant’s own endpoints.

Accuracy improves with every analyst decision, without manual tuning.

Automated response and containment

Detection only matters if something happens next. ETMR acts inline, so a threat is stopped at machine speed rather than waiting in a queue for an available analyst.

  • Features

    • Inline process termination, file quarantine and host isolation.
    • Action gated by confidence band.
    • Every action logged with its full sequence for audit.
  • Benefits

    • Threats are contained in seconds, not at the next shift handover.
    • Blast radius is limited to the first endpoint.
    • Containment is auditable for the board and for regulators.

In action: from a trusted process to a contained incident

The sequence below is illustrative. It shows how the agent and the platform work together, and is not an account of a specific customer incident.

  1. 01

    On the endpoint

    A user opens a macro-enabled attachment.

    Word spawns PowerShell, which writes an executable to a temporary path and begins encrypting files.

    No known-bad signature is involved.

  2. 02

    The agent acts

    ETMR recognizes the process lineage, the anomalous child process and the rapid file-modification pattern together, classifies the behavior as ransomware, and kills the process and isolates the host inline.

  3. 03

    In the platform

    The verdict reaches the TDIR engine, where it meets the phishing context from Identity Threat Protection and the newly registered domain verdict from DNS Shield, correlating into one high-fidelity incident.

    The engine drives Active Defense, and a playbook contains the incident in seconds, with the full sequence recorded for audit.

Two further cases

  • A stolen session token

    A process uses a stolen token to enumerate network shares and attempt remote execution against a domain controller, with no malware file involved. ETMR classifies the behavior, kills the process and isolates the host. Identity Threat Protection has already reported the same user’s credentials in a fresh information-stealer log, and the engine correlates the two into one account-compromise incident.

  • A living-off-the-land script

    A scheduled task launches an obfuscated PowerShell script that uses only trusted, signed Windows tools to stage data for exfiltration. ETMR recognizes the anomalous command-line patterns and the parent-child process chain, bands the verdict as high confidence and contains the host. The engine correlates it with the DNS Shield verdict on the destination domain.

Getting to protective coverage

  1. Onboarding and scoping

    Authorizing endpoint scopes, rolling out the agent, and setting the baseline detection and exclusion policy before enforcement is turned up.

  2. Integration

    Connecting ETMR to the TDIR engine and to your own SIEM, SOAR and collaboration tools for alerting and response.

  3. Enablement and training

    Role-based tracks on policy management, the confidence-band model and the containment and reporting workflow.

  4. Ongoing optimization

    Periodic review of policy effectiveness, false-positive rates and service-level performance as the estate changes.

ETMR is delivered with a professional-services wrap, so you reach policy-governed coverage quickly rather than being handed an agent to configure.

Technical Questions

What does ETMR see that a signature-first product does not?

Behavior. Fileless and living-off-the-land activity that never drops a recognizable file, credential theft from process memory, beaconing from an unexpected process, and rapid file modification characteristic of ransomware.

What stops the two agents from interfering with each other?

Onboarding establishes the baseline detection and exclusion policy for both agents before ETMR enforcement is turned up, which is part of the professional-services wrap above.

Does ETMR act on what the other add-ons find?

Not directly. The add-ons do not exchange intelligence with one another. Every signal routes through the TDIR engine, which correlates it and returns the resulting detection outcomes to ETMR, so the agent acts on a correlated picture rather than on another product’s raw finding.

See the whole endpoint, not just the malware.

No single signal produces a confirmed-malicious verdict by itself.

Request a Demo