Intrusion Detection Service
SOCVault agents scan the monitored systems for malware, rootkits, and suspicious anomalies. They can detect hidden files, cloaked processes, unregistered network listeners, and inconsistencies in system call responses. In addition to agent capabilities, the server component uses a signature-based approach to network intrusion detection (ids), using its regular expression engine to analyze collected log data and look for indicators of compromise.