ClearSkies Endpoint Threat Monitoring and Response

Inside the Platform

The add-ons do not exchange intelligence directly with one another.

  • One engine

    Every add-on connects to the engine, none to another

  • Bidirectional

    Verdicts go in, detection outcomes come back

  • Built for providers

    Row-level isolation, per-tier gating, per-tenant quotas

What ETMR contributes

ETMR is one of the six native add-ons of ClearSkies iISOC, deployed with the platform and reporting to the TDIR engine, the orchestration core through which every add-on connects.

Each connects to the engine, which ingests through iCollector, normalizes, correlates and redistributes the result across the platform.

ETMR and five other ClearSkies add-ons each connect to the ClearSkies iISOC TDIR engine.

Every add-on connects to the engine. None connects to another.

The signal no other layer can see

The endpoint is where an intrusion becomes concrete. No other layer can see a process spawning a child process, a script writing an executable to a temporary path, or a credential store being read from memory.

ContextWhat the analyst receives
Without endpoint contextAn outbound connection from a host is a moderate signal.
With endpoint contextThe same alert, annotated with a PowerShell process spawned by a macro-enabled document that wrote an executable to a temporary path and then beaconed at a fixed interval, is a high-fidelity incident an analyst can prioritize immediately.

That is the signal ETMR contributes: continuous endpoint telemetry, the behavioral verdicts derived from it, and the evidence behind each verdict.

Working with the other add-ons

ETMR never acts on another add-on’s intelligence. When it reports an endpoint-behavior verdict, the engine sharpens that verdict against the other signals it holds.

  • Attack Surface Monitoring

    tells the engine whether the affected host also carries a known external exposure, so a detection on an internet-facing asset is escalated faster.

  • Identity Threat Protection

    supplies the identity context, which turns a process that ran into a compromised user who ran a process.

  • DNS Shield

    contributes the resolution-layer verdict on any domain the endpoint tried to reach, confirming command-and-control intent.

The engine combines those signals into one picture and drives Active Defense to execute a coordinated response.

The integration is bidirectional

The exchange runs both ways, which is what makes the endpoint part of one system rather than a separate product that happens to send alerts.

ETMR to the engine. Process lineage, file and registry events, user activity and network connections, both as enrichment on existing detections and as detections in their own right, such as a credential-theft attempt or a living-off-the-land execution.

The engine to ETMR. Detection outcomes flow back to the agent. A host under investigation can be isolated automatically, a confirmed-malicious hash or behavior is distributed to every agent as detection content rather than customer data, and an analyst false-positive mark suppresses the noise that produced it.

ClearSkies iISOC endpoint view: ETMR verdicts, correlated detections and containment status

A single endpoint event is enriched by every other layer and, in turn, sharpens them.

Governance and evidence

Endpoint evidence is reported against the frameworks the Regulatory Frameworks core function catalogues, including NIST CSF, ISO 27001, NIS2 and DORA.

Regulatory Frameworks

Delivering ETMR as a managed service

Multi-tenancy is a first-class concern at every layer, with row-level isolation, per-tier feature gating and per-tenant quotas, so a provider delivers ETMR across many customers from a single deployment. The tenant-pool model scales economics with the customer base rather than licensing one customer at a time.

  • One cross-tenant console for endpoint status, alerts and containment actions.
  • White-label reporting, so the service carries each customer’s identity.
  • Audit-ready reporting built in, for compliance and for the board.
  • Behavioral detection absorbs the high-volume work, so analyst time goes to judgment.
ClearSkies iISOC for service providers
Delivering ETMR as a managed service

See the whole endpoint, not just the malware.

Because ETMR reports to the engine rather than acting laterally, the same endpoint verdict is reused across every correlation instead of being derived again in each tool.

Request a Demo
ETMR platform dashboard