1stProtect Endpoint Security Distributed by Cyberdis

Real-time endpoint security enforced inside the operating system — stopping credential theft, ransomware and data exfiltration before data leaves the device.

Cyberdis is a value-added distributor of 1stProtect, selling through channel partners with engineer-led evaluation, deployment and support.

Real-time preventionOS-level enforcementOn-device AI forensicsAir-gap friendly

// What it does

1stProtect in short.

1stProtect is a real-time endpoint security platform that enforces protection inside the operating system itself, stopping credential theft, ransomware and data exfiltration at the moment they happen rather than after an alert. The Silicon Valley company was founded by veterans of CrowdStrike, Symantec and Cisco — CEO Kervin Pillay previously served as Cisco’s CTO of Automation, and CTO Rafel Ivgi built endpoint technology at SentinelOne, CrowdStrike, Symantec and Forcepoint. 1stProtect emerged from stealth with 20 million dollars in funding from Andra Capital and All Blue Capital and launched publicly at the RSAC 2026 conference. Its modular engine line — more than 18 engines including CredentialProtect, RansomProtect and ExfilProtect — pairs OS-level enforcement with an on-device AI investigation engine that performs forensics and automated response locally, without sending sensitive data to the cloud. Cyberdis distributes 1stProtect through channel partners, backing every deal with engineer-led PoCs and deployments.

Traditional endpoint tools detect attacks and respond after the fact, and the window between alert and action is where the damage happens. Because 1stProtect investigates and enforces on the endpoint itself, it also fits organizations with strict data-sovereignty requirements or limited connectivity.

Sources: SecurityWeek — out of stealth with $20M · PR Newswire — launch announcement

// Capabilities

What you get.

  • CredentialProtect

    Blocks credential theft at the operating-system level — tokens, hashes and secrets stay where they belong.

  • RansomProtect

    Recognizes and halts encryption behavior in real time, before file systems are damaged.

  • ExfilProtect

    Stops sensitive data from leaving the endpoint — at the moment of theft, not hours after the alert.

  • On-endpoint AI investigation

    Local forensics, root-cause analysis and automated response on the device itself. Nothing sensitive is sent to external systems.

  • AI data governance

    Detects ungoverned AI applications reading regulated data — ranked in 1stProtect’s own risk model as severely as active malware — plus shadow-AI discovery and sanctioned-AI auditing.

// Threat coverage

How 1stProtect ranks what it stops.

1stProtect scores every threat category it covers by business risk to the customer — not by technical novelty. Five dimensions feed each score: impact, irreversibility, scope, regulatory and reputational exposure, and confidence in malicious intent. The result is a 0-100 ranking across five tiers, from catastrophic to hygiene.

# Threat Engine(s) Tier Score Business risk
1 Destructive wiper WiperProtect 1 · Catastrophic 100 Permanent destruction of data and systems. Total operational halt, no recovery, mass breach disclosure.
2 Mass encryption ransomware RansomProtect 1 · Catastrophic 95 Operations stop, ransom demand, mandatory breach disclosure, heavy recovery cost and contractual fallout.
3 Confirmed bulk data exfiltration DataProtect / RecordProtect 1 · Catastrophic 94 Data confirmed leaving the organization. Irreversible confidentiality loss and GDPR/DPA exposure.
4 Backup / shadow-copy destruction RansomProtect / DataProtect 1 · Catastrophic 93 Backup deletion and bcdedit tampering: the last containable moment before destruction. Almost never benign.
5 Infostealer / credential harvester MalwareProtect / CredentialProtect 1 · Catastrophic 90 Automated harvesting of credentials, secrets and data feeding account takeover and follow-on breach.
6 Credential dumping (LSASS / DPAPI / SAM) CredentialProtect 2 · Severe 88 Keys to the kingdom: enables domain-wide takeover and virtually every downstream attack.
7 Reverse shell / interactive C2 ShellProtect 2 · Severe 87 Hands-on-keyboard attacker control of the host. Escalation and exfiltration imminent.
8 Ungoverned AI reading regulated data DataProtect (AI governance) 2 · Severe 85 Ungoverned AI reading regulated personal data. DPA/GDPR violation; data leaves the control boundary.
9 Known malicious binary running MalwareProtect 2 · Severe 84 Confirmed malicious binary executing. High-confidence active infection on the endpoint.
10 Memory-resident (fileless) implant MalwareProtect / ExecutionProtect 2 · Severe 83 Memory-resident malware evading disk-based detection. Sophisticated active compromise.
11 Security tool tampering / agent kill SelfProtect 2 · Severe 83 Disabling defenses LockBit-style. Near-certain skilled adversary mid-operation; blinds every other control.
12 Browser password / cookie / token theft BrowserProtect 2 · Severe 80 Theft of saved passwords, cookies and session tokens leading to SaaS session hijack and account takeover.
13 Privilege escalation (admin / SYSTEM) ExecutionProtect 3 · Significant 78 Gaining admin/SYSTEM unlocks credential theft, persistence and lateral movement.
14 Covert screen recording RecordProtect / ScreenProtect 3 · Significant 77 Covert screen recording of sensitive data; forensic watermark enables source attribution.
15 Lateral movement IDProtect / AppProtect-OSA 3 · Significant 74 Spread to additional hosts expands the blast radius toward domain-wide compromise.
16 Event log clearing / forging EventProtect 3 · Significant 72 Clearing or forging logs destroys forensic evidence and signals deliberate cover-up of an active incident.
17 Unsanctioned remote control (RMM / VNC) AppProtect-OSA 3 · Significant 71 Unsanctioned remote-access tooling: a top ransomware-affiliate access vector and insider-misuse channel.
18 Covert microphone capture AudioProtect / RecordProtect 3 · Significant 70 Covert capture of meetings, calls and secrets. Confidentiality loss of spoken information.
19 Regulated data uploaded to external AI DataProtect 3 · Significant 70 Confidential or regulated data submitted to an external LLM. Data leaves control; regulatory and IP loss.
20 Illegitimate runas / impersonation IDProtect 3 · Significant 68 Illegitimate identity switching. Privilege misuse, evasion and insider risk.
21 Camera photographing the screen LensGuard 3 · Significant 66 A camera or phone photographing the screen. Physical exfiltration; real-time blackout mitigates.
22 Rogue account creation IDProtect 3 · Significant 65 Creation of a rogue admin or user account establishes a persistent backdoor.
23 Living-off-the-land (LOLBin abuse) ExecutionProtect 3 · Significant 64 Abuse of legitimate tools (PowerShell, WMIC, certutil). Evasive execution that is harder to attribute.
24 Persistence (autoruns / services / tasks) AppProtect-OSA / DataProtect 3 · Significant 62 Persistence mechanisms ensure the attacker regains access after reboot or cleanup.
25 Unsanctioned AI application DataProtect 4 · Moderate 58 Shadow AI in use: a governance gap with potential data leakage and compliance drift.
26 Bulk copy to removable media DeviceProtect 4 · Moderate 56 Bulk copy to removable media. Classic insider exfiltration, single-endpoint scope.
27 Stored network credential access CredentialProtect 4 · Moderate 54 Access to stored network credentials enables network pivot and eavesdropping.
28 Mailbox / contact harvesting Email-identity collector 4 · Moderate 54 Harvesting mailbox and contacts seeds phishing/BEC campaigns and exposes PII.
29 Sensitive data handled against policy DataProtect 4 · Moderate 51 Sensitive data handled against policy. Potential leak and compliance issue.
30 System / account enumeration DataProtect / IDProtect 4 · Moderate 43 Early kill-chain reconnaissance; potential not yet realized, some benign overlap.
31 Sanctioned AI touching personal data DataProtect (AI governance) 4 · Moderate 40 Monitored, governed AI access to personal data. Low active risk, retained for audit and oversight.
32 Unapproved / changed app vs baseline AppProtect-OSA 5 · Hygiene 34 Application drift against the hash baseline. Supply-chain and configuration risk, mostly potential.
33 Non-policy device connected DeviceProtect 5 · Hygiene 32 A non-policy device connected. Potential vector, no active harm on its own.
34 Known-vulnerable software present OSVProtect 5 · Hygiene 30 Known-vulnerable package present. Latent exposure that requires exploitation to matter.
35 Policy-blocked browsing Web / URL policy 5 · Hygiene 15 Acceptable-use hygiene with minimal standalone business risk.
36 Informational device-policy event DeviceProtect 5 · Hygiene 12 Informational device-policy event. Near-zero standalone risk.

Note the four AI-governance categories: 1stProtect ranks ungoverned AI reading regulated data (85) as severely as active malware — coverage most endpoint products do not have.

Source: 1stProtect risk model, published with vendor approval. Scores shown are the vendor’s published scores.

// Why through Cyberdis

The vendor is theirs. The deployment is ours.

  1. 01

    PoCs that stage real attacks

    We run credential-theft, ransomware and exfiltration scenarios in the customer environment and let the buyer watch them fail. Prevention is easy to claim on a slide and hard to fake in a live test.

  2. 02

    Policy tuned to your fleet

    OS-level enforcement is only as good as its policy. Cyberdis engineers tune it to the environment, run the rollout and hand over a documented, working deployment.

  3. 03

    A prevention story resellers can sell

    Demo scripts, training and positioning against detect-and-respond incumbents, so commercial teams can carry the real-time prevention argument without an SE on staff.

// FAQ

Frequently asked questions about 1stProtect

What is 1stProtect?

1stProtect is a real-time endpoint security platform from a Silicon Valley company founded by CrowdStrike, Symantec and Cisco veterans. It enforces security policy inside the operating system, stopping credential theft, ransomware and data exfiltration as they happen.

How is 1stProtect different from EDR tools?

EDR detects and responds after suspicious activity is observed. 1stProtect enforces prevention at the OS level in real time and investigates on the device itself — the attack is stopped during execution, not reconstructed after the data is gone.

Does 1stProtect require cloud connectivity?

No. Its AI investigation engine runs on the endpoint, performing forensics, root-cause analysis and automated response locally — a fit for air-gapped, sovereignty-constrained or low-connectivity environments.

What threats does 1stProtect cover?

1stProtect publishes a 36-category threat matrix ranked by business risk: destructive wipers and ransomware at the top (scores 95-100), through credential dumping, fileless implants and browser token theft, down to hygiene events like vulnerable software. Coverage spans 18+ engines, including AI data governance and physical capture detection (camera and microphone).

Who distributes 1stProtect?

Cyberdis is a value-added distributor of 1stProtect, providing channel partners with engineer-led proofs of concept, deployment, enablement and post-sale support.

Weighing approaches? Read: Real-time endpoint prevention vs EDR: stop the attack, or investigate it?

New to the category? Start with: What is data exfiltration?How does endpoint security work in air-gapped environments?What is endpoint security?What is EDR (endpoint detection and response)?What is credential dumping?

// See it running

See 1stProtect on your own terms.

A demo tailored to your environment, or a full proof of concept — run by a Cyberdis engineer.

End customer rather than reseller? Ask anyway: we bring the right partner into the deal and stay on it as the engineering team.