Your identities and mail systems,
under control.
Lightweight agents collect your Active Directory and your mail systems — Microsoft 365, Exchange, MDaemon: accounts, groups, sign-ins and security events, correlated with everything the SOC detects.
Most attacks come through identity: weak accounts, missing MFA, compromised mailboxes. The AD agents collect your directory AND your mail systems (M365, Exchange, MDaemon) and feed SYLink AI: every suspicious sign-in, every dangerous privilege, every brute-force attempt becomes visible — and actionable.
From threat to evidence, in real time.
The module captures the signal, SYLink AI correlates it and decides — you keep control.
The directory put under the microscope.
A permanent Active Directory audit — and, above all, what to do about it.
Directory posture

The problems to fix

How to fix it, concretely

Risk radar and detailed directory

Real screenshots of the UniSOC portal. The data shown comes from a demonstration environment.
The technology, in detail.
What the module actually does — functions, not promises.
Active Directory directory
- Accounts, groups, OUs, GPOs, privileges
- Dormant, non-expiring or MFA-less accounts
- Attack paths to Domain Admin
- Security events (4625, 4740, 4728…)
- Push collection from the domain controller (MSI agent)
Mail systems connected
- Microsoft 365 & Exchange (Graph)
- MDaemon and third-party SMTP servers
- Suspicious connections / impossible travel
- Malicious forwarding rules
- Compromised mailboxes correlated with the EDR
Driven by SYLink AI
- A risk score per identity
- Identity × endpoint × network correlation
- UEBA detection (abnormal behaviour)
- Recommendation: disable or reset MFA
- Signed evidence for the audit
Response & compliance
- Account disabling (signed command)
- Password reset and rotation
- NIS2 / DORA report on identities
- No data leaves France
- Complete logging
What is it actually for?
Detect a compromised mailbox
A forwarding rule created plus a sign-in from an unusual country: the agent sees it on M365 and SYLink AI escalates an incident.
Spot a path to Domain Admin
A Kerberoastable service account opens a path to privilege: detected, prioritised and fixed before it is exploited.
Prove you have identities under control
Accounts without MFA, dormant or privileged: the report is ready for the NIS2 auditor in seconds.
Driven by SYLink AI, hosted 100% in France (HDS v2), with no Cloud Act exposure. Every decision is logged and defensible under NIS2 and DORA.
One building block of the SOC — never on its own.
Each module feeds the others through SYLink AI.
Ready to see what is really
happening on your network?
First trial free, no credit card, no commitment. On your existing infrastructure.
