AI threat detection

Detection that reasons about behaviour, not just about files

Modern intrusions do not drop malware — they log in, they live off the land, they move sideways through legitimate tooling. Guardian Sentinel models what every identity, process and workload normally does, then flags the deviation in under five seconds and explains it in language an analyst can act on immediately.

214 MITRE ATT&CK techniques with production detection coverage
4.9s p95 time from first malicious behaviour to scored detection
0.7% False-positive rate on analyst-facing incidents, fleet median
27 Incidents surfaced per 10,000 endpoints per day, after AI triage
340 Named adversary groups tracked and modelled by Guardian Labs

Detection pipeline

Six stages between a system call and a contained host

Each stage has a latency budget and a published failure mode. The first three run on the endpoint or sensor itself, which is why detection keeps working when the network does not.

Signal lifecycle — median cumulative latency, 100,000-endpoint tenant 010203 040506 Collect Normalise Score Correlate Reason Act Kernel & sensor event capture no polling OCSF record entity keys edge suppression On-device models sequence + static works offline Attack graph cross-surface blast radius AI Analyst narrative + evidence ATT&CK mapping Policy decision isolate / kill / revoke or route to analyst 0.4 ms 9 ms 140 ms 1.1 s 3.2 s 3.8 s Stages 01–03 execute on the host or sensor. Stages 04–06 execute in the control plane and queue locally if it is unreachable.

Scroll horizontally to see the full pipeline on a small screen.

Behavioural analytics

Baselines are per-entity, not per-organisation

A domain controller and a designer's MacBook should not be judged against the same statistical distribution. Sentinel maintains an independent behavioural profile for every asset, identity, service account and workload, refreshed continuously over a rolling 30-day window and weighted by peer-group similarity.

Process lineage, not process names

Detections evaluate the whole ancestry chain. powershell.exe spawned by Excel through WMI is a different event from the same binary launched by SCCM.

Peer-group anomaly scoring

Every identity is scored against colleagues with comparable entitlements, so a finance analyst touching source control registers even when volume looks normal.

Temporal sequence models

Order and timing carry signal. Discovery, then credential access, then an SMB write within nine minutes scores far higher than any of those events alone.

Cross-surface stitching

An endpoint anomaly, an unusual SSO location and a new cloud role assumption become one incident with one score, not three unrelated alerts in three queues.

Why baselining is not enough on its own. Pure anomaly detection drowns analysts in novelty. Sentinel gates every anomaly through adversary-behaviour priors from Guardian Labs, so “unusual” only becomes “alertable” when it also resembles something an attacker would actually do next.

Model portfolio

Nine model families, each with a job it is actually good at

There is no single model that catches everything. Sentinel runs an ensemble in which each member is narrow, measurable and independently replaceable — and where the decision is made by the correlation layer, not by any one model's confidence score.

Model portfolio as of the 2026.7 platform release. Refresh cadence is the median interval between retrained model promotions.
Model family Approach Primary signal Runs Refresh
Static file classifier Gradient-boosted ensemble over 1,900 structural features Portable executables, Mach-O, ELF, Office and PDF containers On device Weekly
Behavioural sequence model Transformer over ordered event sequences with entity context Process lineage, file and registry operations, API calls On device Bi-weekly
Living-off-the-land classifier Command-line and script-block embedding with intent labelling PowerShell, WMI, bash, certutil, rundll32, MSHTA On device Weekly
Ransomware canary monitor Deterministic entropy and write-pattern heuristics Bulk file rewrite, shadow-copy deletion, extension churn On device Continuous
Identity anomaly model Peer-group density estimation with impossible-travel geometry Authentication, token issuance, entitlement change Control plane Daily
Beaconing detector Periodicity and jitter analysis over flow metadata Connection cadence, byte ratios, TLS fingerprints Sensor + control plane Weekly
Cloud control-plane model Sequence scoring over provider audit events with role graphs IAM changes, key creation, snapshot and share operations Control plane Daily
Data movement model Volume, destination and classification-aware egress scoring Uploads, mailbox rules, external shares, USB writes Control plane Weekly
Attack-graph reasoner Probabilistic path scoring across the entity graph All of the above, plus asset criticality and exposure Control plane Continuous

Scroll the table horizontally to see every column.

Every model release is shadow-scored against 30 days of your own telemetry before promotion, and the projected change in alert volume is published in the console first.

MITRE ATT&CK

Coverage measured honestly, tactic by tactic

Vendors who claim uniform coverage are usually counting rules, not detections that survive an evaluation. Guardian publishes per-tactic coverage against ATT&CK Enterprise v18, including where we are deliberately weaker.

Pre-compromise tactics — reconnaissance and resource development — score lower by design: they largely occur on infrastructure we do not observe. We surface them through Guardian Labs intelligence rather than pretending endpoint telemetry can see them.

  • 214 of 231 in-scope techniques have at least one production detection
  • 171 techniques have two or more independent detection paths
  • 96% analytic coverage — detections that carry context, not just telemetry
  • Coverage map exported to your GRC tooling through the API
Detection coverage by ATT&CK tactic Enterprise v18 Credential access Execution Lateral movement Privilege escalation Impact Discovery Persistence Defense evasion Command & control Initial access Exfiltration Collection Reconnaissance Resource development 98% 97% 97% 96% 96% 95% 94% 93% 92% 91% 90% 89% 62% 48% Percentage of in-scope techniques with at least one production detection, measured March 2026.

Scroll horizontally to see the full chart on a small screen.

Signal to noise

From two billion events to twenty-seven decisions

Alert fatigue is not a training problem, it is an architecture problem. Sentinel discards, aggregates and reasons at every stage so the queue an analyst opens contains work that is genuinely worth a human.

One day, one tenant, 10,000 endpoints 1.94 B 248 M 6.1 M 41,600 1,180 27 Raw telemetry events observed Retained after edge suppression Matched a behavioural signal Scored above anomaly threshold Correlated candidate incidents Analyst-facing incidents Of the final 27, a median of 3 need human action; 24 are auto-contained with evidence attached.

Scroll horizontally to see the full chart on a small screen.

Detection in practice

A worked example: from phished session to contained estate in 41 seconds

A real detection sequence, reconstructed from a customer environment with identifying details changed. No malware was ever written to disk.

  1. T+00:00 · Identity

    Valid session, wrong geometry

    A contractor identity authenticates successfully with a legitimate MFA response from a residential ASN in a country the account has never used. On its own: a low-confidence signal worth 0.31. Sentinel scores it and waits.

  2. T+00:06 · Cloud

    Role assumption outside the peer envelope

    The session assumes ci-deploy-prod, a role this identity holds but has used twice in 14 months. Peer-group density scoring lifts the composite to 0.58 and opens a candidate incident in the attack graph.

  3. T+00:19 · Endpoint

    Discovery from a jump host

    On a bastion the same session reaches, net group "Domain Admins" and an LDAP enumeration run within eleven seconds of each other. The sequence model recognises the ordering as T1087 and T1069. Composite score 0.84.

  4. T+00:33 · Network

    Beacon with matching TLS fingerprint

    The bastion opens a periodic outbound session with a JA4 fingerprint Guardian Labs attributes to a known access-broker toolkit. The intelligence prior collapses ambiguity: composite 0.97, severity critical.

  5. T+00:41 · Response

    Contained on every surface at once

    Policy fires: the bastion is network-isolated, the SSO session and refresh token are revoked, the assumed role's temporary credentials are invalidated, and the outbound destination is blocked estate-wide. The AI Analyst files the incident with a full narrative, ATT&CK mapping and a preserved evidence bundle.

Three more detections worth understanding

Ransomware precursor: shadow-copy deletion under a legitimate parent

An operator drops a signed remote-management binary — allowed by policy, present in a third of enterprises — then uses it to invoke vssadmin delete shadows /all /quiet and disable recovery. No file in the chain is malicious.

What fires: the ransomware canary monitor detects shadow-copy destruction, the sequence model recognises the tool-then-destroy ordering, and the lineage check notes that the RMM binary was installed 90 seconds earlier by a process with no software-deployment provenance. Median time to kill and isolate: 1.9 seconds, entirely on device.

See endpoint security for the rollback behaviour that reverses any encryption that did complete.

Kerberoasting followed by service-account lateral movement

A standard user account requests service tickets for 14 SPNs in 40 seconds with RC4 encryption explicitly negotiated — a downgrade no modern client asks for. Twenty minutes later one of those service accounts authenticates to three file servers it has never touched.

What fires: the identity anomaly model flags the encryption downgrade and SPN request burst as T1558.003; the attack-graph reasoner links the cracked service account to the original requesting host and scores the blast radius using the account's actual entitlements, not its nominal group membership.

See identity protection for directory-level controls.

Cloud key exfiltration through a legitimate CI pipeline

A compromised build runner adds a step that reads a secrets-manager entry and writes it to a build artefact, which is then published to an external registry. Every API call is authorised; the pipeline definition change went through an approved merge.

What fires: the cloud control-plane model scores the secret read as anomalous for that runner's historical pattern, the data-movement model recognises the artefact's classification and external destination, and the IaC scanner surfaces the pipeline diff that introduced the step. Containment revokes the secret and quarantines the artefact before the registry push completes.

See cloud security for pipeline and runtime coverage.

Trust and tuning

Detection you can audit, challenge and change

Black-box scoring is a governance failure waiting for an incident review. Every Sentinel detection exposes the evidence, the model version and the policy that acted on it.

Explainable by construction

Each incident carries the contributing signals, their individual weights, the raw events behind them and the exact model build that scored them. Nothing in the record says “because the model said so”.

Shadow scoring before promotion

New models run silently against 30 days of your telemetry. You see the projected alert delta, the newly caught cases and the newly suppressed ones before anything changes in production.

Feedback that actually lands

Marking a detection false-positive creates a scoped, reviewable exception tied to entities and conditions — not a global rule disable that quietly blinds the estate.

Your own detection content

Author detections in Sentinel Query Language, import Sigma rules natively, unit-test them against recorded telemetry, and promote through environments with the API.

Continuous adversary emulation

Scheduled safe emulations run 180 ATT&CK techniques against a control group of your own hosts every month and report what did and did not fire.

Model rollback for 180 days

If a promotion changes behaviour you did not expect, revert that detection family to any previous build in one action, with a full audit record of who and why.

The first thing I asked for was the evidence trail behind an autonomous containment, because my board will ask me the same question. Guardian was the only vendor that could show me the raw events, the model build and the policy clause in one screen.
Sofia Haugen Chief Information Security Officer, Meridian Health Group

Bring us a technique you think we would miss

Our solutions architects run adversary emulations live in a demo tenant. Pick the tradecraft — living off the land, token theft, container escape — and watch what fires and why.