The damaging part of an insider incident is rarely a malicious binary. It is a valid login followed by behavior that drifts off the user's own pattern. Vedric is built to read that drift with content-minimizing collectors and one disclosed bounded PowerShell script-preview exception.
THE PROBLEM
It looks like a slightly longer evening, a query shape that was once quarterly running weekly, or an endpoint whose new-destination count rises beside a first-time command. Those metadata changes can justify review before a loud incident, but they do not by themselves prove data theft.
AV and EDR scoring rests on whether the binary, the hash, or the IoC is known. An employee with legitimate access does not need any of those. Indicator-based tools have nothing to score.
DLP triggers on rule matches. A user staging copies of files they have access to, in formats they normally use, will not match a rule. Insider behavior bends within policy until it bends past it.
Threshold-based monitoring on noisy primitives (every off-hours login, every elevated command) drowns SOCs. The high-signal pattern is correlation across days, not alerting on every primitive.
SIEM queries are excellent at "show me what this user did last week", once you already know to ask. They are not built to surface "this user is trending off their own baseline" before the question is asked.
A deviation is a deviation regardless of who caused it. The same engine flags an honest mistake, a drifting service account, and a borrowed credential, because all three look the same to a baseline that knows what normal is for that primary identity.
Vedric does not need to decide whether the user is malicious, careless, or compromised. The system flags off-baseline behavior; humans interpret intent. That separation is what makes the alert defensible to legal and HR.
A single off-hours login is a footnote. Three correlated deviations on the same user, endpoint, and project, over six days, is a storyline. Vedric promotes correlated patterns and quietly logs the rest.
When an analyst takes a covered sensitive action, Vedric records the actor, reason, and relevant response context in audit rows that the application role cannot update or delete. Alert and storyline records remain operational records; this is not a claim that every detection row is cryptographically immutable.
EXAMPLE SCENARIO · TIMELINE
The contractor was scoped narrowly for a single project. Their access was set up correctly. Over a few weeks, the systems they touch begin to drift outside the project envelope.
No malware. No policy violation by traditional rules. No alert from EDR, SIEM, or DLP. The signal was the shape of the access drifting outside the contractor's scope, the kind of pattern only a per-identity baseline can read.
Vedric minimizes content by design. The collector enforces the refusal list and the documented bounded PowerShell exception in agent code.
Read the full privacy stance →Early access is offered to teams who want behavioral detection at the endpoint without invasive monitoring. We review every request to make sure Vedric is a fit.