Your AI-powered digital armor
Armadillo unifies security telemetry, deterministic detection, prevention and response, with an automated path from threat intelligence to deployable protection.







Unified cyber defense.
One platform that sees your environment, understands what is happening in it, protects it with deterministic logic, and gives analysts the actions to respond.

-
01
See
Endpoint, network, process, file, session and port telemetry from enrolled agents and sensors.
-
02
Understand
Normalize, correlate and put security activity in context, with vulnerability and threat intelligence.
-
03
Protect
Deterministic detection rules, IDS evaluation and IPS enforcement, updated through versioned bundles.
-
04
Respond
Investigation, containment and response actions, every step recorded in an audit trail.
- ≤ 5 s
- maximum observed end to end time to protection, completed reported test set. Method
- Automatic
- from new intelligence to enforced protection, no manual rule writing
- Deterministic
- explicit, versioned, auditable detection logic
- Local
- analysis on site or on in country infrastructure
One platform. Multiple security planes.
Every plane reads from and writes to the same data model, so context never crosses an integration seam.
Management plane
Security overview, hosts and health, bundles and rules, reports in PDF and CSV, notifications, users, host enrollment
Response plane
Response actions, cases, archive, agent event audit trail
Prevention plane
IPS block, drop and reject, manual and automatic IP blocks, containment through response actions
Detection plane
Deterministic rules, IDS detection path, alerts, SIEM ingestion and real time correlation
Intelligence plane
Continuous threat intelligence, vulnerability intelligence, correlation context
Visibility plane
Endpoint and host, processes, file integrity, software inventory, ports, sessions, network traffic, monitoring
From new threat to active protection
New threat intelligence, or a sufficiently detailed attack description, goes in. Validated protection comes out, deployed and enforced in your environment automatically. No vendor release cycle, no manual rule writing.
New threat intelligence
Advisories, exploit information and indicators, or a detailed attack description.

Protection engine
Produces deterministic detection and prevention rules that are validated before release and remain auditable.
Internal method shared under NDAActive protection
A new versioned rule bundle, deployed to enrolled agents and engines and enforced where policy allows.
- Automaticfrom intelligence to enforcement
- Deterministicexplicit logic, not an opaque decision
- Validatedbefore any rule is released
- Auditableevery rule versioned and traceable
Time to protection, measured end to end
≤5seconds
Maximum observed end to end time to protection across the completed reported Armadillo test set.
- Intelligence received
- Protection engine
- Bundle deployed
- Protection active
Replay of a documented benchmark. Stage positions show order, not individual durations.
Every host, in context
Every enrolled host reports agent health, rule bundle state, processes, file integrity and installed software, correlated with vulnerability intelligence. Select a host to investigate it.
Illustrative environment. Vulnerability mappings are real.
app-prod-04
Application server
- Operating system
- Linux, kernel 6.8
- IP address
- 10.20.2.14
- Agent
- Healthy
- Rule bundle
- Current
- Last seen
- 4 s ago
- IPS policy
- Enabled
- 1Open cases
- 1Exposures
- 2File changes, 24 h
- 1Flagged processes
| Process | PID | User | State |
|---|---|---|---|
| systemd | 1 | root | Normal |
| sshd (listener) | 812 | root | Normal |
| sshd: svc-deploy [priv] | 4402 | root | Normal |
| sshd: svc-deploy@pts/0 | 4405 | svc-deploy | Normal |
| bash | 4410 | svc-deploy | Normal |
| python3 /tmp/.x/upd.py | 4471 | svc-deploy | Suspicious |
| Time | Change | Path | SHA-256 | Severity |
|---|---|---|---|---|
| 10:42:41 | Createdby svc-deploy | /tmp/.x/upd.py | c41e…09ab | Medium |
| 10:43:20 | Modifiedby svc-deploy | /home/svc-deploy/.ssh/authorized_keys | 9f2c…a41e → 07bd…e913 | High |
Watched paths: /etc, /home/*/.ssh, /usr/bin
| Package | Version | Advisory | Severity |
|---|---|---|---|
| OpenSSH | 9.6p1 | CVE-2024-6387Signal handler race condition in sshd; fixed in 9.8p1 | High |
| Python | 3.10.12 | None known | Clear |
| OpenSSL | 3.0.13 | None known | Clear |
- 10:42:03Inbound SSH session accepted for svc-deploy from 203.0.113.45
- 10:42:41New file /tmp/.x/upd.py created
- 10:43:12python3 started from the interactive shell, PID 4471
- 10:43:15First seen outbound TLS connection to 198.51.100.7:443
- 10:43:20authorized_keys modified, a persistence indicator
- 10:43:21Signals correlated into case #2041, severity High
Awaiting analyst decision on case #2041.
Network defense, with policy you can see
Traffic is inspected, protocols identified and IDS rules evaluated. Prevention happens only where the IPS policy is enabled. Switch the policy to see the difference.
- Flow observed 198.51.100.23 to db, TCP 5432
- IDS rule matched AR-EXAMPLE-0142, severity high
- IPS enforced drop, block event recorded
- IPS disabled alert raised, traffic not prevented
- Correlated into case with host and session context
IDS path
- Event
- Rule evaluation
- Detection
- Severity
- Alert
- Correlation
IPS path Policy enabledPolicy disabled
- Detection
- Policy check
- Enforcement
- Block, drop or reject
- Audit event
Remote sessions
| Service | Initiator | Receiver | Direction | Duration | Confidence |
|---|---|---|---|---|---|
| SSH 22 | 10.0.4.21 | app-prod-04 | Inbound | 12 min | High |
| RDP 3389 | 198.51.100.23 | ws-fin-117 | Inbound | 3 min | Suspicious |
| FTP 21 | db-prod-02 | 203.0.113.9 | Outbound | 40 s | Medium |
Each session links to host events, alerts and cases.
Port exposure
- Baseline
- New port
- Classified
- Correlated
- Response path
- 443HTTPSBaseline
- 22SSHBaseline
- 3389RDPNewInternet exposedSuspicious serviceLinked to sessionBlock available
Fragmented telemetry becomes one investigation
Signals from different domains are normalized, deduplicated and correlated into a single case, with severity and workflow. Synthetic example.

- Ingest
- Normalize
- Correlate
- Deduplicate
- Severity
- Workflow
- Case
- Archive
- Report
- Notify
From detection to action
Armadillo does not stop at the alert. Prevention runs automatically where policy allows. Deeper actions are analyst initiated, authorized and audited. Select an action to follow its command path.

Automatic under policy
- Block, drop or rejectWhen the IPS policy is enabled, confirmed malicious traffic is prevented and logged
- Automatic IP blockingWhen auto blocking is enabled, detections queue a firewall block at the agent
- Protection updatesNew rule bundles are deployed to active environments automatically
Analyst initiated
Command lifecycle
Kill process python3, PID 4471 on app-prod-04 synthetic example
- Authorization
- Dispatch
- Agent check in
- Execution
- Status returned
- Audit
The whole loop, in one scenario
A conceptual product walkthrough from new intelligence to audited response.
Conceptual walkthrough, not a customer incident
- 01
New threat intelligence arrives
An advisory describing a new exploit technique reaches Armadillo.
- 02
Armadillo produces validated protection
The protection engine turns it into a deterministic rule, validated before release.
- 03
The protection bundle updates
The rule joins a new bundle version and deploys to enrolled agents automatically.
- 04
Suspicious activity appears
Traffic matching the new rule reaches the network boundary.
- 05
IDS detects it
Rule evaluation produces an alert with rule ID, source and host.
- 06
IPS enforces prevention
With the IPS policy enabled, the flow is dropped and a block is recorded.
- 07
Context is correlated
Process, file and session telemetry on the host are linked to the alert.
- 08
A case opens
The incident appears in the investigation workflow with all evidence.
- 09
Response is available
An analyst can isolate the host, kill the process or quarantine a file.
- 10
The audit trail records it
Every rule, block and action is recorded with actor, target and time.
Security analysis that stays in country
Armadillo is designed for deployment models where telemetry, logs and traffic are analyzed on site or on in country infrastructure, with rules that remain visible and auditable.
The deployment model is agreed with each customer. It supports data residency requirements; it does not by itself establish compliance with a specific regulation.
One console, every module
Overview, hosts, alerts, traffic, sessions, ports, blocks, cases, processes, file integrity, software, vulnerabilities, reports, rules and bundles.

| Severity | Detection | Rule ID | Action |
|---|---|---|---|
| Critical | Exploit attempt, web service | AR-EXAMPLE-0142 | Blocked |
| High | Lateral movement pattern | AR-EXAMPLE-0088 | Case opened |
| Medium | Unexpected outbound volume | AR-EXAMPLE-0031 | Investigating |
| Service | Direction | Initiator | Confidence |
|---|---|---|---|
| SSH 22 | Inbound | 10.0.4.21 | High |
| RDP 3389 | Inbound | 198.51.100.7 | Review |
| FTP 21 | Outbound | 10.0.2.9 | Medium |
Port events, last 24 hours
- 8080 newly opened Internet exposed
- 5432 baseline Internal only
- 3389 connection attempts Suspicious
| Change | Path | Host | Severity |
|---|---|---|---|
| modify | /home/svc-deploy/.ssh/authorized_keys | app-prod-04 | High |
| create | /tmp/.x/upd.py | app-prod-04 | Medium |
| create | C:\Users\Public\Libraries\svc.dll | ws-fin-117 | High |
- Inventoryopenssl 3.0.2 on 3 hosts
- Mappingpackage and version resolved
- AdvisoryADV-EXAMPLE-07 matched
- Exposure3 hosts affected
- PriorityCritical
Architecture
Sources feed one engine that correlates, validates and decides. Outcomes surface in one console. Select any stage.
Armadillo data flow
Select any stage for detail

One engine, no seams
Sources feed a single engine that correlates, validates and decides. Select a stage to see what it does.
For security architects
Armadillo Technical Due Diligence
The technical dossier behind this page, for evaluators who need the system model rather than the summary.

- Input, process, output modelSystem level and module by module
- Telemetry fieldsEvery data element Armadillo captures
- Processing flowsTen end to end flows, from normal traffic to reporting
- Rule automationMethod and validation, under NDA
- Time to protectionBenchmark definition and result
See Armadillo in your environment.
A technical session with the engineers who build it: your stack, your threat model, and how Armadillo would be deployed.
