QS-WAN · Endpoint telemetry

Endpoint monitoring that admits when it cannot see

Endpoint monitoring here is thirteen linked views of what your devices are doing: alerts, rules, hosts, logins, compliance checks, MITRE ATT&CK coverage, CVEs, inventory and a posture score that ranks what to fix first. It runs on telemetry from the agent on each machine, and it says so plainly when that telemetry is not there.

What it is

The problem is not missing data. It is a screen that cannot tell the difference.

Most consoles have exactly one way to show nothing, and that is an empty chart. So a host with zero alerts and a host whose agent stopped reporting three weeks ago look identical on the wall. You have refreshed a quiet dashboard and wondered, for about a second, whether it was quiet because everything is fine or because nothing is talking. Then you moved on, because there were four other things on fire. Here they are two different states. No data means the host had nothing to report. Could not get data means the pipe is down and you should go and look at the pipe.

Alerts, and the rules behind them

The Alerts Explorer filters, inspects and manages endpoint alerts without pre-loading expensive payloads, so it stays quick on a busy fleet. The Rules Explorer shows which detection rules fire most, and drills straight down into the alerts that tripped them.

Hosts, logins, CVEs and configuration

Per-host alert activity, risk signals, vulnerability exposure and inventory context in one place, plus login activity and failed access patterns with source attribution. Compliance scores passed over passed plus failed, leaving out anything marked not applicable.

Posture, which is the page that tells you what to do on Monday

It combines per-host risk, vulnerability pressure, KEV exposure, MITRE breadth and internet exposure into a remediation order. Not a grade. An order.

The mechanism

Turn a signal off and watch the queue change its mind

Five hosts, five signals, one order. Then stop the agent on the first machine and watch where it goes: out of the queue, with no position and no score, because a host nothing has heard from is not the same thing as a host with nothing to report.

Remediation ordercombined signal1fin-lap-04risk 72CVEs 61KEV 88MITRE 40exposure 1201dc-srv-01risk 48CVEs 84KEV 30MITRE 66exposure 9101ops-lap-11risk 90CVEs 35KEV 10MITRE 74exposure 2201whs-tab-07risk 26CVEs 70KEV 55MITRE 18exposure 6401eng-lap-02risk 61CVEs 44KEV 72MITRE 88exposure 350not a grade, an order
5 hosts ranked on 5 signals

Five hosts, fin-lap-04, dc-srv-01, ops-lap-11, whs-tab-07 and eng-lap-02, are placed in a remediation order. Each carries five numbers: per-host risk, CVE pressure, KEV exposure, MITRE breadth and internet exposure. Switching any of the five signals off recalculates the combined figure and the queue changes order, which is what it means to say the page hands you an order rather than a grade. The last control stops the agent on fin-lap-04. That host then leaves the queue entirely and reads could not get data, with no position and no score, rather than falling to the bottom of the list as though it had nothing to report. A host with nothing to report and a host nothing has heard from are two different facts.

Why this exists

Four things that go wrong without it

A quiet dashboard is a question, not an answer

One way of showing nothing means a healthy host and a dead agent look the same. You carry that doubt around all week and never quite act on it.

Everybody has a list, nobody has an order

A grade tells you how bad things are. It does not tell you which machine to open first, and that argument eats the first twenty minutes of every meeting.

The interesting half is the half the person cannot see

Four failed logins is a Monday and a keyboard, almost always. What makes it worth looking at is the package on the same machine with a CVE somebody is actively exploiting.

Proving any of it takes a fortnight of archaeology

When a customer or an assessor asks in writing, reconstructing configuration results across a fleet from scratch is the expensive way to answer.

What you get

One fleet, two completely different questions

The person who runs the network wants to know which machine to open first on Monday morning. The person who signs the invoice is thinking about the week somebody asks you to prove any of it, in writing, by Friday.

For the network

An order, not a grade

Posture hands you a queue rather than a letter, and the argument about what goes first is over before the meeting starts.

Silence you can actually trust

A quiet host and a dead agent are two different states with two different words, which means a quiet dashboard is information instead of a small private worry.

Nobody gets a phone call

Alert activity, failed logins, installed packages and configuration results arrive from the agent. You never ask two hundred people to check something and report back, which is fortunate, because that has never once worked.

For the business

The audit evidence is already sitting there

Configuration assessment is scored and tiled by passed, failed, not applicable and hosts with failures. That is a screenshot, not a fortnight of archaeology.

Thirteen views, one console, one login

They live next to the gateways and user profiles you already manage. Every extra tool you buy is also a licence, an integration and the least favourite Thursday of somebody.

You know what it cannot see before you buy it

The partial state of on-demand device intelligence and the best-effort delivery are on this page on purpose. Finding the limits after signing costs a great deal more.

How it works

Three steps, from a laptop in accounts to a decision you can defend

Something happens on a laptop, and nobody files a ticket

It is Monday, 7:42, and someone in accounts fails their login four times before the coffee lands. Four failed logins before coffee is almost always a keyboard and a Monday, and almost always is the part that costs you. The agent records it anyway, along with the packages installed and the configuration checks that passed and failed, and none of that asks the person to notice, decide or report a thing. The one piece they control is the device inventory in the QNova Client, which is a single toggle in settings.

The same morning reaches your console, with context they never had

Those failed logins land on the authentication page with source attribution and the events around them. The same machine has its own row on the hosts page, carrying alert activity, risk signals, vulnerability exposure and inventory context, so you find out that the laptop with four failed logins is also running a package with a CVE somebody out there is actively exploiting. And if the agent went quiet three weeks ago, the page says it could not get data rather than drawing you a reassuring empty chart.

You pick what gets fixed first, and you can show your working

Posture turns per-host risk, vulnerability pressure, KEV exposure, MITRE breadth and internet exposure into a remediation order, and the threats page tracks attacker origins, persistence signals, brute force attribution and multi-stage progressions per host across 30 days, so the ranking has reasons behind it. From management you set automated response rules, tune alert noise, choose notification channels, manage ingestion and retention, and fire a manual response when you would rather pull the trigger yourself.

Before you start

You need the agent on the machines you want to see, and a gateway to dispatch the scans from. Everything on this page is read in the console you already run.

In detail

Looking from the outside too, and asking one machine directly

Outside in

What the device looks like from the network

Agents see the device. Scanners see what the device looks like from outside, which is the view an attacker gets, and QS-WAN does both.

The network scanner is dispatched through a gateway and runs on a schedule of one time, daily, weekly or monthly. There are five presets, host discovery at five minutes, a quick exposure scan at ten, a service inventory at ten, a vulnerability audit at fifteen and a custom scan at fifteen, and six timing templates from the slowest and quietest to the fastest and loudest. The web scanner covers your web applications and returns alerts, discovered URLs and the technical detail behind each one.

On demand

Asking one machine one question

The client can share a device inventory: operating system and build, processor, memory and disk, battery, network interfaces and addresses, graphics adapters and displays, installed and running software, theme and locale, and the client version. Sharing is a single toggle, visible in settings, and the console asks for a snapshot when it needs one instead of the endpoint streaming everything, all day, forever.

There is also device intelligence on demand, where an administrator asks a specific device a question through the gateway and waits around 30 seconds. It can come back with location and geocoded address, addresses, host and user names, operating system and architecture, client version, processor, memory and hardware, with application data as a separate request. Read the limits below before you count on it.

Where this earns its place

Four mornings this changes

Monday morning, and you have two hours

Posture gives you the order. You work down the queue instead of down the loudest inbox, and the reasons behind the ranking are on the same screen.

A dashboard has been quiet for a fortnight

You find out whether it is quiet or deaf, because those are different words here. One of them sends you to look at the pipe.

A customer asks how your fleet is configured

Configuration assessment is already scored and tiled. You show the screen instead of starting a fortnight of reconstruction.

Something is being actively exploited in the wild

CVE exposure per package, the signal that it is being exploited, and the list of affected hosts are the same view, so the question and the answer do not live in two tools.

Works better with

What feeds it, and what you do with what it finds

What happens after something is found. Monitoring is the evidence; response is the part that acts on it.

The per-host number that feeds the remediation order, and what actually goes into it.

The fleet side of the same console: which gateway each machine is behind, and whether the path to it is alive at all.

Where the configuration results stop being a screen and start being an answer to a specific framework question.

What this does not do

The limits, because they are what make the rest believable

It is not a security operations centre

Nobody here watches your network. It is a product that puts the evidence in your console, for your people, and the honest version of that sentence has no round-the-clock in it.

Device intelligence on demand is partial today

When a request fails, it does not reliably separate a gateway that is offline from a client that is unreachable, an unsupported path, a timeout, or a person who turned sharing off. You learn that it did not work. You do not yet learn why, and we are not going to dress that up.

A green response is a recorded intention

The database is the authority. Delivery out to gateways and clients is best effort, so a device that is off gets your instruction when it comes back, not before.

It only sees the machines that carry the agent

That is what the scanners are for, and they see the outside rather than the inside. A machine with neither is not in any of the thirteen views, and no screen here pretends otherwise.

Questions people ask

The ones that come up first

What is endpoint monitoring in QS-WAN?

Thirteen linked views of what your devices are doing: alerts, the rules behind them, hosts, logins, compliance checks, MITRE ATT&CK coverage, CVEs, threats, inventory and a posture page that ranks what to fix first. They link into each other rather than sitting in separate tabs.

What is the difference between no data and could not get data?

No data means the host had nothing to report. Could not get data means the pipe is down and you should go and look at the pipe. Most consoles draw both as one empty chart, which is how a dead agent spends three weeks looking like a quiet machine.

Is the posture score a grade?

No, it is an order. It combines per-host risk, vulnerability pressure, KEV exposure, MITRE breadth and internet exposure into a remediation queue, so the output is which machine to open first rather than a letter to interpret.

How is the compliance figure calculated?

Passed divided by passed plus failed, leaving out anything marked not applicable. The tiles show passed, failed, not applicable and hosts with failures, so the number and the things behind it are on the same screen.

Can the person using the laptop see what is collected?

Yes. The device inventory shared by the client is a single toggle, visible in settings, and it covers the operating system and build, processor, memory and disk, network interfaces, installed software and the rest. The console asks for a snapshot when it needs one rather than the endpoint streaming everything all day.

Do you monitor our fleet for us?

No. This is a product, not a managed service. The alerts, the queue and the evidence are yours, in your console, read by your people.

Tell us which machine you would open first, and why.

We open the posture page on a console shaped like yours, turn the signals off one at a time, and see whether the queue agrees with you. It is free, it lasts as long as you want, and there is nothing to sign.

Scroll to Top