EDR Agent · Endpoint module

Every machine protected,
every action traced.

A sovereign EDR agent for Windows, macOS and Linux. Detects, prevents and responds right on the machine — 9 MB of RAM, zero foreign cloud dependency.

Windows · macOS · Linux9 MB RAMETW + YARA + SigmaActive Response
9 MB
of RAM per agent
< 200 ms
pour tuer un process
125 000
embedded YARA rules

The agent sees everything happening on the machine: process execution, file access, DLL loading, registry, network, DLP operations. It detects malicious patterns locally — without waiting for the SOC — including ransomware, exfiltration, lateral movement and persistence, and can block, isolate or kill the process. The SOC watches in real time and drives the agent remotely through signed commands.

How it works

From threat to evidence, in real time.

The module captures the signal, SYLink AI correlates it and decides — you keep control.

Workstation
Processes, files, network
EDR agent
Local detection (9 MB)
SYLink AI
Rebuilds the kill chain
Isolation / kill
< 200 ms
In the portal

From the whole estate down to a single machine.

The same console gives you the overall posture, the agent fleet, then hands-on control of one specific machine.

01

Posture of machines and servers

console.unisoc.fr/endpoint
Posture of machines and servers
Threats handled, behavioural Sigma rules, YARA signature rules, events analysed — figures reported by the machines themselves.
02

The agent fleet

console.unisoc.fr/edr
The agent fleet
Windows, macOS and Linux in one list: agent version, status, last check-in, event volume over 24 h.
03

Remote control & RMM actions

console.unisoc.fr/edr
Remote control & RMM actions
Signed script, file retrieval, hardware inventory: every action is graded by risk level and logged on the SOC side.
04

The agent, on the machine

SYLink EDR Agent — local host
The agent, on the machine
The agent carries its own console: collection services, threats, quarantine, DLLs, DLP, RMM.
05

The detection engines on board

SYLink EDR Agent — local host
The detection engines on board
Behavioural Sigma rules and YARA signatures (APT families), synchronised from the SOC.

Real screenshots of the UniSOC portal. The data shown comes from a demonstration environment.

Detection engines

Several engines, one agent.

Where others stack products, SYLink EDR combines every engine in a single 9 MB agent — correlated by the AI.

Behavioural (ETW)

Every process, thread and system call analysed in real time.

Anti-ransomware

Canary files plus OS heuristics (encryption speed) → killed in under 200 ms.

YARA · 125,000 rules

Memory and file signatures, updated every three hours.

Sigma · behavioural

3,200 cross-platform detection rules.

DLL Sideloading

Detects side-loading of hijacked legitimate DLLs.

SYLink AI

Correlates every engine, qualifies and decides — the verdict in plain language.

Anti-ransomware

Blocked — and your files recovered.

The ransomware is stopped dead by the decoys and the heuristics. But SYLink EDR goes further: it automatically restores the files already hit (rollback). Zero loss, zero ransom.

client.unisoc.fr/edr/incident
Ransomware detected · PC-FINANCE-04 · 14:32:07
14:32:07Anomalous encryption · 340 files/sdetected
14:32:07The ransom.exe process killedstopped
14:32:08Machine isolated from the networkisolated
14:32:11340 files restored (rollback)restored
Resolved in4 secondes· zero files lost · zero ransom
Paid edition · fleet management

Stop merely detecting. Start fixing.

On subscription, SYLink EDR drives your entire fleet from a single console — a match for the best (Cyberwatch, HarfangLab), and sovereign.

client.unisoc.fr/edr/parc
1 284
machines managed
6
Critical CVEs
3
policies actives
Patches to deploy
CVE-2024-21413Microsoft Exchange12 postesDeploy
CVE-2024-3400PAN-OS47 postesDeploy
CVE-2023-34362MOVEit8 postesDeploy
Patch management

Deploy Windows and Linux patches from the console — compatible with WSUS and Red Hat Satellite. The SOC prioritises what is actively exploited (KEV).

Centralised control

Bulk actions across the whole estate: isolation, updates, forensic collection, policies per group — one click, any number of machines.

Compliance & hardening

Hardening checks (CIS), NIS2/DORA reports per estate, a full inventory with history.

Driven by SYLink AI

The AI prioritises patches by real risk and proposes the rollout plan — you approve it.

Download

Ready to protect your machines?

The SYLink EDR agent for Windows, macOS and Linux — lightweight, signed, deployable at scale (GPO, MDM, Ansible).

Download the EDR agentWindows · macOS · Linux · v2.0.5
Capabilities

The technology, in detail.

What the module actually does — functions, not promises.

Endpoint visibility

  • ETW: process, image load, file, registry, network
  • Sysmon-equivalent, built in (nothing to install)
  • macOS Endpoint Security + Unified Log
  • Linux: auditd + eBPF + inotify
  • SHA-256 hash and signature of every executable

Detection

  • YARA: 125,000 rules (tiered prevent / detect / analyse)
  • Sigma: 3,200 rules converted automatically
  • 21 MITRE ATT&CK workers (LotL, persistence, kill-chain)
  • 50-feature ML model: a real-time risk score
  • C2 beacons, UEBA and tampering detection (AMSI/ETW)

Built-in DLP

  • 11 patterns: email, IBAN, card number, national ID, AWS keys, JWT, PEM…
  • USB DLP: per-tenant allowlist, automatic quarantine
  • Network DLP: file-sharing and webmail blocking, plus anti-DoH
  • Blocking at the moment of copy — not merely detection
  • Full NIS2 art. 21 / GDPR audit

Active Response

  • File quarantine (move + ACL deny)
  • Process kill with forensic evidence (optional memory dump)
  • Network isolation (temporary allowlist)
  • TCP reset on suspicious outbound connections
  • Restore through a signed SOC admin command

SYLink AI driven

  • Automatic alert triage (4.2% hallucination)
  • Recommended actions: isolate / patch / watch
  • Automatic MITRE kill chain reconstruction
  • Local AI — no CrowdStrike or SentinelOne cloud
  • Mandatory human review (DORA audit art. 28)

Lightweight & robust

  • 9 MB of RAM (Rust)
  • 60-second heartbeat, commands polled every 5 min
  • Auto-update through signed .msi / .deb / .pkg packages
  • Self-healing: tampering detection plus automatic restart
  • A dedicated or unified licence per tenant
Use cases

What is it actually for?

Stop ransomware before encryption

The tier-1 YARA rules recognise the Conti / LockBit / BlackCat signature before any file is touched. Process killed and machine isolated in under 200 ms.

Block data exfiltration

Uploading client_accounts.xlsx to a personal Drive: the DLP IBAN pattern matches → upload blocked, SOC alerted, audit trail signed.

Detect lateral movement

An admin account signs into 12 machines in five minutes over PsExec. The model flags the pattern, the AI correlates it with the DPI data, and the SOC gets a critical alert.

ANSSI + DORA compliance

The EDR feeds NIS2 and DORA reports with signed events (chained HMAC). An auditor can replay each chain and check its integrity.

The method, in four steps
From raw signal to defensible evidence.
Detect
Understand
Decide
Prove
01The module captures the raw signal — traffic, behaviour or indicator.signal captured
Specifications
Memory footprint9 MB (Rust, idle)
Supported operating systemsWindows 10/11, Server 2016+, macOS 12+, Linux
Heartbeat60 s bidirectionnel
CommandsPolled every 5 min (HMAC-signed by the SOC)
YARA / Sigma125,000 / 3,200 rules
Process kill latency< 200 ms after detection
Cloud egressNone — everything goes to your SOC
DeploymentLocal agent · on your machines
Natively integrated with
SYLink AI — triage + kill-chain
DPI sensor — endpoint × network correlation
Mobile XDR — phone and tablet extension
HoneyPot — lateral attempts
Compliance module — NIS2 / DORA
Sovereign

Driven by SYLink AI, hosted 100% in France (HDS v2), with no Cloud Act exposure. Every decision is logged and defensible under NIS2 and DORA.

Live in under 48 hours

Ready to see what is really
happening on your network?

First trial free, no credit card, no commitment. On your existing infrastructure.

Cookie settings

We use cookies to improve your experience on our site. By continuing to browse, you accept our privacy policy and our use of cookies under the GDPR.