Fenrir SOCFenrir MDRGARM · gratisFenrir WP BridgeFenrir WP Central How it works Pricing Compliance Blog
ENDPOINT · MICROSOFT DEFENDER · 24/7
Fenrir MDR

Managed detection & response. The AI never sleeps.

Fenrir MDR covers Windows, Linux and macOS clients. The AI detects, classifies and neutralises threats with graduated autonomy, 24/7 — isolating the endpoint in under a minute. You supervise the high-impact actions, or we stand alongside you.

Fenrir MDR · endpoint console RANSOMWARE CONTAINED
notebook-mktg-04
hidden PowerShell · Defender disabled
ISOLATED
srv-prod-01
SOC sensors · no anomaly
OK
mac-design-02
processes and network monitored
OK
<60s
containment
97%
AI confidence
0
files encrypted
01 · Coverage

One console. Three surfaces. No blind spot.

Fenrir MDR sees your devices’ endpoints, Microsoft Defender signals and the servers covered by the SOC — and correlates them into a single incident queue.

Endpoints
Windows, macOS and Linux. The Fenrir agent monitors processes, network connections, filesystem changes and anomalous behaviour on every device.
Microsoft Defender / M365Coming soon
Defender for Endpoint signals and M365 alerts flow into the console. One incident queue, one coordinated response.
Servers
The Linux and macOS servers covered by Fenrir SOC sensors appear in the same console. Endpoints and infrastructure, correlated at once.
02 · A real scenario

An attack at 2 a.m. on the endpoint.

No human analyst awake — only Fenrir MDR. Watch what happens in the seconds after the infection.

Ransomware on endpoint · at 2 a.m. CRITICAL · 97%
02:14
Suspicious execution on a laptop

An unknown executable launches hidden PowerShell and tries to disable Defender. Confidence 97%.

02:14
Lateral movement detected

RDP connections to other hosts on the LAN. The AI classifies: ransomware, pre-encryption phase.

02:14
AI: endpoint isolation

Device isolated from the network (reversible action). Process terminated and quarantined.

02:15
Alert on Telegram + email

Incident summary, malware hash, host isolated. Approval requested for the reimage.

08:30
MSP approves the reimage

Incident contained. Zero files encrypted. Evidence pack generated for the NIS2/GDPR notification.

Ransomware contained in < 60 seconds. Zero files encrypted. Without MDR: average damage €75,000 for an SMB.
03 · AI vs human supervision

The AI never tires. The human decides where it counts.

Fenrir MDR doesn’t promise an always-on human team. It promises something different: an AI that works 24/7, backed by human supervision on high-impact actions.

AI · 24/7, autonomously
What the AI does
  • Behavioural detection on endpoints and M365
  • Automatic triage and severity classification
  • Endpoint isolation (reversible action)
  • Process blocking / file quarantine
  • Immediate alert on Telegram & email
  • Evidence pack for NIS2/GDPR compliance
MSP / P3 · supervision
What the human supervises
  • Approval of high-impact actions (reimage, reset)
  • Handling of complex incidents and forensics
  • Bespoke proactive threat hunting
  • Escalation to an external MSSP if needed
  • Periodic review of playbooks and AI thresholds
04 · Graduated autonomy

It acts on its own only when it’s sure.

Above 90% confidence it isolates or blocks on its own; between 60% and 90% it asks for confirmation; below, it logs. The action always remains reversible.

> 90%

Automatic

Immediate block. Action executed and notified.

brute-force, known scanners
60–89%

Approval

Alert on Telegram, confirm with a tap.

suspect IPs, new patterns
< 60%

Log only

Recorded in the digest. No action.

low-level anomalies
05 · Pricing

A simple price, per user.

No surprises, no tiers to decipher. Detection, autonomous response, alerts and evidence pack: all included.

Most chosen
Fenrir MDR
€12
/user · month · up to 3 devices
All inclusive: 24/7 detection, autonomous response, alerts, NIS2/GDPR evidence pack. Data in Italy.
  • Behavioural detection 24/7
  • Autonomous low-risk response
  • Microsoft Defender integration
  • Telegram + email alerts
  • NIS2 / GDPR / ISO 27001 evidence pack
  • Data in Italy
06 · The family

Endpoints, servers, WordPress. One single SOC.

MDR covers the devices; the server line and the WordPress line live in the same console and the same AI.

The AI doesn’t sleep. You do.

Request an MDR demo: in half an hour you see the scenario of an attack contained in under a minute.

Install GARM · free