Most security tools focus on the perimeter. Vedric focuses on what happens after a trusted user, contractor, or service account is already inside - and starts behaving outside their own pattern.
THE PROBLEM
Endpoint protection blocks known-bad. Identity providers verify the login. SIEMs aggregate logs after the fact. None of them watch what a valid user actually does once their session is open. Insider risk lives in that gap - and it covers the honest mistake, the drifting service account, and the borrowed credential equally.
Built around process and binary verdicts. A signed PowerShell session running a perfectly legitimate cmdlet at 2am does not look like malware - and EDR will not flag it. Insider behavior almost never trips a binary verdict.
Aggregates events. Excellent for retroactive search. Without per-user behavioral memory it cannot tell you that this user has not run that query in six months - only that the query happened.
Tied to file content and pattern-matching rules. Misses the behavioral shape of staging, compression, and gradual exfiltration when files themselves do not match a rule.
Most UEBA modules score authentication logs. They see who logged in. They do not see what the endpoint is doing afterward at the process, command, and file-access level.
The collector ships endpoint metadata across six surfaces: process, command, authentication, network, file, and DNS. The cloud baselines the user against themselves and against their peer group, then correlates deviations into a single storyline an analyst can act on.
Every user gets a personal baseline of what they do: when, where, how often, against which systems. After warm-up the model has enough memory that drift becomes visible without triggering noise on a normal Tuesday.
A single deviation is a footnote. Three correlated deviations across the same user, endpoint, and time window are a storyline. Vedric promotes only correlated activity to the analyst surface - typically one alert per investigation.
When a storyline materializes, an AI triage layer reads only that tenant's context and produces a verdict, evidence chain, and recommended next action. Every tool call is read-only. Every action against the endpoint is admin-gated.
EXAMPLE SCENARIO · TIMELINE
Identifying details removed. This is a composite of behavioral shapes Vedric reads in the run-up to a departure - one of many patterns the engine recognizes.
On day 14 the employee submits resignation. Vedric had eleven days of correlated warning. The analyst has a single storyline with an append-only audit trail to bring to HR, legal, and the offboarding decision.
Vedric is metadata-only by design. The collector enforces these limits at the source code of the agent.
Read the full privacy stance →Early access is offered to security teams, IT leaders, and MSPs running production Windows fleets who want behavioral visibility without invasive monitoring. We review every request manually.