ThreatBook OneSEC
Endpoint detection and response — behaviour-based detection tied to the same intelligence as the rest of the stack
What happened on the host, in order
A single suspicious process alert is rarely the full story. Understanding an incident requires knowing the full sequence: what ran beforehand, what processes it spawned, and what traffic left the machine. Providing that context is the purpose of behavioural endpoint detection.
Behaviour-based detection
Detection keys on what a process does, so novel and fileless techniques are still visible.
Attack-chain reconstruction
Related process activity is assembled into a sequence rather than a list of disconnected alerts.
Response on the host
Contain an affected endpoint and act on the finding without walking to the desk.
Threat hunting
Query endpoint telemetry to test a hypothesis instead of waiting for an alert.
Shared intelligence
The same intelligence drives verdicts here, in TDP and in OneDNS — one view, three vantage points.
Estate visibility
An inventory of what is installed and running, which is half of most compliance questions.
From endpoint signal to contained host
Three ways to get it running
Endpoint agent
Deployed to servers and workstations for behavioural detection and response.
- Behavioural detection
- Host response actions
- Estate inventory
With network detection
Pair endpoint evidence with TDP so an intrusion is visible from both sides.
- Endpoint + network
- Correlated incidents
- Shared intelligence
Managed service
If you have no 24/7 SOC, ThreatBook offers managed detection and response.
- Vendor-run monitoring
- Analyst escalation
- Pricing on request
APAC offices & coverage
Same-jurisdiction threat-intel for ASEAN and East Asian compliance frameworks.
Common questions
Is OneSEC the same as OneEDR?
OneSEC is ThreatBook's endpoint security platform and OneEDR is its detection-and-response capability within that platform; the vendor's domestic material uses both names. If you are comparing quotes, confirm which modules a given proposal includes.
How is this different from antivirus?
Signature-based antivirus just asks if a file is on a blocklist. EDR records what actually happens on the host, which lets you reconstruct an attack, hunt for activity that no signature would catch, and take response actions beyond just quarantining a file.
Does it replace TDP?
No, they see different things. An endpoint agent cannot run on a printer or an appliance, and can be disabled by an attacker with sufficient privilege; network detection covers those gaps. Most mature deployments run both against one intelligence source.
Which platforms does the agent support?
ThreatBook publishes support for mainstream server and workstation operating systems, and its domestic products also cover Chinese platforms and CPU architectures that Western vendors often do not. Confirm your exact estate with us before committing; that specific coverage is a key differentiator if you run those platforms.
Does RECATOOLS get paid to list OneSEC / OneEDR?
We earn no per-click fee for this listing and our editorial coverage is independent. For full disclosure: RECASYS is an authorised reseller of ThreatBook products under SAIBERGARD Pte. Ltd., ThreatBook's authorised distributor, so it earns revenue if you buy a commercial licence through us — the same relationship disclosed on our other ThreatBook listings.
Need pricing, a demo, or the full brochure?
Tell us about your environment and our team will get back to you with ThreatBook licensing, a guided demo, or the product brochure — usually within one business day.
Handled by RECASYS, an authorised reseller of ThreatBook products under SAIBERGARD Pte. Ltd., ThreatBook's authorised distributor for the region. Enquiries are copied to their sales desk. No obligation — your details are used only to answer you.
Interested in OneSEC?
We can scope an endpoint rollout and arrange a demo.
See OneSECExplore related tools & intelligence
Hand-picked RECATOOLS pages relevant to endpoint detection and response.
Related News
You may be interested in these recent stories from our newsroom.
-
Five APAC Markets, Five AI Rulebooks — but They Agree on the One That Matters
Korea has a comprehensive AI law; Australia decided against one. On text and data mining, three of the five markets have quietly converged.
-
Thirty Minnesota Water Utilities Were Hit in One Weekend. The Flaw at the Centre Is Five Years Old and Has No Patch
A coordinated attack reached operational technology at more than 30 municipal water systems. One plant went offline for two hours, and staff...
-
Three Singapore-Based Operators Moved Into South Korea's Data-Centre Market in Two Weeks
STT GDC opened its first South Korea data centre this month, days after Keppel and Digital Edge each moved on Greater Seoul. Singapore-based...