The appliance reads the traffic passively from a switch mirror port, across more than 20 network protocols. Unusual connections, misconfigured hosts and data leaving the network show up even on machines with nothing installed.
Ombra, the Kondra endpoint agent, adds what the network cannot see: the applications installed on each machine and how it is configured. Changes to Active Directory users, groups and group policies are recorded too, so a new admin account is an event Kondra can alert on.
Auditors and regulators ask the same questions after every incident: what happened, when, and what was done about it. With Kondra the answers are already on record. Every event is searchable, the EXYS SOC opens a case with the logs and indicators of compromise (IoC) attached, and the forensic report is written from the same data. Retention is set per customer, so logs are kept as long as your auditors, regulators or internal policies require. EXYS itself is ISO 27001 certified.