Click up chevron icon

Raising the bar for virtualised environments security

Ryzome is built for stealth, precision, and deep observability to enhance security in virtualised environments. We instrument the hypervisor and leverage its introspection capabilities to monitor guest activity in real-time and in great detail, without any agent or footprint inside your virtual machines.
Why a new approach is needed

Traditional monitoring approaches can't deliver stealth, depth, and real-time visibility all at once

Robust security in virtualised environments is critical. When virtual machines run workloads essential to your business operations, you can’t afford to compromise on their security. Yet, current models all force security tradeoffs.
Agent-based
While security agents offer deep and real-time insights into virtual machines activity, they can be detected, disabled, and compromised by sophisticated and nation-state threat actors.
Agentless
Traditional agentless models often rely on periodic snapshots, which miss real-time behaviours, and network traffic and API calls, which can be intercepted or altered by malicious actors.
Network-based
Network-based security does not capture granular activity into individual virtual machines, and does not have visibility into encrypted communications, used by adversaries for evasion.

Virtualisation technology offers the ability to rethink existing models to enhance security.

How Ryzome Exovision™ Technology Works

Security engineered for virtualised environments: offering stealth, depth, and real-time visibility

Ryzome Exovision™ is based on a radical new approach to virtualised environments security, going beyond existing models.
Our technology uses hypervisor instrumentation to provide the granularity and real-time capabilities you would expect from agent-based security, while being agentless.
Architectural DESIGN

Outside the virtual machine, within the hypervisor

Our technology lives at the hypervisor layer, giving us an isolated vantage point and privileged visibility into virtual machine activity – without being inside the VM.
In-guest threats can't detect or interfere with our monitoring. Even if a virtual machine is fully compromised, we remain invisible and operational, and your visibility remains intact.
Monitoring Technology

Inside the action,
via introspection

Using advanced Virtual Machine Introspection (VMI) built for production environments, we capture what’s happening inside your virtual machines as it happens.
We observe and analyse system calls, process execution, memory access, and more, to provide you, in real-time, granular and high-fidelity telemetry essential to your security operations.

Security benefits

Evasion- and tamper-resistant by design
Invisible to and isolated from threats
Full visibility and in-depth monitoring in real-time
High-fidelity observation and data

Operational benefits

No agents to deploy and update
Reduced management complexity
Complete VMs coverage and high scalability
Direct and non-intrusive
SETTING A NEW STANDARD

Recommended by NIST,
implemented by Ryzome

“Security Recommendation HY-SR-15: Solutions for Security Monitoring and security policy enforcement of VMs should be based outside of VMs and leverage the virtual machine introspection capabilities of the hypervisor.”

COMPARISON

Hypervisor-based threat detection
vs traditional approaches

Agent-based
Agentless
Ryzome Exovision™
Requires agents?
Yes
No
No
Can be detected?
Yes
Possible
No
Can be bypassed?
Yes
Possible
No
Can be tampered?
Yes
No
No
Provides real-time, continuous threat visibility?
Yes
No
Yes
Gets deep visibility inside the virtual machine?
Yes
No
Yes
Leads to operational overheads?
High
Low
Low
Real-time visibility at runtime. Stealth monitoring. Zero agents.

See Ryzome Security Monitor in Action

Detect and analyse the most evasive and sophisticated threats in your virtualised environments
Get a Demo