Where the attacker must pass, we intercept
It continuously monitors activity across workstations and servers and qualifies abnormal behavior, including against an unknown threat, then blocks and isolates the endpoint before the attack can progress.
Every attack follows the same path.
Tehtris EDR acts from the very first step, execution, stopping malicious code before it can gain privileges, settle in or spread to other machines.
Every stage of an attack is an opportunity to stop it.
Once on a workstation, an attacker still has to go through unavoidable steps: executing code, escalating privileges, and spreading.
This is precisely where Tehtris EDR steps in to stop the attack in its tracks. The right defenses, in the right places.
An approach centered on
attack checkpoints
Tehtris EDR sits at the chocke points every attack must pass through, to block it as early as possible.

Instead of static signatures, it uses a neural network developed by our R&D team and trained on real-world threats. It is one detection component among many, combined with context: the quality of the data is what makes the difference.
Design choices made by cybersecurity experts
Block where the attacker must pass
A chocke point-based approach, born from our pentesting and honeypot research, rather than massive data collection.
Integrate anti-tampering protections
Anti-tampering mechanisms protect the agent from being disabled or bypassed: an attacker cannot simply shut it down to move forward.
Centralize policy management
Policies defined once and applied by machine group: consistent rules across the entire fleet, without needing to configure each workstation individually.
Keep protecting legacy machines
Windows XP to 11, Server 2003 to 2025, Linux from kernel 2.6.18, macOS from Sierra onwards.
Where is your data located?
Hosting
OVHcloud hosting with a SecNumCloud option available. Data does not leave the infrastructure and is not subject to the U.S. CLOUD Act.
Processing
Processing performed within the Tehtris infrastructure in Europe.
Jurisdiction
Outside the scope of the U.S. CLOUD Act.
A French solution trusted by demanding European organizations



For organizations with stringent protection requirements, Tehtris EDR can be deployed with the OVHcloud SecNumCloud option. This ANSSI qualification ensures hosting in France, operated exclusively by personnel based in Europe. This option is designed for operators of essential services and organizations handling sensitive data.
.png)
The difference is made in the first moments
How Tehtris EDR makes a real difference
depending on your role

Concrete evidence for your audits and reports
- Hosted in Europe, SecNumCloud option available
- Agent protection against deactivation
- Action logging, ready for your reports
- Centrally managed response

Deployment that doesn't force you to change everything
- From legacy to the latest: Windows XP to 11, Server 2003 to 2025, Linux from kernel 2.6.18, and macOS from Sierra onwards
- A single console for EPP and EDR
- Phased deployment, without replacing everything

Alerts that enable fast action
- Configurable response policies
- Search and investigation from a single console
- Prioritization based on context rather than alert volume
- Automated policy-based response, optional and configurable
FAQ
No, the two complement each other. EPP prevents threats from executing in the first place, while EDR detects and responds to suspicious behavior that slips through. Tehtris EDR integrates both, managed from a single console. If you prefer to keep your current EPP, Tehtris EDR can also coexist with it.
Yes: from Windows XP to 11 and Server 2003 to 2025, in both 32 and 64-bit versions, as well as on Linux from kernel 2.6.18 and macOS from Sierra onwards.
Not necessarily. Without a SOC, policy-based automated response blocks and isolates threats without human intervention. With a team of analysts, you retain control over every decision and can fully leverage telemetry and investigation. Everything in between is configurable based on your team's maturity. And if you lack the resources to qualify alerts, our services can take over: MDR (Managed Detection and Response), a dedicated TAM (Technical Account Manager), and Professional Services.
Depending on the configured policies, Tehtris EDR analyzes the event, classifies the behavior, and executes a response: for example, the malicious process is terminated, the workstation is isolated from the network, and an alert is sent to the console. The state of the workstation (processes, network connections) is preserved for investigation.
Yes. The analysis is based on metadata, hashes, and behavioral telemetry, not on the content of your documents. Only certain suspicious files, such as executables or scripts, may be uploaded for automated analysis within the Tehtris infrastructure. If your organization requires it, a setting is available to disable the uploading of Microsoft Office documents.
Data is hosted in Europe on OVHcloud infrastructure and remains stored within that environment. A SecNumCloud option is available.
Tehtris EDR relies on an agent designed to remain lightweight and unobtrusive in daily operations. To balance protection with performance, security policies can be fine-tuned for specific groups of machines. Our TAMs and Professional Services team are here to help you align these policies with your security goals and operational requirements.