MITRAL · i-ASM

See every endpoint. Stop threats in seconds.

A SIEM with built-in active response, protecting every agent in your network.

Server
Windows
Cloud
Container
macOS
Linux
Threat blocked
248agents online

Some of the organizations that we had the pleasure to work with

Detect. Respond. Prove.

01

Detect

Correlate events from every agent, mapped to MITRE ATT&CK.

02

Respond

Block, kill or isolate automatically, in seconds.

03

Prove

Every alert and response logged for your audits.

EVERYWHERE YOUR AGENTS RUN
Windows
Linux
macOS
Cloud
Containers
Kubernetes
Microsoft 365
Servers

Every agent. One dashboard.

Agents online 248
Events (24h) 1.2M
High-severity alerts 37
Auto-responses 12
Alerts over time
Top MITRE ATT&CK tactics
Credential Access
Execution
Persistence
Privilege Escalation
Agents
web-prod-02 14 alerts
win-fin-14 9 alerts
db-prod-01 5 alerts
mac-dev-07 3 alerts
k8s-node-3 1 alert
dc-01 0 alerts

Everything your SOC needs

From the first event to the last response.

SSH brute forceT1110
Encoded PowerShellT1059
Scheduled task addedT1053

Threat detection

Every alert mapped to MITRE ATT&CK.

Isolate host

Active response

Contain threats on the agent, automatically.

/etc/ssh/sshd_config- PermitRootLogin no+ PermitRootLogin yes PasswordAuthentication no+ AllowUsers backdoor

File integrity monitoring

Know who changed what, and when.

8.1CVE-2024-6387
10.0CVE-2024-3094
8.8CVE-2023-4863

Vulnerability detection

Known CVEs on every agent, prioritized.

81%
156 passed37 failedCIS benchmark

Configuration assessment

Hardening checks against CIS benchmarks.

Malware & rootkit detection

Catch hidden processes and malicious files.

Log data analysis Cloud workload monitoring Container security Threat intelligence Custom detection rules System inventory

Inside the Mitral stack

Outside exposure, inside activity, tested and proven.

e-ASMExposed assets
i-ASMActivity & response
PTaaSFindings & retests
GRCEvidence & reports

Mapped to the frameworks you're audited on

PCI DSS
GDPR
HIPAA
NIST 800-53
SOC 2

Deploy your first agent in minutes

Windows, Linux or macOS. One command, full visibility.

Book a Demo

Frequently asked questions

Which operating systems are supported?

Agents run on Windows, Linux and macOS. The platform also monitors cloud services, containers and network devices through log collection.

Will the agent slow down my systems?

No. The agent is lightweight and built to run continuously on production servers and workstations.

What can active response do?

Block IP addresses, kill processes, isolate hosts, disable accounts or run custom scripts. Each response is set per rule, severity and agent group, and can run automatically or alert only.

How is i-ASM different from e-ASM?

e-ASM finds what is exposed on the internet. i-ASM watches what happens inside your environment, on every agent. Together they cover both sides of your attack surface.

Does it help with compliance?

Yes. Alerts and checks map to PCI DSS, GDPR, HIPAA, NIST 800-53 and SOC 2, and feed Mitral GRC as audit evidence.

Can you manage it for us?

Yes. Our team can help with deployment, rule tuning and ongoing monitoring.