Most security tools focus on the perimeter. Vedric focuses on what happens after a trusted user, contractor, or service account is already inside - and starts behaving outside their own pattern.
THE PROBLEM
Endpoint protection blocks known-bad. Identity providers verify the login. SIEMs aggregate logs after the fact. None of them watch what a valid user actually does once their session is open. Insider risk lives in that gap - and it covers the honest mistake, the drifting service account, and the borrowed credential equally.
Built around process and binary verdicts. A signed PowerShell session running a perfectly legitimate cmdlet at 2am does not look like malware - and EDR will not flag it. Insider behavior almost never trips a binary verdict.
Aggregates events. Excellent for retroactive search. Without per-user behavioral memory it cannot tell you that this user has not run that query in six months - only that the query happened.
Tied to file content and pattern-matching rules. Misses the behavioral shape of staging, compression, and gradual exfiltration when files themselves do not match a rule.
Most UEBA modules score authentication logs. They see who logged in. They often lack endpoint process and command metadata, authentication-event cadence, DNS/network aggregates, and removable-media write evidence.
The collector ships process and command metadata, security-event counts, DNS/network aggregates, sensitive-extension inventory, and removable-media write metadata. The cloud correlates only the evidence those collectors actually produce.
Every user gets a personal baseline of what they do: when, where, how often, against which systems. After warm-up the model has enough memory that drift becomes visible without triggering noise on a normal Tuesday.
A single deviation is a footnote. Three correlated deviations across the same user, endpoint, and time window are a storyline. Vedric promotes only correlated activity to the analyst surface - typically one alert per investigation.
When a storyline materializes, an AI triage layer reads only that tenant's context and produces a verdict, evidence chain, and recommended next action. Every tool call is read-only. Every action against the endpoint is admin-gated.
EXAMPLE SCENARIO · TIMELINE
Identifying details removed. This is a composite of behavioral shapes Vedric reads in the run-up to a departure - one of many patterns the engine recognizes.
On day 14 the employee submits resignation. Vedric had eleven days of correlated warning. The analyst has a single storyline with an append-only audit trail to bring to HR, legal, and the offboarding decision.
Vedric minimizes content by design. The collector enforces the refusal list and the documented bounded PowerShell exception in agent code.
Read the full privacy stance →Early access is offered to security teams, IT leaders, and MSPs running production Windows fleets who want behavioral visibility without invasive monitoring. We review every request manually.