sensorzero
Sign in Start free
Collection

Every log source, collected three ways.

SensorZero collects from your hosts with a lightweight agent, from your cloud environments over their APIs, and from your network with a passive sensor. All three feed the same normalised schema, so a detection can span an endpoint, a mailbox and a packet in one query.

01 — AGENT COLLECTION

One agent per host, on every platform you run.

A single lightweight agent runs on Windows, Linux and macOS. By default it collects Windows Sysmon, EVTX event logs and host configuration details — the telemetry that shows both how a host is misconfigured and how an attacker is behaving on it.

sensorzero

Windows agent

Sysmon process, network, file and registry telemetry alongside EVTX event logs — the primary source behind most detections.

sensorzero

Linux agent

Process execution, authentication and system logs from servers and workloads, with the same schema as every other source.

sensorzero

macOS agent

Endpoint telemetry from Mac laptops and desktops, so a mixed fleet doesn't leave a blind spot in your coverage.

Windows Sysmon
EVTX event logs
Host configuration
02 — CLOUD COLLECTION

Direct cloud integration.

An easy-to-setup workflow connects your cloud environments to SensorZero, then continuously polls and pulls in their logs. Nothing to install on a host — authorise the app against your tenant and the data starts arriving.

Microsoft 365

Microsoft 365

SensorZero connects to Microsoft 365 to read audit logs, user directory, and licence status, so security teams can detect advanced attacks and recover rapidly.

SensorZero M365 Ingestor
Google Workspace

Google Workspace

SensorZero connects to Google Workspace to read audit logs, user directory, and licence status, so security teams can detect advanced attacks and recover rapidly.

SensorZero Google Workspace Ingestor
03 — NETWORK COLLECTION

The traffic that endpoint and cloud logs never see.

A passive network sensor collects network data from your environment. Correlated with endpoint and cloud logs, it exposes the attacks that are hardest to spot from either source alone.

PASSIVE

No agent required

The sensor watches traffic without touching the hosts on it — including devices that can't run an agent at all.

EAST-WEST

Lateral movement

Host-to-host traffic inside the perimeter is where intrusions spread, and it rarely leaves a trace in a cloud audit log.

UNMANAGED

Everything else on the wire

Printers, cameras, contractor laptops and shadow IT show up the moment they talk to the network.

Where it goes

Collected once, used everywhere.

Everything the agents and cloud collectors send lands in one normalised schema — searchable in seconds, retained for the long term, and correlated across sources.

sensorzero

Connect your first source today.

Start free Back to the platform