Xcitium
Xcitium runs code it does not recognise inside a container, so an unknown file cannot damage the machine while the verdict is still being formed.
The alternative
CrowdStrike Falcon, SentinelOne and Microsoft Defender for Endpoint. All three decide whether a file is malicious and act on the decision.
At a glance
- Platform
- Xcitium Enterprise Platform
- Core technology
- ZeroDwell Containment
- Packages
- Essential EDR, Pro EDR, Enterprise EDR with EXDR
- Managed service
- Managed detection and response, managed threat hunting, guided security operations
- Free edition
- OpenEDR
- Regions
- Platform instances in the United States and the European Union
- Test results
- MRG Effitas, AVLAB, AV-TEST
- Tenancy
- Multi-tenant, with a service provider programme
Detection has to decide whether a file is malicious before it runs. Containment does not need an answer that early.
Every endpoint product faces the same moment. An executable nobody has seen before is about to run, and the product has to act on incomplete information. Detection guesses, and a guess that is wrong in one direction lets ransomware through while a guess that is wrong in the other direction stops a legitimate tool and generates a support ticket. Blocking everything unknown is the textbook answer and no organisation runs it, because the business stops. Xcitium removes the need to decide at that moment. The unknown file runs inside a container with no route to the disk, the registry or the data, so it can behave exactly as it intends and change nothing. The verdict arrives afterwards. The user is not prompted and does not notice.
The second difference is about who operates it, and it decides which deals a partner can bid on. Endpoint security is bought with monitoring attached, and a tender that asks for twenty four hour coverage eliminates any partner without a staffed operations centre. Xcitium sells the monitoring as well as the platform, through managed detection and response, managed threat hunting and a guided operations centre. A partner in this region can answer that requirement without building the team first, and can grow into running it later.
The third difference is what a buyer can check before signing anything. This category is bought on independent test results, and Xcitium publishes certifications from MRG Effitas, AVLAB and AV-TEST. There is also a free and open edition, OpenEDR, which means endpoint visibility can be put into a customer's estate before a purchase order exists. Two of the products in this portfolio can be evaluated at no cost, and both of them are the ones a partner opens a conversation with.
How it works
- An agent is deployed to workstations and servers
- Known good code runs, known bad code is blocked
- Anything unrecognised runs inside a container with no access to the system
- Behaviour inside the container is recorded and sent for a verdict
- Detection and response records process, file and network activity for investigation
- Device control, host firewall and exploit prevention run in the same agent
Who it is for
- Organisations whose main exposure is ransomware arriving through a user
- Estates where an unknown executable runs every week and nobody can review each one
- Buyers who require twenty four hour monitoring and do not have a security team
- Partners who want to sell endpoint security without staffing an operations centre first
What we can point to
- A free and open edition anyone can deploy before buying
Where it sits
Endpoint security. DefensX secures the browser, where most work now happens. Xcitium secures the operating system underneath it. They cover two different unmanaged surfaces on the same machine, and a partner can sell both into one account. CyberCyte, in exposure and vulnerability, is the product that tells you whether an endpoint agent is actually running on every machine.
