Your AI-powered digital armor

Armadillo unifies security telemetry, deterministic detection, prevention and response, with an automated path from threat intelligence to deployable protection.

See how it works

Armadillo

Unified cyber defense.

One platform that sees your environment, understands what is happening in it, protects it with deterministic logic, and gives analysts the actions to respond.

A protection dome over enterprise infrastructure, with incoming threats stopped at its surface
  1. 01

    See

    Endpoint, network, process, file, session and port telemetry from enrolled agents and sensors.

    HostsTrafficProcessesFilesSessionsPorts
  2. 02

    Understand

    Normalize, correlate and put security activity in context, with vulnerability and threat intelligence.

    SIEMCorrelationThreat intelExposure
  3. 03

    Protect

    Deterministic detection rules, IDS evaluation and IPS enforcement, updated through versioned bundles.

    RulesIDSIPSBundles
  4. 04

    Respond

    Investigation, containment and response actions, every step recorded in an audit trail.

    CasesActionsIsolationAudit
≤ 5 s
maximum observed end to end time to protection, completed reported test set. Method
Automatic
from new intelligence to enforced protection, no manual rule writing
Deterministic
explicit, versioned, auditable detection logic
Local
analysis on site or on in country infrastructure

One platform. Multiple security planes.

Every plane reads from and writes to the same data model, so context never crosses an integration seam.

Detection plane

Deterministic rules, IDS detection path, alerts, SIEM ingestion and real time correlation

From new threat to active protection

New threat intelligence, or a sufficiently detailed attack description, goes in. Validated protection comes out, deployed and enforced in your environment automatically. No vendor release cycle, no manual rule writing.

Earth at night seen from orbit, city lights across a continent
Input

New threat intelligence

Advisories, exploit information and indicators, or a detailed attack description.

Armadillo

Protection engine

Produces deterministic detection and prevention rules that are validated before release and remain auditable.

Internal method shared under NDA
Output

Active protection

A new versioned rule bundle, deployed to enrolled agents and engines and enforced where policy allows.

  • Automaticfrom intelligence to enforcement
  • Deterministicexplicit logic, not an opaque decision
  • Validatedbefore any rule is released
  • Auditableevery rule versioned and traceable

Time to protection, measured end to end

≤5seconds

Maximum observed end to end time to protection across the completed reported Armadillo test set.

Review the method

  1. Intelligence received
  2. Protection engine
  3. Bundle deployed
  4. Protection active
00.0 s≤ 05.0 s

Replay of a documented benchmark. Stage positions show order, not individual durations.

Every host, in context

Every enrolled host reports agent health, rule bundle state, processes, file integrity and installed software, correlated with vulnerability intelligence. Select a host to investigate it.

Illustrative environment. Vulnerability mappings are real.

A rack of servers in a data centre

app-prod-04

Application server

Suspicious activity
Operating system
Linux, kernel 6.8
IP address
10.20.2.14
Agent
Healthy
Rule bundle
Current
Last seen
4 s ago
IPS policy
Enabled
  • 1Open cases
  • 1Exposures
  • 2File changes, 24 h
  • 1Flagged processes

Network defense, with policy you can see

Traffic is inspected, protocols identified and IDS rules evaluated. Prevention happens only where the IPS policy is enabled. Switch the policy to see the difference.

Close view of network servers with status lights
Architecture view, synthetic traffic
External Protected network webappdb IDSIPS DROP ALERT ONLY
  1. Flow observed 198.51.100.23 to db, TCP 5432
  2. IDS rule matched AR-EXAMPLE-0142, severity high
  3. IPS enforced drop, block event recorded
  4. IPS disabled alert raised, traffic not prevented
  5. Correlated into case with host and session context

IDS path

  1. Event
  2. Rule evaluation
  3. Detection
  4. Severity
  5. Alert
  6. Correlation

IPS path Policy enabledPolicy disabled

  1. Detection
  2. Policy check
  3. Enforcement
  4. Block, drop or reject
  5. Audit event

Remote sessions

Synthetic session log
ServiceInitiatorReceiverDirectionDurationConfidence
SSH 2210.0.4.21app-prod-04Inbound12 minHigh
RDP 3389198.51.100.23ws-fin-117Inbound3 minSuspicious
FTP 21db-prod-02203.0.113.9Outbound40 sMedium

Each session links to host events, alerts and cases.

Port exposure

  1. Baseline
  2. New port
  3. Classified
  4. Correlated
  5. Response path
  • 443HTTPSBaseline
  • 22SSHBaseline
  • 3389RDPNewInternet exposedSuspicious serviceLinked to sessionBlock available

Fragmented telemetry becomes one investigation

Signals from different domains are normalized, deduplicated and correlated into a single case, with severity and workflow. Synthetic example.

Threat detection radar with normal signals in blue and three flagged threats in orange
Network eventRDP from 198.51.100.23Port event3389 newly exposedRemote sessionInbound RDP, suspiciousProcess eventpowershell.exe spawnedFile changetmp.bin createdVulnerability contextHost exposure present Case6 linked signalsseverity critical Respond
  1. Ingest
  2. Normalize
  3. Correlate
  4. Deduplicate
  5. Severity
  6. Workflow
  7. Case
  8. Archive
  9. Report
  10. Notify

From detection to action

Armadillo does not stop at the alert. Prevention runs automatically where policy allows. Deeper actions are analyst initiated, authorized and audited. Select an action to follow its command path.

A digital shield of hexagonal cells fed by circuit traces, with an orange chevron

Automatic under policy

  • Block, drop or rejectWhen the IPS policy is enabled, confirmed malicious traffic is prevented and logged
  • Automatic IP blockingWhen auto blocking is enabled, detections queue a firewall block at the agent
  • Protection updatesNew rule bundles are deployed to active environments automatically

Analyst initiated

Command lifecycle

Kill process python3, PID 4471 on app-prod-04 synthetic example

  1. Authorization
  2. Dispatch
  3. Agent check in
  4. Execution
  5. Status returned
  6. Audit

The whole loop, in one scenario

A conceptual product walkthrough from new intelligence to audited response.

Conceptual walkthrough, not a customer incident

  1. 01

    IntelligenceINGEST

    New threat intelligence arrives

    An advisory describing a new exploit technique reaches Armadillo.

  2. 02

    DetectionRULE VALIDATED

    Armadillo produces validated protection

    The protection engine turns it into a deterministic rule, validated before release.

  3. 03

    ManagementBUNDLE CURRENT

    The protection bundle updates

    The rule joins a new bundle version and deploys to enrolled agents automatically.

  4. 04

    VisibilityTELEMETRY

    Suspicious activity appears

    Traffic matching the new rule reaches the network boundary.

  5. 05

    DetectionALERT

    IDS detects it

    Rule evaluation produces an alert with rule ID, source and host.

  6. 06

    PreventionIPS ACTIVE

    IPS enforces prevention

    With the IPS policy enabled, the flow is dropped and a block is recorded.

  7. 07

    DetectionCORRELATED

    Context is correlated

    Process, file and session telemetry on the host are linked to the alert.

  8. 08

    ResponseCASE OPEN

    A case opens

    The incident appears in the investigation workflow with all evidence.

  9. 09

    ResponseACTION READY

    Response is available

    An analyst can isolate the host, kill the process or quarantine a file.

  10. 10

    ManagementAUDIT

    The audit trail records it

    Every rule, block and action is recorded with actor, target and time.

Security analysis that stays in country

Armadillo is designed for deployment models where telemetry, logs and traffic are analyzed on site or on in country infrastructure, with rules that remain visible and auditable.

The deployment model is agreed with each customer. It supports data residency requirements; it does not by itself establish compliance with a specific regulation.

Doha skyline at night

One console, every module

Overview, hosts, alerts, traffic, sessions, ports, blocks, cases, processes, file integrity, software, vulnerabilities, reports, rules and bundles.

Conceptual Armadillo console panels: activity chart, alert queue and an escalated alert
ArmadilloConsole
Conceptual view, synthetic data
Hosts4846 healthy
Open alerts72 high
Active blocks12IPS on
Bundlev.nextcurrent

Architecture

Sources feed one engine that correlates, validates and decides. Outcomes surface in one console. Select any stage.

Armadillo data flow

Select any stage for detail

Sources
ArmadilloEngine
Outcomes

One engine, no seams

Sources feed a single engine that correlates, validates and decides. Select a stage to see what it does.

Data flow as described in the Armadillo technical due diligence dossier.Engineers walk through the detailed architecture during evaluation.

For security architects

Armadillo Technical Due Diligence

The technical dossier behind this page, for evaluators who need the system model rather than the summary.

Encrypted data streaming through layered protection rings
  1. Input, process, output modelSystem level and module by module
  2. Telemetry fieldsEvery data element Armadillo captures
  3. Processing flowsTen end to end flows, from normal traffic to reporting
  4. Rule automationMethod and validation, under NDA
  5. Time to protectionBenchmark definition and result

See Armadillo in your environment.

A technical session with the engineers who build it: your stack, your threat model, and how Armadillo would be deployed.