Features
Privacy-first EDR with a focused device management console and endpoint detection powered by Rustinel.
Privacy and end-to-end encryption
Radegast is designed to reveal as little sensitive information to the hosted service as possible. End-to-end encrypted, including alert details and detection exclusions. Alert content is encrypted on the endpoint and decrypted in your browser.
Transparent by default
Radegast is open source and Apache 2.0 licensed, so you can inspect how data is collected, encrypted, stored, and displayed.
European operation
Built and hosted in the European Union
Device management console
The hosted console keeps administration approachable for small teams and home labs. It guides enrollment and gives you one place to manage the parts of your EDR setup you use most often.
Devices and groups
Enroll Windows, Linux or mac devices, organize them into groups, and see device status from a central dashboard.
Detection packs
Choose prepared detection packs and assign them by group, so each device receives the detections appropriate for its environment.
Alert review
Review decrypted details in the browser, track context, and create exclusions when a detection is a false positive.
Guided installation
After you add a device, the console provides installation instructions for its operating system and confirms when enrollment succeeds.
Detection powered by Rustinel
Rustinel is the independent open-source endpoint detection engine used by Radegast.
Native telemetry
Rustinel uses ETW on Windows and eBPF on Linux for process, network, file, registry, and DNS activity supported by each platform.
Sigma detections
Evaluate community Sigma rules against normalized events to identify suspicious behavior such as PowerShell abuse, WMI execution, and unusual process chains.
YARA scanning
Inspect executables at process creation and scan private executable memory regions for packed, obfuscated, or runtime-unpacked malware.
IOC matching
Match file hashes, IP addresses, domains, and path patterns for threat hunting and incident response.
Protect your endpoints without surrendering your data.
Start with the hosted console, or inspect the engine and platform source code first.