113SEC  —  113EDR
X000Y000
[113SEC]TR
SUPPORT
NEW · ENDPOINT DEFENCE

113

Behavioural endpoint defence, engineered by 113SEC. It reads what a process does — not just what it is — and stops ransomware, credential theft and living-off-the-land attacks that signature antivirus never sees.

LAYERS5
ENGINES6
MITREMAPPED
RESPONSEAUTONOMOUS

113EDR is an endpoint detection and response agent for Windows. Instead of matching files against a signature list, it watches process behaviour, network calls, memory access and file activity in real time — and can kill, quarantine or isolate on its own when an attack is unambiguous.

It does not replace Microsoft Defender. It sits above it: Defender blocks known-bad at the kernel, 113EDR adds the behavioural detection, the correlation and the reflexes — and streams every verdict to the same console we watch your fleet on.

FIVE LAYERS,
ONE · AGENT

An intrusion is a sequence, not a single event. 113EDR watches it at every stage it passes through — so a step missed at one layer is caught at the next.

01Network

Blacklisted IPs and domains, high-entropy DGA lookups, LOLBin outbound connections and port scans — watched at the wire, before a payload lands.

DNS · C2
02File

Canary files under continuous integrity polling and a bulk-encryption detector catch ransomware the moment it starts rewriting your data — not after.

RANSOMWARE
03Process

23 behavioural rules mapped to MITRE ATT&CK: Office spawning a shell, encoded PowerShell, mshta / regsvr32 / certutil, shadow-copy deletion, log clearing.

BEHAVIOUR
04Memory

LSASS credential access and process injection — the quiet middle of an intrusion, where an attacker steals the keys to move sideways.

CREDENTIALS
05Response

Kill, quarantine or isolate — automatically when the verdict is certain, behind a human checkpoint when it is not. Isolation keeps management channels alive, so you never lose the box.

SOAR

SIX
ENGINES & AT WORK

  • 01
    Process Behaviour

    The core engine. Sysmon events read continuously against 23 rules — encoded commands, LOLBins, shadow-copy wipes and log clearing all raise a verdict, whatever binary they hide behind.

    BEHAVIOUR
  • 02
    Ransomware Shield

    Canary integrity polling plus a PID-aware bulk-encryption detector. Three encrypted files is enough — the process is killed, and most of your data survives.

    RANSOMWARE
  • 03
    Network

    DGA and high-entropy DNS, blacklisted destinations, unexpected LOLBin egress and port-scan behaviour — command-and-control caught before it settles in.

    NETWORK
  • 04
    Identity & Memory

    LSASS credential-dumping and process injection detection — the techniques attackers use to escalate and spread once they are inside.

    CREDENTIALS
  • 05
    Persistence

    Registry Run-key and autostart tampering — the footholds malware plants to survive a reboot — flagged as they are written.

    PERSISTENCE
  • 06
    YARA & Hash

    1.13 million known-malware hashes checked on execution, plus YARA rules for known families — with automatic quarantine on a match.

    SIGNATURE
+FIG.01 — ENDPOINT TELEMETRY
BEHAVIOURAL DETECTION · RANSOMWARE SHIELD · MITRE ATT&CK · ABOVE MS DEFENDER · AUTONOMOUS RESPONSE · 1.13M HASHES · ASR HARDENING · MANAGED · 

A RANSOMWARE
IT HAD · NEVER SEEN

We wrote a brand-new ransomware strain — present in no signature database and no hash list — and released it on a live machine. 113EDR had nothing to match it against.

It caught it anyway. On behaviour alone, it saw the bulk encryption start, killed the process mid-run, and recovered most of the files. Signature antivirus would have watched the whole disk go.

That is the line between antivirus and EDR: one knows yesterday's malware, the other reads what is happening right now.

RANSOM-2RANSOM-ENCRESP-KILL
30Files targeted by the strain
70%Recovered — 21 of 30 files
0Signatures it could match
KILLProcess stopped mid-run
6Detection & prevention engines on every endpoint
23+Behavioural rules mapped to MITRE ATT&CK
1.13MKnown-malware hashes checked on execution
127.0.0.1The only address the agent listens on

A BRAIN ON
TOP OF · THE KERNEL

++FIG.02 — DEFENDER + 113EDR

Microsoft Defender already blocks known-bad at the kernel. 113EDR is the layer above it — the part that thinks and the part that acts.

As part of the install we also harden Defender's own defences: thirteen Attack Surface Reduction rules and Controlled Folder Access, so some techniques never even start. You keep Defender. You gain sight and reflexes.

And it is managed. We tune the rules; you get the verdicts. Every detection streams to the same 113SEC console you watch your fleet on — and to the Windows Event Log, so your SIEM sees it too. No black boxes.

More context: our managed security service · the stack we run · what a 24/7 SOC does.

PUT IT ON YOUR ENDPOINTS

"SIGNATURES KNOW YESTERDAY'S MALWARE. BEHAVIOUR CATCHES TODAY'S."

FREQUENTLY
ASKED · QUESTIONS

  • 01
    What is 113EDR?

    113EDR is 113SEC's endpoint detection and response agent for Windows. It watches process behaviour, network calls, memory access and file activity in real time, and can kill, quarantine or isolate a threat on its own.

  • 02
    How is it different from antivirus?

    Antivirus asks whether it has seen a file before. 113EDR asks what a process is doing. That is why it catches new ransomware and attacks that abuse legitimate tools, which signature antivirus misses.

  • 03
    Do we still keep Microsoft Defender?

    Yes. 113EDR runs above Defender, not instead of it. Defender blocks known-bad at the kernel; 113EDR adds behavioural detection, correlation and response, and manages both from one place.

  • 04
    Will it stop ransomware we have never seen?

    That is what it is built for. In testing, a brand-new strain present in no signature database and no hash list was caught on behaviour alone, killed mid-run, and most of the files were recovered.

  • 05
    Does it slow machines down or need a reboot?

    The agent is light and listens only on the local loopback address, with no open network port. Installation does not require a reboot.

  • 06
    Is it managed, or do we run it?

    It is managed by 113SEC. We tune the rules and watch the verdicts; every detection also appears in your own console and the Windows Event Log, so nothing is a black box.

PUT IT ON
YOUR ENDPOINTS

REQUEST A DEMO