How it works

From source to verdict, in three moves

VigilanceX deploys without touching your administrator accounts and without heavy agents. Here is the full journey, from collection to notification.

Step 1: Active Directory collection

Direct collection, no administrator account

A ready-to-use installation kit runs directly on each domain controller. The account used is a least-privilege service account: VigilanceX reads the logs, and nothing else.

Ready to use

Direct installation kit

The kit installs in a few minutes on each domain controller, with a guided installation. Logs flow without any intermediary.

  • Ready-to-use kit, guided installation
  • Direct collection from each domain controller
  • Least-privilege service account: never an administrator account
Silent servers. VigilanceX monitors silent servers: if a source stops sending logs, you are notified.
Step 2: Sophos Central pairing

Each tenant linked to its own account

Pairing is done tenant by tenant: each keeps its own Sophos Central account, licenses and data. VigilanceX pulls XDR/MDR detections and blocks, then correlates them with the Active Directory activity of the same accounts, machines and IP addresses.

  • Endpoints, servers, firewalls, e-mail depending on licenses
  • Malware cleaned, exploit stopped, website blocked, firewall threats, e-mail alerts
  • Automatic correlation with accounts, machines and IPs seen in Active Directory
Step 3: The alert lifecycle

Five steps, from event to decision

01

The event arrives

A domain controller log or a Sophos Central detection enters the corresponding tenant.

02

The rules engine evaluates

The tenant's rules (default rules provided and tunable) qualify the event and raise an alert when needed.

03

The alert is contextualized

Severity from LOW to CRITICAL, accounts, machines and IP addresses involved, recent tenant history.

04

The AI agent analyzes

On demand or automatically based on severity: reads the alert, runs read-only queries on tenant data, enriches with file, URL and IP reputation. Structured verdict with evidence, MITRE ATT&CK techniques and recommendations.

05

The notification goes out

E-mail and Telegram, in the tenant's language. System events (failed import, new source, failed Sophos connector, analysis completed) are notified the same way.

The easiest way is to see it running

A guided demonstration on a demo tenant, with fictional data.

No public pricing: every deployment is scoped with you. Request a demonstration.

Request a demonstration
HostCitadel