Tehtris EDR

Where the attacker must pass, we intercept

An attacker can bypass a signature, but not the stages of an attack. To reach their goal, they have to execute code, escalate privileges, establish persistence and move laterally. Tehtris EDR sits on these choke points.

It continuously monitors activity across workstations and servers and qualifies abnormal behavior, including against an unknown threat, then blocks and isolates the endpoint before the attack can progress.

Every attack follows the same path.
‍Tehtris EDR acts from the very first step, execution, stopping malicious code before it can gain privileges, settle in or spread to other machines.

Every stage of an attack is an opportunity to stop it.

Once on a workstation, an attacker still has to go through unavoidable steps: executing code, escalating privileges, and spreading.

‍

This is precisely where Tehtris EDR steps in to stop the attack in its tracks. The right defenses, in the right places.

An approach centered on
attack checkpoints

Tehtris EDR strengthens detection and response at the stages where an attack leaves exploitable traces on workstations and servers: a process launched, a permission obtained, a configuration modified. Our agent monitors these signals continuously and blocks the attack at the exact moment it reveals itself.
Act where the attack becomes visible

Tehtris EDR sits at the chocke points every attack must pass through, to block it as early as possible.

NGAV: a next-generation antivirus trained in France

Instead of static signatures, it uses a neural network developed by our R&D team and trained on real-world threats. It is one detection component among many, combined with context: the quality of the data is what makes the difference.

What makes us different

Design choices made by cybersecurity experts

Block where the attacker must pass

A chocke point-based approach, born from our pentesting and honeypot research, rather than massive data collection.

Integrate anti-tampering protections

Anti-tampering mechanisms protect the agent from being disabled or bypassed: an attacker cannot simply shut it down to move forward.

Centralize policy management

Policies defined once and applied by machine group: consistent rules across the entire fleet, without needing to configure each workstation individually.

Keep protecting legacy machines

Windows XP to 11, Server 2003 to 2025, Linux from kernel 2.6.18, macOS from Sierra onwards.

European independence & data

Where is your data located?

Hosting

OVHcloud hosting with a SecNumCloud option available. Data does not leave the infrastructure and is not subject to the U.S. CLOUD Act.

Processing

Processing performed within the Tehtris infrastructure in Europe.

Jurisdiction

Outside the scope of the U.S. CLOUD Act.

A French solution trusted by demanding European organizations

For organizations with stringent protection requirements, Tehtris EDR can be deployed with the OVHcloud SecNumCloud option. This ANSSI qualification ensures hosting in France, operated exclusively by personnel based in Europe. This option is designed for operators of essential services and organizations handling sensitive data.

Operational impact

The difference is made in the first moments

When facing an intrusion, acting in time matters more than seeing everything.

How Tehtris EDR makes a real difference

‍depending on your role

Concrete evidence for your audits and reports
NIS2, DORA, and audits require you to demonstrate your security posture. Tehtris EDR helps you provide proof: hosting in Europe, agent protection against deactivation, and action logging. Tangible elements for your decision-making and compliance reports.
  • Hosted in Europe, SecNumCloud option available
  • Agent protection against deactivation
  • Action logging, ready for your reports
  • Centrally managed response
Deployment that doesn't force you to change everything
A heterogeneous fleet doesn't require fragmented security. Tehtris EDR deploys across Windows, Linux, and macOS, including legacy environments, and offers management from a single console.
  • From legacy to the latest: Windows XP to 11, Server 2003 to 2025, Linux from kernel 2.6.18, and macOS from Sierra onwards
  • A single console for EPP and EDR
  • Phased deployment, without replacing everything
Alerts that enable fast action
Targeted telemetry, fleet-wide searching, and execution context: everything you need to investigate an intrusion and decide fast. You cut investigation time, and response can be automated according to your policies.
  • Configurable response policies
  • Search and investigation from a single console
  • Prioritization based on context rather than alert volume
  • Automated policy-based response, optional and configurable

FAQ

Does an EDR solution replace an antivirus or an EPP?
FAQ icon

No, the two complement each other. EPP prevents threats from executing in the first place, while EDR detects and responds to suspicious behavior that slips through. Tehtris EDR integrates both, managed from a single console. If you prefer to keep your current EPP, Tehtris EDR can also coexist with it.

Does Tehtris EDR work on Windows 7 and legacy systems?
FAQ icon

Yes: from Windows XP to 11 and Server 2003 to 2025, in both 32 and 64-bit versions, as well as on Linux from kernel 2.6.18 and macOS from Sierra onwards.

Do I need a SOC to run Tehtris EDR?
FAQ icon

Not necessarily. Without a SOC, policy-based automated response blocks and isolates threats without human intervention. With a team of analysts, you retain control over every decision and can fully leverage telemetry and investigation. Everything in between is configurable based on your team's maturity. And if you lack the resources to qualify alerts, our services can take over: MDR (Managed Detection and Response), a dedicated TAM (Technical Account Manager), and Professional Services.

‍

What happens when a threat is detected?
FAQ icon

Depending on the configured policies, Tehtris EDR analyzes the event, classifies the behavior, and executes a response: for example, the malicious process is terminated, the workstation is isolated from the network, and an alert is sent to the console. The state of the workstation (processes, network connections) is preserved for investigation.

Do my documents stay confidential?
FAQ icon

Yes. The analysis is based on metadata, hashes, and behavioral telemetry, not on the content of your documents. Only certain suspicious files, such as executables or scripts, may be uploaded for automated analysis within the Tehtris infrastructure. If your organization requires it, a setting is available to disable the uploading of Microsoft Office documents.

Where is the data hosted?
FAQ icon

Data is hosted in Europe on OVHcloud infrastructure and remains stored within that environment. A SecNumCloud option is available.

How does Tehtris EDR impact the performance of workstations and servers?
FAQ icon

Tehtris EDR relies on an agent designed to remain lightweight and unobtrusive in daily operations. To balance protection with performance, security policies can be fine-tuned for specific groups of machines. Our TAMs and Professional Services team are here to help you align these policies with your security goals and operational requirements.

Contact

Request your Tehtris EDR demo

In 30 minutes, let's discuss your environment, the workstations and servers you need to protect, your security maturity, and your endpoint detection and response requirements.