Skip to content
Self-hosted or hosted: Compare the two

Security

Detections from endpoints and Microsoft 365 in one queue

The agent ships Windows event logs, macOS and Linux logs, and Microsoft 365 sign-in signals come in from the tenants you manage. Rules turn them into detections with the device, the user and the evidence attached.

Security detections with severity, customer and device

Endpoint signals

Encoded PowerShell, event log clearing, new local admins and brute force patterns.

Microsoft 365 signals

Password spray, sign-ins from new countries, risky users and forwarding inbox rules.

Triage that fits

New, investigating and closed statuses with severity and owner.

Page someone

Critical detections can page the on-call technician.

Every detection has its evidence

Open a detection to see what fired, the raw events behind it, the device or user involved and what else happened around the same time. Remote in or raise a ticket from the same page.

  • Linked to the customer, device and user
  • Raw events kept with the detection
  • Status and ownership for triage
A security detection with its events and the affected device

See Tenvara running an MSP.

A 30 minute walkthrough on a call, with the real product and real questions. Bring the awkward ones about moving over, pricing and self-hosting.