Everything in WatchTower AI
Detection
- Tiered EDR: Microsoft Defender for Endpoint, native OS tooling, or our heuristic engine
- 12 MITRE ATT&CK rule families covering encoded PowerShell, LOLBINs, ransomware, lateral movement, persistence
- YARA scanning with graceful fallback
- Threat-intel auto-enrichment via VirusTotal, AbuseIPDB, AlienVault OTX (your keys, your bill)
- Behavioural detection engine for anomalous activity
- Customer-defined custom rules: regex, keyword, or threshold
Response & SOAR
- Declarative SOAR-lite playbooks: ransomware, credential dump, critical-by-default
- One-click host isolation, lock, kill-process, file quarantine
- Volume Shadow Copy rollback (Windows)
- USB mass-storage block / unblock policy
- Ransomware canaries with auto-isolation on first touch
Visibility
- Kill-chain stories: every alert in a 60-minute window stitched into a single MITRE timeline
- Persistent foothold hunter: Run keys, scheduled tasks, services, WMI subscriptions, LaunchAgents, cron, systemd
- LAN discovery to find unmanaged hosts
- Application inventory + vulnerability scanner against a curated CVE feed
- Threat hunting DSL with saved queries
Integration
- HMAC-SHA256 signed outbound webhooks with retry + delivery log
- Scoped REST API at
/api/v1/* with Argon2id-hashed keys
- M365 ITDR for risky sign-ins, risky users, OAuth grants
- PSA ticketing for Halo, ConnectWise, Autotask
- OIDC SSO (Azure AD, Okta, Google Workspace)
- Prometheus
/metrics endpoint
Compliance
- UK GDPR self-service data export and audited delete-request workflow
- Append-only, hash-chained audit log
- Encrypted secrets at rest (Fernet)
- Cyber-insurance evidence-pack export per kill-chain story