Platform capability

Operational

Endpoint detection and response across servers and workstations

Agent-based visibility into process execution, persistence, configuration drift and vulnerability state on every monitored host.

Overview

Antivirus answers one question: does this file match something already known to be bad. That is a useful question and an insufficient one. Modern intrusions increasingly use tooling that is already present and already signed - PowerShell, WMI, remote management utilities, legitimate administrative credentials.

Vanguard deploys a lightweight agent to each server and workstation and reports on behaviour rather than signatures alone: what process spawned what, under which account, with what command line, reaching which destination.

On Windows estates we ingest full process-creation telemetry, because without it process lineage is largely invisible. On Linux we use a curated kernel audit ruleset covering execution, privilege escalation and access to sensitive paths, tuned before it is enabled broadly rather than after it has buried the alert stream.

What this identifies

  • Credential dumping and LSASS access attempts
  • Ransomware precursors: shadow-copy deletion and mass file rename
  • Unsigned or unusual binaries executing from user-writable paths
  • New persistence mechanisms appearing on a monitored host
  • Endpoint agents going silent or being stopped

Delivery status: Operational - deployed and in production service.

Capabilities

What endpoint detection & response does

  • Process lineage and command-line capture

    See the full parent-child chain behind a suspicious execution, not just the process name.

  • Security configuration assessment

    Hosts are assessed against CIS benchmarks on a schedule, with the score trend reported per environment each month.

  • Malware and rootkit checks

    Scheduled integrity and rootkit checks, with every finding treated as real until it has been disproven.

  • Contained active response

    Automated responses use short, auto-expiring blocks rather than permanent ones, so a false positive degrades gracefully instead of taking a business offline.

  • Per-host vulnerability state

    Installed package inventory is matched continuously against vulnerability data for that specific host.

Under the hood

The engineering underneath

How this capability is actually engineered and operated. The specific detection tooling behind the security operations centre is shared with customers under agreement rather than published, for the same reason you would not publish yours.

  • Agents are registered into one group per organisation, so the tenant key flows into every alert it produces.
  • Process lineage telemetry on Windows and a curated kernel audit ruleset on Linux, both tuned before broad rollout rather than after.
  • Automated blocking is short-lived and auto-expiring by design.
  • Agent health is itself monitored: a stopped agent raises an alert rather than silently reducing coverage.

The full platform architecture is documented on the architecture page.

Services

Services delivered on this capability

The platform provides the capability. These are the engagements in which Tech49Originals operates it on your behalf.

  • Operational

    Managed SOC

    A staffed security operations centre in Windhoek monitoring your endpoints, servers and network around the clock, so you do not have to build one.

    Explore
  • Operational

    SIEM-as-a-Service

    A fully operated SIEM for Namibian organisations, covering collection, retention, correlation and detection, without the infrastructure cost of running one yourself.

    Explore
  • Operational

    Security Monitoring

    An entry-level monitored service for smaller Namibian organisations: continuous detection, alerting and monthly reporting, without a full SOC engagement.

    Explore

Related

  • Operational

    SIEM & XDR

    Collects security telemetry from servers, endpoints, network devices and cloud workloads into one correlated detection engine.

    Explore
  • Operational

    Vulnerability Management

    Continuous assessment of operating system packages and application dependencies, prioritised by exploitability and exposure rather than raw severity score.

    Explore
  • Operational

    File Integrity & Configuration

    Detects unauthorised change to critical files, configuration and binaries - one of the highest-signal, lowest-noise detections available.

    Explore

Get started

Find out what is actually happening on your network

A short conversation is usually enough to establish whether monitoring would tell you something you do not already know. There is no obligation and no sales script.