← All services
Core · Included

Security Automation & Containment

Reduce Mean-Time-To-Contain (MTTC) from hours to ~800 milliseconds — with human SOC approval on every action.

What this service offers

This Core service runs active-response playbooks to isolate hosts (ISOLATE_HOST), stop malicious processes, and block known-bad hashes — so attacks do not wait on a ticket queue.

AI accelerates correlation; human SOC engineers validate every containment action before it runs.

  • Host network isolation using OS-native controls (ISOLATE_HOST)
  • Remote process termination by process identity
  • Malicious hash blocking across connected endpoints
  • Verification that containment actions completed
  • Target path: reduce MTTC from hours to ~800 milliseconds under approved playbooks

Limitations (honest scope)

Clear boundaries help you buy the right module — not oversell.

  • Requires healthy endpoint connectivity and correct entitlements for targeted assets.
  • Isolation can disrupt business applications on that host — change control still matters.
  • Not a substitute for backup, patching, or network segmentation strategy.
  • Some actions need SOC/customer approval depending on policy — not blind auto-fire everywhere.

Who should go for it

  • Every Kevantic customer — this is Core and included in the base plan.
  • Customers worried about ransomware lateral movement.
  • Teams that need faster containment than manual SSH/RDP firefighting.

Usually not the best fit if…

  • Environments that forbid any remote containment actions by policy.
  • Assets that cannot run or receive endpoint response agents.