What a program starts, what starts it, and whether it reaches for powers it should not have.
Extend explainable
security to Windows
environments.
Sentra pre execution scanning, Helio behavioural monitoring and Vulco attack chain analysis in one desktop console, on the same intelligence layer that protects Android today.
-
Sentra pre execution scanning Every file is inspected and scored before it is allowed to run.
-
Helio behavioural monitoring Live tracing follows what a process does for its whole life, not just its launch.
-
Vulco attack chain correlation Rolling activity windows and completed process histories judge the sequence, then quarantine.
-
Emora memory behaviour Watches how a process behaves in memory, where threats hide once they are already running.
-
Styx encryption defence Catches mass encryption of your files early and stops it before the damage spreads.
What the Windows agent is designed to observe.
Each area carries its own status, so you can tell what is already designed from what is still on paper. Below is the console those signals report into.
System Overview
Real time Monitoring of all Active Detection engines
- Benign 62%
- Suspicious 26%
- Malicious 12%
| Time | Verdict | Target / Process | Score | Sensor Source | Full Path (Click to Inspect) |
|---|---|---|---|---|---|
| 12:04:31 | Benign | browser.exe | 0.02 | Sentra | C:\Program Files\Browser\browser.exe |
| 12:04:29 | Suspicious | script_host.exe | 0.87 | Helio | C:\Windows\System32\script_host.exe |
| 12:04:22 | Malicious | invoice_2026.pdf.exe | 0.99 | Sentra | C:\Users\Public\Downloads\invoice_2026.pdf.exe |
| 12:04:18 | Benign | system_service.exe | 0.01 | Helio | C:\Windows\System32\system_service.exe |
| 12:04:11 | Benign | editor.exe | 0.04 | Vulco | C:\Users\Public\Programs\Editor\editor.exe |
| 12:03:58 | Suspicious | module_loader.exe | 0.74 | Helio | C:\Windows\System32\module_loader.exe |
| 12:03:44 | Benign | file_manager.exe | 0.00 | Sentra | C:\Windows\file_manager.exe |
| 12:03:31 | Malicious | cred_dump.exe | 0.97 | Vulco | C:\Users\Public\Samples\cred_dump.exe |
Sentra Scan Activity
Files inspected and scored before they are allowed to run
| Timestamp | Verdict | File Name | Confidence | Detected by | System Path (Click to Inspect) |
|---|---|---|---|---|---|
| 12:04:31 | Benign | browser.exe | 0.02 | Sentra | C:\Program Files\Browser\browser.exe |
| 12:04:22 | Malicious | invoice_2026.pdf.exe | 0.99 | Sentra | C:\Users\Public\Downloads\invoice_2026.pdf.exe |
| 12:04:18 | Benign | system_service.exe | 0.01 | Sentra | C:\Windows\System32\system_service.exe |
| 12:04:11 | Benign | editor.exe | 0.04 | Sentra | C:\Users\Public\Programs\Editor\editor.exe |
| 12:03:44 | Benign | file_manager.exe | 0.00 | Sentra | C:\Windows\file_manager.exe |
| 12:03:31 | Malicious | cred_dump.exe | 0.97 | Sentra | C:\Users\Public\Samples\cred_dump.exe |
| 12:03:02 | Benign | web_client.exe | 0.02 | Sentra | C:\Program Files\Browser\web_client.exe |
| 12:02:29 | Benign | runtime.exe | 0.06 | Sentra | C:\Runtime\runtime.exe |
Helio Behaviour Monitor
Real time behavioural analysis of processes while they run
| Time | EDR Verdict | Process Name | Score | Source Path (Click to Inspect) |
|---|---|---|---|---|
| 12:04:31 | Benign | browser.exe | 0.02 | C:\Program Files\Browser\browser.exe |
| 12:04:29 | Suspicious | script_host.exe | 0.87 | C:\Windows\System32\script_host.exe |
| 12:04:18 | Benign | system_service.exe | 0.01 | C:\Windows\System32\system_service.exe |
| 12:04:11 | Benign | editor.exe | 0.04 | C:\Users\Public\Programs\Editor\editor.exe |
| 12:03:58 | Suspicious | module_loader.exe | 0.74 | C:\Windows\System32\module_loader.exe |
| 12:03:31 | Malicious | cred_dump.exe | 0.97 | C:\Users\Public\Samples\cred_dump.exe |
| 12:03:20 | Benign | messaging.exe | 0.03 | C:\Users\Public\Programs\Messaging\messaging.exe |
| 12:02:47 | Suspicious | script_runner.exe | 0.81 | C:\Windows\System32\script_runner.exe |
Vulco Attack Chain Analysis
Rolling activity windows and completed process histories, reviewed side by side
| Time | Verdict | Process Name | Confidence | Analysis | Source Path (Click to Inspect) |
|---|---|---|---|---|---|
| 12:04:31 | Benign | browser.exe | 0.04 | Vulco · rolling window | C:\Program Files\Browser\browser.exe |
| 12:04:12 | Malicious | cred_dump.exe | 0.96 | Vulco · rolling window | C:\Users\Public\Samples\cred_dump.exe |
| 12:03:58 | Suspicious | script_host.exe | 0.79 | Vulco · rolling window | C:\Windows\System32\script_host.exe |
| 12:03:41 | Benign | system_service.exe | 0.01 | Vulco · full history | C:\Windows\System32\system_service.exe |
| 12:03:27 | Malicious | invoice_2026.pdf.exe | 0.99 | Vulco · full history | C:\Users\Public\Downloads\invoice_2026.pdf.exe |
| 12:03:04 | Benign | editor.exe | 0.03 | Vulco · rolling window | C:\Users\Public\Programs\Editor\editor.exe |
| 12:02:49 | Suspicious | module_loader.exe | 0.72 | Vulco · full history | C:\Windows\System32\module_loader.exe |
| 12:02:33 | Benign | file_manager.exe | 0.00 | Vulco · full history | C:\Windows\file_manager.exe |
Unified Threat Incident Center
Consolidated real time detections from Sentra, Helio and Vulco.
Click any path to reveal and inspect the artifact in Windows Explorer.
- C:\Users\Public\Downloads\invoice_2026.pdf.exe0.99Detections: 14
- C:\Users\Public\Samples\cred_dump.exe0.97Detections: 9
- C:\Windows\System32\script_host.exe0.87Detections: 6
- C:\Users\Public\Temp\tmp7c41\setup.exe0.84Detections: 5
- C:\Windows\System32\script_runner.exe0.81Detections: 4
- C:\Windows\System32\module_loader.exe0.74Detections: 3
- C:\ProgramData\updater\update.exe0.71Detections: 2
| Time | Classification | Confidence | Detection Source | Full Path (Click to Inspect) |
|---|---|---|---|---|
| 12:04:29 | Suspicious | 0.87 | Helio | C:\Windows\System32\script_host.exe |
| 12:04:22 | Malicious | 0.99 | Sentra | C:\Users\Public\Downloads\invoice_2026.pdf.exe |
| 12:03:58 | Suspicious | 0.74 | Helio | C:\Windows\System32\module_loader.exe |
| 12:03:31 | Malicious | 0.97 | Vulco | C:\Users\Public\Samples\cred_dump.exe |
| 12:02:47 | Suspicious | 0.81 | Helio | C:\Windows\System32\script_runner.exe |
| 11:58:02 | Malicious | 0.94 | Vulco | C:\ProgramData\updater\update.exe |
| Time | Status | Detection Source | Full Path |
|---|---|---|---|
| 09:14:20 | Remediated | Sentra | C:\Users\Public\Downloads\unknown_setup.exe |
| 08:51:07 | Remediated | Helio | C:\Windows\Temp\module_host.exe |
| 08:22:39 | Downgraded | Vulco | C:\Program Files\Archiver\archive_tool.exe |
| 07:40:11 | Remediated | Sentra | C:\Users\Public\Documents\payload.bin |
| 07:02:55 | Downgraded | Helio | C:\Windows\System32\cert_tool.exe |
What a file really is, who signed it, and whether it has arranged to come back after a restart.
Where the machine is talking to, whether that destination is trusted, and whether the pattern is normal for it.
Files being read or rewritten in bulk, and quiet changes to the settings that decide what runs next.
Which account was used, from where, and whether that fits how the person normally works.
What gets plugged in, what runs from it, and how much leaves the machine that way.
Where Windows support stands today.
Real phase names and honest status. A dated roadmap builds more trust than a vague "coming soon".
-
Complete
Research & architecture
Signal sources, model line up and console architecture settled, and proven against the engine that already runs on Android.
-
In progress
Internal prototype
Sentra, Helio and Vulco running in the desktop console against a controlled internal test fleet.
-
Next
Design partner preview
Limited release to selected organisations, with Emora and Styx next on the list.
-
Planned
General availability
Full console integration, automatic remediation policy and unified cross platform reporting.
Help shape what ships first.
We are looking for a small number of organisations already running ARGUS on Android who want a say in how the Windows agent behaves. Here is exactly what that involves.
- Early access to preview builds
- Direct line to the engineering team
- Influence over the detection backlog
- Preferential terms at launch
- A test fleet of 10+ endpoints
- Monthly feedback session
- Permission to use anonymised findings
- A named technical contact
Be part of the Windows preview
Want early access?
Tell us about your endpoint estate and we'll include you in the
design partner programme as builds become available