Windows
ETW, WFP, minifilter, and native services where required, with driver and service signing treated as separate security work.
ENDPOINT DEFENSE
Oten Endpoint Defense uses platform-native sensors, normalized telemetry, detection, and security verdicts to inform shared trust context without collapsing detection and enforcement into one unsafe step.
System role: Oten Endpoint + Oten Guard
Evaluation depends on: Requires a trusted shared Agent core, platform-native sensors, common telemetry, and response guardrails.
ETW, WFP, minifilter, and native services where required, with driver and service signing treated as separate security work.
Endpoint Security Framework and Network Extension, subject to entitlement and system-extension lifecycle requirements.
eBPF plus LSM or audit sources by capability, with explicit kernel compatibility and verifier constraints.
Capture bounded, policy-authorized telemetry through the platform sensor.
Map evidence into a common schema with source, time, release, and integrity context.
Evaluate rules or validated behavior analytics and preserve supporting evidence.
Create a finding with severity, confidence, and reason codes rather than an unexplained score.
Adjust risk or access trust only through validated policy and mandatory-gate semantics.
Notify, contain, isolate, terminate supported access, or run another guarded action with recovery requirements.
Record the enforcement acknowledgement, failure, rollback, or unreachable device state.
FAQ
It should not. A shared core can reduce duplicated identity, policy, update, and telemetry code, but module boundaries, OS privileges, IPC authorization, signing, and rollback remain explicit.
No. A mapping can document intended visibility or analytics, but it is not evidence of efficacy, completeness, or acceptable false-positive behavior.
The site uses that term only when a specific observation-to-confirmation latency has been measured. Local sensor actions, cloud decisions, Gateway revoke, and offline devices have different timing domains.
Next in Oten Access
See the shared Agent architecture and the security stages required for verified endpoint response.