SIEM + EDR/XDR
Last updated
Sec1 SIEM + EDR/XDR is unified detection and response. A lightweight agent collects logs and endpoint telemetry from your fleet; the platform detects threats, correlates them into incidents and lets your SOC respond — from one console.
Understand what the platform does and how the pieces fit together:
A simple end-to-end picture — agents, ingest, pipeline, detection, correlation, AI and response:
Two ways to get data in — the Sec1 agent or an existing log collector — and how one agent serves SIEM, EDR and XDR:
Reach the live console, sign in with your platform credentials and understand the gateway:
Prerequisites, the network allowlist and single vs bulk install on Windows, Linux or macOS:
Read the per-host detail view — the telemetry collected from each endpoint:
Find and triage vulnerable software across the fleet and per host:
Inventory connected peripherals and approve or block them:
Allow or deny software execution and installation by rule:
Follow the detection-to-incident flow and investigate cases:
The live-response toolkit for acting on a host:
Last updated