INSIDER RISK DETECTION

Insider risk is the access you already granted.

Most security tools focus on the perimeter. Vedric focuses on what happens after a trusted user, contractor, or service account is already inside - and starts behaving outside their own pattern.

Request Early AccessView PlatformWindows endpoints today.

THE PROBLEM

Trusted access is the part of your stack that nobody is watching.

Endpoint protection blocks known-bad. Identity providers verify the login. SIEMs aggregate logs after the fact. None of them watch what a valid user actually does once their session is open. Insider risk lives in that gap - and it covers the honest mistake, the drifting service account, and the borrowed credential equally.

WHY CURRENT APPROACHES FALL SHORT

Insider risk is invisible to perimeter-shaped tools.

EDR

Built around process and binary verdicts. A signed PowerShell session running a perfectly legitimate cmdlet at 2am does not look like malware - and EDR will not flag it. Insider behavior almost never trips a binary verdict.

SIEM

Aggregates events. Excellent for retroactive search. Without per-user behavioral memory it cannot tell you that this user has not run that query in six months - only that the query happened.

DLP

Tied to file content and pattern-matching rules. Misses the behavioral shape of staging, compression, and gradual exfiltration when files themselves do not match a rule.

UEBA add-ons

Most UEBA modules score authentication logs. They see who logged in. They do not see what the endpoint is doing afterward at the process, command, and file-access level.

HOW VEDRIC HELPS

Vedric watches what valid users actually do - and notices when it changes.

The collector ships endpoint metadata across six surfaces: process, command, authentication, network, file, and DNS. The cloud baselines the user against themselves and against their peer group, then correlates deviations into a single storyline an analyst can act on.

01 /BASELINE

Per-user, per-peer behavior memory

Every user gets a personal baseline of what they do: when, where, how often, against which systems. After warm-up the model has enough memory that drift becomes visible without triggering noise on a normal Tuesday.

02 /CORRELATE

Storylines, not raw alerts

A single deviation is a footnote. Three correlated deviations across the same user, endpoint, and time window are a storyline. Vedric promotes only correlated activity to the analyst surface - typically one alert per investigation.

03 /TRIAGE

Tenant-isolated AI verdicts

When a storyline materializes, an AI triage layer reads only that tenant's context and produces a verdict, evidence chain, and recommended next action. Every tool call is read-only. Every action against the endpoint is admin-gated.

EXAMPLE SCENARIO · TIMELINE

A senior developer in their last two weeks.

Identifying details removed. This is a composite of behavioral shapes Vedric reads in the run-up to a departure - one of many patterns the engine recognizes.

  1. T+01
    Day 03 - query pattern outside the user's six-month norm. Logged as a deviation. Not yet alerting.
  2. T+02
    Day 05 - access scope drifts outside their assigned project. Same credentials, different behavior. Correlated against the day-03 deviation.
  3. T+03
    Day 08 - off-hours activity in a window the user has never worked in before. Temporal deviation logged.
  4. T+04
    Day 09 - three deviations on the same user/endpoint within six days. Storyline materializes. One alert reaches the analyst surface.
  5. T+05
    Day 11 - privileged query not seen in the last six months runs against a system outside the user's normal scope. Privilege-drift signal added to the storyline.
  6. T+06
    Day 13 - egress volume above personal baseline, during off-baseline hours. Exfiltration-shaped pattern flagged for response.
OUTCOME

On day 14 the employee submits resignation. Vedric had eleven days of correlated warning. The analyst has a single storyline with an append-only audit trail to bring to HR, legal, and the offboarding decision.

WHAT THE PLATFORM SURFACES

Designed to find behavior, not to read content.

VEDRIC SURFACES
  • Per-user and per-peer baselines across process, command, authentication, network, file, and DNS metadata
  • Correlated storylines that connect related deviations across days
  • Privilege drift, scope drift, and temporal drift on the same primary identity
  • AI-generated verdict, evidence chain, and recommended next action - tenant-isolated
  • Append-only audit log of every detection and every analyst response
VEDRIC DOES NOT DO
  • Read keystrokes
  • Capture screenshots, webcam, or microphone
  • Inspect file contents or private messages
  • Take destructive endpoint actions without admin sign-off and a stated reason
  • Cross tenant boundaries - every query is scoped to a single tenant
PRIVACY-FIRST BY DEFAULT

No keystrokes. No screenshots. No file contents.

Vedric is metadata-only by design. The collector enforces these limits at the source code of the agent.

Read the full privacy stance →
  • No keystrokes
  • No screenshots
  • No webcam
  • No microphone
  • No file contents
  • No private messages
FREQUENTLY ASKED

Questions buyers ask first.

See insider risk before it becomes damage.

Early access is offered to security teams, IT leaders, and MSPs running production Windows fleets who want behavioral visibility without invasive monitoring. We review every request manually.

Request Early AccessTalk to security teamResponse within one business day.