113
Behavioural endpoint defence, engineered by 113SEC. It reads what a process does — not just what it is — and stops ransomware, credential theft and living-off-the-land attacks that signature antivirus never sees.
113EDR is an endpoint detection and response agent for Windows. Instead of matching files against a signature list, it watches process behaviour, network calls, memory access and file activity in real time — and can kill, quarantine or isolate on its own when an attack is unambiguous.
It does not replace Microsoft Defender. It sits above it: Defender blocks known-bad at the kernel, 113EDR adds the behavioural detection, the correlation and the reflexes — and streams every verdict to the same console we watch your fleet on.
FIVE LAYERS,
ONE · AGENT
An intrusion is a sequence, not a single event. 113EDR watches it at every stage it passes through — so a step missed at one layer is caught at the next.
Blacklisted IPs and domains, high-entropy DGA lookups, LOLBin outbound connections and port scans — watched at the wire, before a payload lands.
DNS · C2Canary files under continuous integrity polling and a bulk-encryption detector catch ransomware the moment it starts rewriting your data — not after.
RANSOMWARE23 behavioural rules mapped to MITRE ATT&CK: Office spawning a shell, encoded PowerShell, mshta / regsvr32 / certutil, shadow-copy deletion, log clearing.
BEHAVIOURLSASS credential access and process injection — the quiet middle of an intrusion, where an attacker steals the keys to move sideways.
CREDENTIALSKill, quarantine or isolate — automatically when the verdict is certain, behind a human checkpoint when it is not. Isolation keeps management channels alive, so you never lose the box.
SOARSIX
ENGINES & AT WORK
- 01Process Behaviour
The core engine. Sysmon events read continuously against 23 rules — encoded commands, LOLBins, shadow-copy wipes and log clearing all raise a verdict, whatever binary they hide behind.
- 02Ransomware Shield
Canary integrity polling plus a PID-aware bulk-encryption detector. Three encrypted files is enough — the process is killed, and most of your data survives.
- 03Network
DGA and high-entropy DNS, blacklisted destinations, unexpected LOLBin egress and port-scan behaviour — command-and-control caught before it settles in.
- 04Identity & Memory
LSASS credential-dumping and process injection detection — the techniques attackers use to escalate and spread once they are inside.
- 05Persistence
Registry Run-key and autostart tampering — the footholds malware plants to survive a reboot — flagged as they are written.
- 06YARA & Hash
1.13 million known-malware hashes checked on execution, plus YARA rules for known families — with automatic quarantine on a match.
A RANSOMWARE
IT HAD · NEVER SEEN
We wrote a brand-new ransomware strain — present in no signature database and no hash list — and released it on a live machine. 113EDR had nothing to match it against.
It caught it anyway. On behaviour alone, it saw the bulk encryption start, killed the process mid-run, and recovered most of the files. Signature antivirus would have watched the whole disk go.
That is the line between antivirus and EDR: one knows yesterday's malware, the other reads what is happening right now.
A BRAIN ON
TOP OF · THE KERNEL
Microsoft Defender already blocks known-bad at the kernel. 113EDR is the layer above it — the part that thinks and the part that acts.
As part of the install we also harden Defender's own defences: thirteen Attack Surface Reduction rules and Controlled Folder Access, so some techniques never even start. You keep Defender. You gain sight and reflexes.
And it is managed. We tune the rules; you get the verdicts. Every detection streams to the same 113SEC console you watch your fleet on — and to the Windows Event Log, so your SIEM sees it too. No black boxes.
More context: our managed security service · the stack we run · what a 24/7 SOC does.
PUT IT ON YOUR ENDPOINTS"SIGNATURES KNOW YESTERDAY'S MALWARE. BEHAVIOUR CATCHES TODAY'S."
FREQUENTLY
ASKED · QUESTIONS
- 01What is 113EDR?
113EDR is 113SEC's endpoint detection and response agent for Windows. It watches process behaviour, network calls, memory access and file activity in real time, and can kill, quarantine or isolate a threat on its own.
- 02How is it different from antivirus?
Antivirus asks whether it has seen a file before. 113EDR asks what a process is doing. That is why it catches new ransomware and attacks that abuse legitimate tools, which signature antivirus misses.
- 03Do we still keep Microsoft Defender?
Yes. 113EDR runs above Defender, not instead of it. Defender blocks known-bad at the kernel; 113EDR adds behavioural detection, correlation and response, and manages both from one place.
- 04Will it stop ransomware we have never seen?
That is what it is built for. In testing, a brand-new strain present in no signature database and no hash list was caught on behaviour alone, killed mid-run, and most of the files were recovered.
- 05Does it slow machines down or need a reboot?
The agent is light and listens only on the local loopback address, with no open network port. Installation does not require a reboot.
- 06Is it managed, or do we run it?
It is managed by 113SEC. We tune the rules and watch the verdicts; every detection also appears in your own console and the Windows Event Log, so nothing is a black box.