What I Do
Set it up, tune it, teach you to read it
- Install the platform — on hardware you already own, or a small cloud server if you would rather not run one.
- Deploy agents to your Windows and Linux machines, servers and workstations alike.
- Tune the alerts so you are told about things that matter to your business, not the factory defaults.
- File integrity monitoring — you are told when a file that should never change, changes.
- Vulnerability reporting — which of your machines run software with known holes in it, and which to fix first.
- Configuration assessment — every machine scored against a hardening benchmark, with a plain list of what to correct.
- Train your people — which alerts mean pick up the phone, and which mean nothing.
- Written reports a business owner can act on. Not a wall of log entries.
How the agents actually arrive
Every machine you want watched needs a small program on it — the agent. How it gets there depends on what you already have, and it changes the cost, so it is worth being straight about it up front.
If you have a Windows domain
The agent is published once through Group Policy from your domain controller, and every machine installs it by itself at the next restart. Nobody walks anywhere. A fifty-machine office can be covered in an afternoon.
If you already have management software
Intune, PDQ, or whatever your IT company uses to push updates — the agent installs through that. It inherits your existing testing and reporting.
If you have neither
Then it is machine by machine, about ten minutes each, and I quote for that time honestly rather than discovering it halfway through. For a small office it is one visit. For a larger one we may set up a deployment method first — that pays for itself the second time you need it.
Linux and Mac
Handled with standard automation tools. One script, as many machines as you have.
Your switches, routers and firewall too
You cannot install software on a switch. That does not mean it goes unwatched — and for a lot of businesses these are the devices that matter most, because they are the front door.
- They send their logs to us. Managed switches, routers and firewalls all speak syslog. They are pointed at the monitoring server and report what they see: failed logins, ports going up and down, VLAN changes, errors.
- We watch the configuration. The system logs into the device and keeps an eye on its configuration — and tells you when it changes. Somebody quietly altering a firewall rule at two in the morning is exactly the event you want to hear about.
- Nothing to install. No agent, no software, no risk to the device.
- Printers, cameras, NAS. Anything on your network that can send a log can be brought in. The forgotten devices are often the ones with default passwords still on them.
One honest limit. This is security monitoring, not network management. It will tell you if somebody logs into your switch or changes its configuration. It will not draw you a topology map or graph your bandwidth — that is a different tool, and if you want it I will tell you which one rather than pretend this does it.