THE FALYS PLATFORM
FALYS transforms raw filesystem changes into meaningful security insights through lightweight endpoint agents, centralized analysis, and explainable detection.
WHAT IS FALYS
FALYS continuously monitors designated directories across Windows and Linux endpoints, captures file activity, attributes changes where possible, and evaluates every event through a multi-stage detection engine.
SYSTEM ARCHITECTURE
Lightweight agents monitor filesystem activity, collect hashes, permissions, and user attribution data before securely forwarding events.
Events are transferred through authenticated connections using HTTPS and individually assigned agent identities.
The FALYS server receives events, processes detection logic, stores history, and powers the monitoring dashboard.
DATA FLOW
DETECTION ENGINE
SECURITY DESIGN
Every deployed agent receives its own unique authentication key, allowing individual management and revocation.
HTTPS communication with certificate pinning protects agent-to-server communication.
Each detection includes classification, confidence information and reasoning behind the score.
Read the technical documentation and system guide.
View Resources