PROSENTRIQ attaches a kernel-level eBPF probe to your box in one command and starts scoring real traffic in under two minutes — in a mode that is structurally incapable of dropping a single packet. You decide when, or if, it's allowed to start blocking anything.
No credit card. No reboot. No Zeek installed until you say so.
This is the entire path from a cold box to enforced, monitored infrastructure. Each step is real and independently testable.
One command validates your API key against the Detection API before touching your system, then live-attaches prosentriq_observe.o — a build of the probe with every drop and redirect code path removed, not merely disabled. It cannot block traffic even if instructed to.
Behavioral baselining, GeoIP and reputation scoring, and threat correlation all run exactly as they would in production — you just see the output instead of the enforcement. The Threat Historian starts linking events across days immediately.
prosentriq-ctl enable-enforcement confirms your account and tier with the Detection API, swaps in the real enforcement probe, and logs the change to an audit trail. Reversible at any time with disable-enforcement.
The kernel agent enforces locally and never needs to phone home to function. The Detection API scores, correlates, and evolves rules across your whole fleet. Neither one is a thin client for the other.
Inspects packets at the kernel boundary before they reach userspace — efficient enough to run on every packet, hard to fake with a userspace agent.
Learns what "normal" looks like per host — process identity, memory legitimacy, connection patterns — instead of matching static signatures.
Scores and evolves firewall rules against real traffic automatically, without a human writing or approving each one.
Correlates low-and-slow attack patterns across days — a day-1 scan linked to a day-9 login attempt, the kind of thing signature tools miss entirely.
An attack detected on one node updates reputation data shared across your fleet through the Threat Hub, in minutes, not after a manual review.
Generates SOC 2, PCI DSS, and HIPAA control-mapped reports on demand — JSON, Markdown, or a signed-checksum PDF an auditor can verify.
A security tool that silently turns itself off during a network blip is worse than one that was never installed. PROSENTRIQ treats that as a design constraint, not an edge case.
Free to try in observation mode for as long as you want. Pay when you turn on enforcement.
An email and one command. The account exists before install.sh does anything to your system — not after.