QNova Client · Endpoint detection and response

Detection that contains first and asks afterwards

Endpoint detection and response in the QNova Client watches each Windows device with eleven engines. When one of them fires, the whole process tree is suspended on the thread that caught it, before anyone sees a decision card. Two kernel drivers sit underneath the agent.

What it is

The gap between seeing something and stopping it

Nearly every endpoint tool sees the bad thing. What separates them is what happens in the next two seconds. The usual sequence: an engine flags a process, an alert gets written, a prompt appears, and through all of it the process keeps running. On a normal Tuesday that gap costs nothing. During a ransomware run it is the whole story. You have had the thought yourself, reading one of those prompts: is it still going while I am reading this? Usually, yes.

Contain first, ask second

When an engine detects something, the agent suspends the process tree right there, on the thread that did the detecting. Not after a queue, not after the event reaches a server, not after a person picks an option. The card that asks what to do shows up afterwards.

Eleven engines, overlapping on purpose

Each one watches a different tell. Something built to look innocent on its command line has a harder time looking innocent while it also writes a startup key and reaches for credentials. One engine is a checkbox. Eleven overlapping ones are a net.

A trade we will name out loud

You will occasionally freeze something that turned out to be fine. That is recoverable. The other order is not, because the encryption does not pause while a dialog box waits for somebody to get back from lunch.

The mechanism

The same four steps. Only the suspension moves.

Pick an engine to see what it watches, then walk the four steps. Both lanes see the same thing at the same moment. In one of them the process is still running when a person is asked what to do about it.

process chaincommand linefile pathregistryfile droppingcredential accessnetwork behaviourkernel tracingin-memoryransomwarestartupwatches: a child process no parent of that kind should ever startThe usual orderthe process is runningan engine firesthe alert is writtenthe card is showna person answersContain first, ask secondthe process is runningan engine firesthe tree is suspendedthe card is showna person answerssame four steps, and the suspension is in a different place
nothing has happened yet

Eleven detection engines sit above two lanes: process chain, command line, file path, registry persistence, file dropping, credential access, network behaviour, kernel event tracing, in-memory injection, ransomware behaviour and startup persistence. Selecting one shows the tell it watches. Below, the same four steps run in both lanes: an engine fires, the alert is written, the card is shown and a person answers. In the usual order the process is still running through all four, and only stops when somebody chooses an option. In the QNova order the process tree is suspended at the second step, on the thread that did the detecting, so by the time the card is shown the thing it is asking about is already frozen. The four steps are identical. Only the position of the suspension is different, and that is the whole argument.

Why this exists

Four things that go wrong without it

The prompt is not the protection

A dialog box is a request for attention. Anything that keeps running while it waits has made the person at the keyboard part of the control loop.

One engine is a checkbox

Anything written to look innocent on one dimension will look innocent on that dimension. It is the overlap that catches it, not the individual rule.

A rule name is not an instruction

A switch labelled with an internal rule identifier tells an administrator nothing at nine in the morning on a rollout day, which is exactly when they need to decide.

Software that can be switched off is not protection

If a process that just landed on the machine can turn the agent off, everything above this line was decoration.

What you get

One agent, two arguments

The person who rolls it out wants switches they can explain to a room. The person who signs for it wants to know who checked the code and what it does not do yet.

For the rollout

Switches written for a person

Nine plain-language categories plus three engine features. You will never see the name of an internal rule. Every switch says what it does, gives a real scenario, and where one exists, a warning about what it can break.

Analysis that fails closed

Executables are checked against the signature catalogue, documents for macros, PDFs for embedded scripts and launch actions, scripts for the download-and-run pattern. If the analysis cannot finish, the file does not get the benefit of the doubt.

Cleanup that covers everybody on the machine

Remediation enumerates the real interactive profiles, so something that installed itself for five accounts gets removed from five.

For the business

Somebody independent looked at the code

Microsoft has authorised us to distribute kernel drivers. That is kernel driver authorisation and nothing wider: not a certification, not a partnership. We mention it because the honest objection to buying security from a company our size is who checked this, and that is the answer.

It cannot be turned off by what it is protecting you from

The rule store lives in a directory only administrators can write to, changes travel by named pipe to a service that refuses privileged commands from callers that are not elevated, and elevation goes through the consent dialog of the operating system.

You will know the platform gaps before you buy

Windows has everything on this page. Linux has detection and none of the containment. macOS and iOS are planned rather than shipped. That is on this page on purpose.

How it works

Three steps, and two of them happen before anyone is asked

Something starts, and eleven engines are already watching

Process chain, command line, file path, registry persistence, file dropping, credential access, network behaviour, kernel event tracing, in-memory injection, ransomware behaviour and startup persistence. They overlap on purpose, because anything written to look innocent on one of those has a harder time looking innocent on three of them at once.

The tree is suspended on the thread that caught it

Not after a queue, not after the event reaches a server, not after a person picks an option. Then, and only then, the person at the keyboard gets a decision card about a process that has already stopped, written in the language they use rather than in rule names. Most days they see nothing at all, which is the point.

You decide what happens to it, one finding at a time

A scan runs quick or full, with live progress, an estimated time and a cancel button that works, and each finding can be ignored, quarantined or trusted on its own. Scheduled scans run anywhere from every hour to every thirty days and keep a history of what ran and when. The rest of the fleet picture lives in endpoint monitoring.

Before you start

You need the client on the Windows machines you want protected, and an administrator to choose which folders the anti-ransomware driver guards, because that part is off until somebody turns it on.

In detail

Two kernel drivers, and what each one is for

Prevention

The sensor that sees a process start

It takes synchronous notifications when processes start and exit, so there is no polling and no race to lose. Execution denial runs a verdict path ordered by speed: cache first, then whether the file sits under the system directory, then whether it is validly signed, then a content scan.

It strips handle rights on the credential process of the operating system, and on the service itself, instead of denying access outright, which protects both without wedging the machine. Auto-start persistence is blocked in real time.

Anti-ransomware

A separate driver guarding the folders you name

It is an isolated driver, not a mode of the first one. Untrusted processes can read what is in the folders you configure and cannot modify, overwrite, delete or rename anything in them. Scanning happens on access, so an infected file on a memory stick is refused the moment something touches it, not at the next scheduled scan. Silent downloads are refused the same way.

Read the limit below before you count on it: folder blocking is off by default, and its posture is fail-open. Somebody has to turn protection on for the folders that matter.

Where this earns its place

Four mornings this changes

A ransomware run starts at 02:40

The tree is suspended on the thread that caught it, before any card exists to be answered. Nobody had to be awake for that part.

An infected file arrives on a memory stick

Scanning happens on access, so it is refused the moment something touches it rather than at the next scheduled scan.

A rollout day, and you have to explain the switches

Nine plain-language categories, each with a scenario and a warning about what it can break. You can read them out in a meeting.

Something installed itself for five accounts

Remediation enumerates the real interactive profiles, so it comes off five, not off the one that happened to be signed in.

Works better with

What surrounds the agent on the machine

The same anti-ransomware driver, read from the angle of the thing it is there to stop, with the folder posture explained at length.

What the console does with everything this records: alerts, rules, hosts, CVEs and the order in which to fix things.

The port the infected memory stick arrived on, and the policy that decides whether it is allowed to be there at all.

How protection settings travel to the fleet as a signed company policy rather than as a visit to each desk.

What this does not do

The limits, because they are what make the rest believable

It is not the same product on every platform

Windows has everything on this page. On Linux there is detection and none of the containment described here. macOS and iOS are planned, not shipped, and we would rather you read that now than find it in a rollout.

Folder blocking is off by default

The posture of the anti-ransomware driver is fail-open, so somebody has to turn protection on for the folders that matter. If the driver is not loaded, the service says so plainly and reports that it is running in user mode only.

It will sometimes freeze something that was fine

That is the trade, and it is the one we chose deliberately. A false suspension is recoverable in a minute. The other order is not recoverable at all.

Nobody here is watching your network

This is not managed detection and response, and there is no analyst on a rota. The product detects, contains and records. Your people read it.

Questions people ask

The ones that come up first

What is endpoint detection and response here?

Eleven detection engines on each Windows device, two kernel drivers underneath the agent, and one rule about ordering: when an engine fires, the process tree is suspended on the thread that caught it, before any card is shown to anybody.

Why suspend before asking?

Because the alternative leaves the process running while an alert is written, a prompt appears and somebody decides. On a normal Tuesday that gap costs nothing. During a ransomware run it is the whole story.

What if it suspends something that was fine?

It happens, and it is recoverable in a minute. That is the trade we chose out loud rather than hid. Each finding can be ignored, quarantined or trusted on its own.

Who checked the kernel drivers?

Microsoft has authorised us to distribute kernel drivers. That is kernel driver authorisation and nothing wider, so it is not a certification and it is not a partnership. We say it because the honest objection to buying security from a company our size is who checked this code.

Can malware switch the agent off?

The rule store sits in a directory only administrators can write to. Every change travels by named pipe to the system service, which refuses privileged commands from a caller that is not elevated, and elevation goes through the consent dialog of the operating system. Turning it off takes a real administrator and a real prompt.

Is this managed detection and response?

No. There is no analyst on a rota here and nobody watches your fleet. The product detects, contains and records, and your people read it in your console.

Bring a machine and we will suspend something on it.

We run a detection on a real device, show you the card arriving after the process is already frozen, and walk the nine switches with you. It is free, it lasts as long as you want, and there is nothing to sign.

Scroll to Top