ENDPOINT SECURITY · OLLANDI DIP

Monitor endpoint processes, users, files, software changes, connections, and device health in wider infrastructure context.

Specialized endpoint security that contributes live evidence and domain actions to Ollandi’s cross-domain defense loop.

Compare all DIPs

From domain telemetry to a decision operators can use.

01 · MONITORS
  • Process and parent-child execution
  • User sessions and privilege
  • Files, persistence, and configuration changes
  • Software lineage and network connections
02 · DETECTS
  • Suspicious execution and persistence
  • Credential or session misuse on a host
  • Unexpected software or configuration drift
  • Endpoint behavior linked to wider attack activity
03 · EXPLAINS
  • Who initiated the process and from which session
  • Whether software and behavior are expected
  • Which services, identities, and destinations are connected
  • The smallest safe containment scope
04 · ENABLES RESPONSE
  • Preserve host and process evidence
  • Restrict a process or connection
  • Revoke suspicious sessions
  • Isolate a device within approved bounds
COVERAGE

The context this DIP brings into Ollandi.

The DIP normalizes domain evidence with source and time preserved. Ollandi then relates it to other DIPs, service dependencies, policy, authority, and historical state.

  • Endpoint and process telemetry
  • User and session records
  • File and configuration changes
  • Software inventory and lineage
  • Network destinations
  • Asset ownership and service context
ENDPOINT DIPHost behavior chain
MANAGED DEVICE
User session
Process created
File changed
External path
Connected to shared infrastructure context

See how the Endpoint DIP moves from signal to verified outcome.

01Observe

A managed endpoint launches an unusual process after a software change.

02Interpret

Ollandi compares software lineage, user session, file changes, network activity, and neighboring devices.

03Contain

Process, connection, session, or device-level action is selected according to confidence and policy.

04Verify

Device health and connected service state are confirmed after action.

The DIP supplies depth. Ollandi supplies the shared state, threat reasoning, action validation, and evidence.

Domain stateCross-domain hypothesisPolicy-checked actionVerified evidence
See the complete Ollandi lifecycle