Every machine protected,
every action traced.
A sovereign EDR agent for Windows, macOS and Linux. Detects, prevents and responds right on the machine — 9 MB of RAM, zero foreign cloud dependency.
The agent sees everything happening on the machine: process execution, file access, DLL loading, registry, network, DLP operations. It detects malicious patterns locally — without waiting for the SOC — including ransomware, exfiltration, lateral movement and persistence, and can block, isolate or kill the process. The SOC watches in real time and drives the agent remotely through signed commands.
From threat to evidence, in real time.
The module captures the signal, SYLink AI correlates it and decides — you keep control.
From the whole estate down to a single machine.
The same console gives you the overall posture, the agent fleet, then hands-on control of one specific machine.
Posture of machines and servers

The agent fleet

Remote control & RMM actions

The agent, on the machine

The detection engines on board

Real screenshots of the UniSOC portal. The data shown comes from a demonstration environment.
Several engines, one agent.
Where others stack products, SYLink EDR combines every engine in a single 9 MB agent — correlated by the AI.
Behavioural (ETW)
Every process, thread and system call analysed in real time.
Anti-ransomware
Canary files plus OS heuristics (encryption speed) → killed in under 200 ms.
YARA · 125,000 rules
Memory and file signatures, updated every three hours.
Sigma · behavioural
3,200 cross-platform detection rules.
DLL Sideloading
Detects side-loading of hijacked legitimate DLLs.
SYLink AI
Correlates every engine, qualifies and decides — the verdict in plain language.
Blocked — and your files recovered.
The ransomware is stopped dead by the decoys and the heuristics. But SYLink EDR goes further: it automatically restores the files already hit (rollback). Zero loss, zero ransom.
Stop merely detecting. Start fixing.
On subscription, SYLink EDR drives your entire fleet from a single console — a match for the best (Cyberwatch, HarfangLab), and sovereign.
Deploy Windows and Linux patches from the console — compatible with WSUS and Red Hat Satellite. The SOC prioritises what is actively exploited (KEV).
Bulk actions across the whole estate: isolation, updates, forensic collection, policies per group — one click, any number of machines.
Hardening checks (CIS), NIS2/DORA reports per estate, a full inventory with history.
The AI prioritises patches by real risk and proposes the rollout plan — you approve it.
Ready to protect your machines?
The SYLink EDR agent for Windows, macOS and Linux — lightweight, signed, deployable at scale (GPO, MDM, Ansible).
The technology, in detail.
What the module actually does — functions, not promises.
Endpoint visibility
- ETW: process, image load, file, registry, network
- Sysmon-equivalent, built in (nothing to install)
- macOS Endpoint Security + Unified Log
- Linux: auditd + eBPF + inotify
- SHA-256 hash and signature of every executable
Detection
- YARA: 125,000 rules (tiered prevent / detect / analyse)
- Sigma: 3,200 rules converted automatically
- 21 MITRE ATT&CK workers (LotL, persistence, kill-chain)
- 50-feature ML model: a real-time risk score
- C2 beacons, UEBA and tampering detection (AMSI/ETW)
Built-in DLP
- 11 patterns: email, IBAN, card number, national ID, AWS keys, JWT, PEM…
- USB DLP: per-tenant allowlist, automatic quarantine
- Network DLP: file-sharing and webmail blocking, plus anti-DoH
- Blocking at the moment of copy — not merely detection
- Full NIS2 art. 21 / GDPR audit
Active Response
- File quarantine (move + ACL deny)
- Process kill with forensic evidence (optional memory dump)
- Network isolation (temporary allowlist)
- TCP reset on suspicious outbound connections
- Restore through a signed SOC admin command
SYLink AI driven
- Automatic alert triage (4.2% hallucination)
- Recommended actions: isolate / patch / watch
- Automatic MITRE kill chain reconstruction
- Local AI — no CrowdStrike or SentinelOne cloud
- Mandatory human review (DORA audit art. 28)
Lightweight & robust
- 9 MB of RAM (Rust)
- 60-second heartbeat, commands polled every 5 min
- Auto-update through signed .msi / .deb / .pkg packages
- Self-healing: tampering detection plus automatic restart
- A dedicated or unified licence per tenant
What is it actually for?
Stop ransomware before encryption
The tier-1 YARA rules recognise the Conti / LockBit / BlackCat signature before any file is touched. Process killed and machine isolated in under 200 ms.
Block data exfiltration
Uploading client_accounts.xlsx to a personal Drive: the DLP IBAN pattern matches → upload blocked, SOC alerted, audit trail signed.
Detect lateral movement
An admin account signs into 12 machines in five minutes over PsExec. The model flags the pattern, the AI correlates it with the DPI data, and the SOC gets a critical alert.
ANSSI + DORA compliance
The EDR feeds NIS2 and DORA reports with signed events (chained HMAC). An auditor can replay each chain and check its integrity.
Driven by SYLink AI, hosted 100% in France (HDS v2), with no Cloud Act exposure. Every decision is logged and defensible under NIS2 and DORA.
One building block of the SOC — never on its own.
Each module feeds the others through SYLink AI.
Ready to see what is really
happening on your network?
First trial free, no credit card, no commitment. On your existing infrastructure.
