Catch the attack
as it happens.
Attackers move in minutes — your SOC has hours. OnDuty CDR correlates eBPF runtime telemetry, cloud audit logs and identity activity into a single live threat graph, with response actions built in.
Signal to Incident
Median detect
<3s
Active incidents
9
From first signal to contained.
OnDuty CDR closes the loop between observation and action. Runtime, identity and control-plane signals converge, get scored against MITRE ATT&CK, and trigger response playbooks — automatically or with a single click.
Observe
eBPF sensors capture every process, syscall and API call
Correlate
Runtime, identity and network signals merge into one graph
Detect
150+ MITRE ATT&CK detections surface the attack story
Respond
Isolate, revoke or trigger SOAR — one click or automatic
Every signal. One incident timeline.
From the first eBPF heartbeat to a contained incident — six layers of intelligence that turn cloud noise into a focused response.
eBPF sensors see every process, syscall and packet.
OnDuty deploys agentless eBPF sensors across every workload — no code changes, no sidecars. Process launches, file writes, outbound connections and syscalls stream in real time so reverse shells, crypto-miners and file-integrity events surface within seconds of the first indicator.
Real threats first — noise auto-suppressed.
The OnDuty threat score fuses runtime behavior, identity risk and control-plane anomalies, then weights every alert by exploit context — whether an attacker actually reached a workload, moved laterally, or touched a crown-jewel asset. Repeat noise and known-benign patterns are auto-baselined so your responders only see the ones that matter.
Live incidents · sorted by OnDuty threat score
See the whole kill chain, not one alert at a time.
Runtime, identity and network signals stitch into a single live threat graph. One view shows exactly how an attacker landed on a workload, assumed a role, and pivoted toward sensitive data — with blast-radius modeling for every ongoing incident.
Live kill chain — INC-4211
attacker → nginx → assumed role → crown jewel
Kill chain stages
4 / 4
Initial access → RCE → lateral → data
Confidence
0.97
Runtime + identity + network agreement
Time to detect
2.4s
First indicator to opened incident
150+ MITRE ATT&CK detections, always current.
Curated detections for cloud, container and identity attacks — mapped to MITRE ATT&CK for Cloud and enriched with live threat intel. New TTPs land as detection updates within hours, not release cycles.
Every incident, explained in plain English.
Each incident ships with an LLM-written narrative citing the exact runtime, identity and audit evidence behind it — a shareable story your responders can act on, your CISO can brief, and your auditors can defend.
+2.0
eBPF
+1.8
C2 IP
+1.5
Identity
+1.5
Baseline
Kill, isolate, revoke — one click or automatic.
Response playbooks kill a rogue process, quarantine a workload, revoke a session or disable a leaked key — triggered automatically for high-confidence detections or with a single click for the rest. Every action integrates with Slack, PagerDuty and your SOAR of choice.
INC-4211 · Reverse shell
INC-4207 · Impossible travel
INC-4189 · Leaked AWS key
2
active
5
contained
92
resolved
Related solutions
Explore the platform
OnDuty is one platform on a single graph. Here's where the rest of it connects.
Stop chasing alerts
Catch the attack
before it spreads.
See real detections, response playbooks and the live threat graph in a 30-min guided demo with our team.
- <3s median detection — eBPF runtime, no sidecars
- One live threat graph across runtime, identity and cloud audit
- 150+ MITRE ATT&CK-mapped detections, auto-baselined to your env
- One-click isolate, revoke and SOAR playbooks built in
- Evidence for your SOC 2 · ISO 27001 · HIPAA · PCI audits