Privacy and end-to-end encryption

Radegast is designed to reveal as little sensitive information to the hosted service as possible. End-to-end encrypted, including alert details and detection exclusions. Alert content is encrypted on the endpoint and decrypted in your browser.

Transparent by default

Radegast is open source and Apache 2.0 licensed, so you can inspect how data is collected, encrypted, stored, and displayed.

European operation

Built and hosted in the European Union

Device management console

The hosted console keeps administration approachable for small teams and home labs. It guides enrollment and gives you one place to manage the parts of your EDR setup you use most often.

Devices and groups

Enroll Windows, Linux or mac devices, organize them into groups, and see device status from a central dashboard.

Detection packs

Choose prepared detection packs and assign them by group, so each device receives the detections appropriate for its environment.

Alert review

Review decrypted details in the browser, track context, and create exclusions when a detection is a false positive.

Guided installation

After you add a device, the console provides installation instructions for its operating system and confirms when enrollment succeeds.

Detection powered by Rustinel

Rustinel is the independent open-source endpoint detection engine used by Radegast.

Native telemetry

Rustinel uses ETW on Windows and eBPF on Linux for process, network, file, registry, and DNS activity supported by each platform.

Sigma detections

Evaluate community Sigma rules against normalized events to identify suspicious behavior such as PowerShell abuse, WMI execution, and unusual process chains.

YARA scanning

Inspect executables at process creation and scan private executable memory regions for packed, obfuscated, or runtime-unpacked malware.

IOC matching

Match file hashes, IP addresses, domains, and path patterns for threat hunting and incident response.

Protect your endpoints without surrendering your data.

Start with the hosted console, or inspect the engine and platform source code first.