AI DEFENCEBY ALTARI SYSTEMS
Menu

Protection / After the initial assessment

Continuous threat monitoring against an accepted baseline.

Continuous threat monitoring compares current evidence with an accepted security baseline and emerging risk information. AI Defence is designed to identify new vulnerabilities, unexpected exposure and suspicious changes after the initial audit, while keeping response within customer-approved boundaries.

IN DEVELOPMENTExplore the specified scope. See capability availability.

A baseline is an explicit record of the expected environment

The specified baseline records known hosts, services, ports, users, packages, network paths, workloads, configuration and approved exceptions. It is established after findings and authorised changes have been reviewed. It must not silently treat every newly observed state as acceptable.

A legitimate release may introduce a service or change a package. Those changes should be reconciled with authorised work. Unexplained changes need investigation; approved exceptions need an owner and enough context to distinguish an accepted risk from an overlooked one.

  • Detect new devices, ports, services and newly exposed endpoints.
  • Detect account, privilege, SSH-key and security-configuration changes.
  • Detect suspicious processes, unexpected outbound connections and malicious indicators.
  • Track certificate expiry, exposed secrets and repository or dependency risks.
  • Identify attack attempts, anomalous behaviour and software becoming vulnerable.

Detection depends on usable telemetry

Authentication, system, application, web, network, firewall and audit logs provide different parts of the picture. AI Defence’s initial audit includes log availability, integrity, retention, alerting and centralisation, as well as blind spots that would limit future monitoring.

Continuous describes the intended ongoing operating model. It is not a promise that every event is detected instantly or that an unspecified uptime or response SLA applies. Collector availability, data freshness and supported detection coverage must be visible to the customer.

Keep suspicious, confirmed and resolved states separate

An unexpected connection or process is evidence to correlate, not automatic proof of an intrusion. Repeated signals, affected identities, exposure and known indicators can change the priority and confidence of a finding. The report should make that confidence understandable.

A monitoring alert does not automatically authorise isolation, credential revocation or firewall modification. Responses remain subject to the permitted scope. Following an approved action, the original condition and relevant service health need retesting before the incident is recorded as resolved.

Questions answered

Does monitoring mean automatic changes to my network?

No. Detection and remediation are separate capabilities. Customers determine which actions are authorised; the initial assessment is observational by default.

Can continuous monitoring guarantee no breach?

No. Coverage, telemetry and detection methods have limits. The design requires those limits and incomplete checks to be reported rather than presenting silence as proof of safety.

Start with understanding

What does your environment need to defend?

Discuss the assessment scope, current capabilities and the control you need with Altari Systems.

Talk to Altari