IT / infra
Windows shops with exposed services
RDP and management ports on the internet, limited SOC bandwidth, need early warning that isn’t “another log silo.”
Product
One Windows agent. Decoy services on the host. A live cloud panel to block and respond — without turning your stack into a SIEM project.
Local agent runs on the Windows server you authorize. It opens decoy listeners (RDP, SSH, SQL, FTP, …), watches canary/ransomware signals, and can apply firewall rules you request.
Asteria cloud receives heartbeats and attack events, powers the multi-server dashboard, and delivers remote commands (Premium) over authenticated channels.
Your real production services stay yours. Asteria’s job is to make the wrong door loud — then let you shut the attacker out.
Not a replacement for EDR or perimeter firewall. Asteria is a deception + response layer that shortens time-to-detect and time-to-block on exposed Windows hosts.
Download the Windows installer from asteria.run, run it on the host, and let it register with the cloud. You get a private dashboard path and can link the server to your membership account.
Enable the bait services you want. Probes, credential stuffing attempts, and ransomware staging signals land in your threat timeline — without opening real databases or domain controllers to the bait ports.
From any browser: review the timeline, auto-block or manually block IPs (AR-BLOCK / AR-INTEL), open remote desktop, kill processes, log off sessions, run Windows Tools & Repair, and clear rules when the investigation is done. Email alerts hit your notify mailbox on high severity (Premium).
IT / infra
RDP and management ports on the internet, limited SOC bandwidth, need early warning that isn’t “another log silo.”
MSP
Link agents under one account. Standard for visibility; Premium seats where traps and remote response matter.
Security buyer
Read Security & architecture, Privacy, and Threat scenarios before rollout.
Map your risks on Threats, then see every capability on Features — or install the agent now.