- Process and parent-child execution
- User sessions and privilege
- Files, persistence, and configuration changes
- Software lineage and network connections
ENDPOINT SECURITY · OLLANDI DIP
Monitor endpoint processes, users, files, software changes, connections, and device health in wider infrastructure context.
Specialized endpoint security that contributes live evidence and domain actions to Ollandi’s cross-domain defense loop.
WHAT THE ENDPOINT DIP DOES
From domain telemetry to a decision operators can use.
- Suspicious execution and persistence
- Credential or session misuse on a host
- Unexpected software or configuration drift
- Endpoint behavior linked to wider attack activity
- Who initiated the process and from which session
- Whether software and behavior are expected
- Which services, identities, and destinations are connected
- The smallest safe containment scope
- Preserve host and process evidence
- Restrict a process or connection
- Revoke suspicious sessions
- Isolate a device within approved bounds
COVERAGE
The context this DIP brings into Ollandi.
The DIP normalizes domain evidence with source and time preserved. Ollandi then relates it to other DIPs, service dependencies, policy, authority, and historical state.
- Endpoint and process telemetry
- User and session records
- File and configuration changes
- Software inventory and lineage
- Network destinations
- Asset ownership and service context
MANAGED DEVICE
User session
Process created
File changed
External path
ONE INCIDENT · COMPLETE LOOP
See how the Endpoint DIP moves from signal to verified outcome.
A managed endpoint launches an unusual process after a software change.
Ollandi compares software lineage, user session, file changes, network activity, and neighboring devices.
Process, connection, session, or device-level action is selected according to confidence and policy.
Device health and connected service state are confirmed after action.
PART OF OLLANDI - NOT ANOTHER SILO
The DIP supplies depth. Ollandi supplies the shared state, threat reasoning, action validation, and evidence.
Domain state→Cross-domain hypothesis→Policy-checked action→Verified evidence
See the complete Ollandi lifecycle