Windows-first SIEM and EDR for small IT teams
Endpoint security your whole IT team can read
Fyter watches every Windows endpoint, turns suspicious activity into incidents written in plain language, and tells you what to do next. Installed in an afternoon. No analyst required.
Fyter is in pilot. There is no self-serve signup yet.
Incidents
Enroll device- Open incidents
- 4
- Critical or high
- 3
- Devices online
- 47 / 52
- Detections today
- 9
| Severity | Incident | Device | Status | Last seen |
|---|---|---|---|---|
| critical | LSASS credential store access | DIRECTOR-LT | investigating | 4 min ago |
| high | Encoded PowerShell on FINANCE-01 | FINANCE-01 | open | 12 min ago |
| high | Microsoft Defender protection disabled | OUTREACH-02 | open | 38 min ago |
| medium | New scheduled task by a standard user | RECEPTION-01 | open | 2 hr ago |
| low | Local user created | FRONTDESK-03 | resolved | Yesterday |
Built for the team you have
Everything a security operations center does, without the operations center.
Incidents, not alerts
Related detections on one device roll into a single incident with a plain-language title, a severity, and the next step.
Windows telemetry, collected for you
The agent reads Security, Sysmon, PowerShell, and Defender logs and streams them signed, batched, and deduplicated.
Guarded response
Isolate a host or kill a process from the incident. Every action is confirmed, audited, and reversible.
Defender alerts alongside
Connect Microsoft Defender and its findings sit next to Fyter's own, in the same list, with the same triage.
One login, many tenants
Managed IT teams switch between organizations from the rail. Access is scoped per tenant and fully audited.
Notifications that reach you
Email and webhooks per severity, with per-user preferences and a delivery log you can check.
Detections
Rules written for how small organizations actually get breached.
Eleven curated rules across five MITRE ATT&CK tactics, each with a plain title and a next step. Suppress the noisy ones per tenant. Every rule ships in shadow first, so a bad release can never page you.
See the rule catalog| Tactic | Rule | State |
|---|---|---|
| Execution | Encoded PowerShell | Active |
| Execution | Office spawning a command shell | Active |
| Execution | Suspicious script block | Active |
| Persistence | New Windows service | Active |
| Persistence | Scheduled task created by a user | Active |
| Persistence | Run-key autostart written | Active |
| Persistence | Local user created | Active |
| Privilege escalation | Added to local Administrators | Active |
| Credential access | LSASS memory access | Active |
| Credential access | Browser credential store read | Active |
| Defense evasion | Defender protection disabled | Active |
How it works
Three steps between an event on a laptop and a decision on your screen.
- 01
Install the agent
One MSI, one enrollment token, or push it through Intune. The agent enrolls itself and starts reporting in seconds.
- 02
Telemetry streams in
Security, Sysmon, PowerShell, and Defender events arrive signed and deduplicated. Rules run on every one.
- 03
Decide and act
Open the incident, read what happened and why it matters, then isolate the host or close it as a false positive.
Pricing
Priced per endpoint, not per analyst.
Illustrative pricing during the pilot period. Plans are not yet available to buy.
Starter
One IT generalist, one organization.
$3per endpoint / month
- Up to 50 endpoints
- All detection rules
- Email incident alerts
- 30-day retention
Team
Most teamsA small team that shares on-call.
$5per endpoint / month
- Up to 250 endpoints
- Assignment, notes, audit trail
- Guarded response actions
- Defender alerts alongside
- 90-day retention
Organization
Multi-site nonprofits and managed IT.
Custom
- Unlimited endpoints
- Multiple tenants, one login
- Intune rollout support
- Longer retention and export