Agentless Datacenter Detection & Response

Detection and response for the layer your EDR can't reach.

Hypervisors, control planes and management interfaces run the most valuable machines you own, and endpoint tooling cannot see any of them. TensorOne watches that layer: behavioral detections mapped to MITRE ATT&CK, multi-stage correlation that reconstructs a kill chain instead of alerting on each step in isolation, and response playbooks for what it finds.

The detections are engineered by former NSA operators, and the platform was designed from the ground up by one of them.

Nothing is installed on your hosts to do it, and it funds itself: the same edge filter that feeds the detections drops up to 99% of your datacenter log volume before your SIEM bills for it. Guaranteed 50% or you don't pay.

FORMER NSA ENGINEERED
Detections written by operators who spent their careers on the offensive side
NOTHING ON YOUR HOSTS
One collector VM. No agents, no VIBs, no kernel modules, no reboots
UP TO 99% FILTERED
Datacenter log noise dropped before your SIEM can bill you for it
The blind spot

The most valuable machines in your datacenter are the ones nothing is watching.

A hypervisor can snapshot, clone, or wipe every workload you run — yet no endpoint sensor can live on it. That's true on every platform: VMware (Broadcom), Proxmox, Nutanix, OpenShift, KVM, or your cloud.

And organizations don't migrate off one platform onto another. They run several at once, for years. Each has its own control plane, its own logging format, and its own security model. EDR covers none of them, and a single-platform tool covers a fraction of the estate.

You're not running one hypervisor. You're running three. What's watching all of them?

In public federal contract records for FY2025–26, 33 of 62 agencies with a measurable virtualization estate bought two or more virtualization platforms in the same two-year window. Twelve bought three. One bought four.

The industry’s answer is to spend more every year. It isn’t working.

What we spend on EDR↑ 99% in two years
$2.87B
2022
$3.55B
2023
$5.7B
2024

On pace for $16.89B by 2030.

What cybercrime costs↑ 50% in three years
$7T
2022
$8T
2023
$9.5T
2024
$10.5T
2025

Headed for $15.6T by 2029 — and still climbing.

3RD
If cybercrime were a country, its $10.5 trillion economy would rank the third-largest on Earth — behind only the U.S. and China, and more profitable than the entire global trade in illegal drugs combined.
Break the cycle. TensorOne cuts your datacenter log bill and detects what EDR can’t reach — so the coverage you are missing is funded by the spend you are already making.
The Solution

Coverage where it's dark. Detection where it counts.

Detections written from the offensive side

Behavioral detections for the hypervisor control layer, each mapped to its MITRE ATT&CK technique and carrying a severity that states the expected response window. Written by former NSA operators who spent their careers learning how intruders stay invisible at this layer, and revised as tradecraft shifts.

Kill chains, assembled

Multi-stage correlation links a brute force, a successful login from the same user and address, and the high-risk command that follows into one incident — with the time delta between each stage and the evidence attached to every node.

Authentication analysis that knows your clock

Off-hours logic runs in your own timezone, handles night shifts that wrap past midnight, exempts the service accounts that are supposed to run at 3 a.m., and declines to judge at all when the source clock has drifted more than two hours from ours.

Response playbooks for what it finds

Every detection ships with the response playbook for the technique it catches: what to contain, what to preserve, and what to verify before you call it closed. Written by the operators who wrote the detection.

Six source types, one console

Collects from VMware (Broadcom) vSphere and vCenter, Proxmox VE, Nutanix AHV, Red Hat OpenShift, KVM/libvirt and AWS CloudTrail at the same time, with live inventory and exposure matching across all of them. Behavioral detection content is deepest on vSphere and ESXi.

The edge filter that pays for itself

Up to 99% of datacenter log volume dropped before egress — a live meter shows, to the dollar, what that removes from your SIEM bill. Usually enough to fund the detections outright.

Who we are

The people who wrote the playbook you're defending against.

To catch an adversary who knows how to evade detection, you need the people who spent their careers doing it. Here's exactly who that is.

Founder headshot
James Ball
Chief Executive Officer

Eight years at the National Security Agency in Computer Network Operations (CNO), working on Exploitation Analysis. Founder of TensorOne; owns detection engineering and security operations.

Founder headshot
Sean Byrd
Director of Strategic Engagement

Nearly two decades of experience designing security protocols for U.S government agencies at home and abroad. At TensorOne, owns growth and engagement strategy .

Isolation & trust

Your telemetry never shares a table with anyone else's.

Isolation isn't a setting we bolt on — it's the architecture. Every organizational context is scoped, access is bound to identity, and your data stays yours.

01

Per-context database isolation

Each organizational context — a subsidiary, a datacenter, a business unit — gets its own dedicated database. No shared tables, no row-level co-mingling.

02

Identity-bound access

Tenant scope is cryptographically bound to the authenticated session. It can't be reassigned by a client, so a user only ever sees the contexts they're granted.

03

Dedicated infrastructure

Regulated workloads run on infrastructure dedicated to your organization, with data residency to match your obligations — not a shared pool.

04

Filter on-prem, by design

Raw telemetry is filtered inside your network. Only the signal you approve ever leaves the building — the rest never crosses the boundary.

05

Silence is a detection

The obvious move against a passive collector is to stop feeding it. We track expected volume and heartbeat per host, so a source that goes quiet raises an alert instead of leaving a gap — including when someone turns syslog off.

06

Read-only, and we'll prove it

Inventory and configuration state come from read-only service accounts. The complete permission list is a one-page document we send before you grant anything — your security team reviews it first, not after.

The savings, up front

Put your own numbers in.

Most of what your hypervisors and control planes emit is noise your SIEM still bills you to store. Enter your ingest and rate to see the annual cost our edge filter takes off the table — then get the seven-day assessment to replace this estimate with a figure measured on your own telemetry.

Filtered before egress 85% 50% — the floor we guaranteeup to 99%
SIEM cost removed per year
$155,125
$12,927 / month · at 85% filtered
Measure your real number →

An estimate from the numbers you entered. The seven-day assessment reports the reduction actually measured on your telemetry — never an average from our lab. Filtering alone is our entry tier, Delta — $100 per host per year; what it saves is how most customers fund the full detection platform.

How you start

Seven days of your logs. No purchase order.

Before anyone talks about contracts, we measure what your datacenter layer is actually costing you and what is already hiding in it. Nothing gets installed on a hypervisor to do this.

You

Point syslog at one VM

A single configuration line on your hosts, reversible in seconds. No agents, no VIBs, no kernel modules, no change window, nothing installed on the hypervisors themselves.

Us

Seven days, then a written report

Your real ingest volume and what it costs at your SIEM's rate, the share we would filter out, and anything already anomalous sitting in that telemetry.

Then

You decide with your own numbers

If the report is not compelling, we part ways and you keep it. If it is, we scope a deployment against figures from your estate instead of averages from ours.

No cost, no procurement, no commitment — the assessment is a measurement, not a trial. Book the scoping call →
Pricing

Detection first. The filter pays for it.

And if we don't cut your hypervisor ingest by 50%, you don't pay.

Start with the 7-day assessment — or take a 14-day free trial of Eagle, full detections, no credit card. Start free trial →
Start here
Delta
Filter & Forward
$100 / host · yr

Cut your SIEM bill today.
Expert-crafted filtering keeps only the telemetry worth paying for and stops the bleeding on ingest costs — for less than the noise from a single host costs you now.

Eagle processes only what Delta forwards, so upgrading isn't a second deployment or a new change window — it's rewriting the destination on telemetry already flowing.

Start with filtering. Turn on detection whenever you're ready.

  • Collector + edge filter logic
  • Forward to your SIEM / syslog
  • Asset inventory & ROI metering
  • No storage or detections
  • One collector per license
Start with Delta →
Where Delta customers end up
Eagle
Full Detection & Response
Free Quote

The full platform — MITRE-mapped detections, kill-chain correlation, response playbooks and the event explorer across every host you run.

This is what the NSA experience buys you. And the savings Delta frees up are how most customers pay for it.

  • Everything in Delta
  • Cloud storage & event explorer
  • Proprietary detections, updated daily against new threat signatures
  • Response playbooks + AI that explains an alert's evidence
  • One collector per license
  • Quoted against your measured environment after the free seven-day assessment.
Start free trial
Patriot
Enterprise & Regulated
Let's talk

Everything in Eagle, on infrastructure dedicated to your organization — built for regulated estates that answer to auditors.

  • Everything in Eagle
  • Dedicated infrastructure per account
  • CMMC 2.0 · HIPAA · GLBA aligned controls
  • Data residency & multiple collectors
  • Full on-prem deployment
  • Named support & onboarding
Contact sales

Billed per active host · annual or monthly · design partner pricing available

Hunt the dark layer

Catch what your EDR can't see.

Start with seven days of your own telemetry. Stand up one collector, watch the noise — and the bill — fall away, and see what has been running underneath your EDR the whole time.