GATECORE ENDPOINT PROTECTION · IDENTITY + DEVICE POSTURE

Lock the door.
Then prove it's locked.

GateCore protects the sign-in and the machine behind it. When something feels wrong, the screen locks itself and your admin knows within the same second. And every endpoint reports what protection is actually running — measured on the host, not assumed from a policy.

ONE AGENT · TWO LAYERS

Who's at the keyboard.
And whether the machine is safe to use.

Most tools answer one of these. An attacker only needs the other one to be unanswered.

LAYER ONE
Identity & access
Every sign-in verified, every failed attempt counted, every session accountable to a real person.
✓Brute force detected and the account locked in under a second
✓Push approval on the phone — console, RDP and remote sessions
✓Lock any user from the admin console, instantly
✓Active Directory and Microsoft Entra ID, no migration
LAYER TWO
Device posture
Microsoft Defender and Windows security settings, managed and verified from one panel — across every tenant.
✓Turn Defender protections on or off across the fleet
✓Core isolation, Secure Boot, BitLocker — state and control
✓A live security score for every machine, worst first
✓Isolate a suspicious host from the network in one click
Same agent. Same console. Same bill. Nothing to integrate.
⚡ ATTACK INTERCEPTED

A brute force attempt.
An immediate response.
A recovery in seconds.

This is what happens the moment an attacker tries to break in — from detection to lockdown to your admin console. Every step, automatic. Every event, accounted for.

1
14:32:01

Repeated login attempts

password123 ✗
admin2024 ✗
letmein! ✗
welcome1 ✗
qwerty99 ✗
P@ssw0rd ✗

An attacker tries credential after credential. The system is already watching — and the address they are coming from is already on its way to being blocked.

2
14:32:04

Account locked

🔒
Account Locked
Too many attempts

The screen freezes. No more attempts possible — only an authorized admin can unlock it.

3
14:32:04

Admin notified instantly

🔔
Lockdown alert
WIN-DESK-04
john@acme.com

A real-time alert reaches your admin console. They know what, where, and who — within the same second.

4
14:32:18

Admin reviews & decides

john@acme.com LOCKED
14 failed attempts WIN-DESK-04
Unlock account

The admin sees full context — failed attempts, device, timing — and acts with one click.

5
14:32:22

Back to work — securely

✓
Access restored
Operation continues

The legitimate user is back online. The threat is logged. Everything else kept running, undisturbed.

< 1s
Lockdown time
0
Successful breaches
~20s
Avg admin response
100%
Events recorded
🚫 SOURCE BLOCKING

Locking the account stops the attempt.
Blocking the address stops the attacker.

An attacker who runs out of guesses on one account simply moves to the next one. So GateCore doesn't just protect the account — it takes the road away.

IF YOU HAVE A FIREWALL

Blocked at the edge, before it touches your network.

Already running a hardware firewall? GateCore talks to it directly. The attacking address is pushed straight onto its block list, so the traffic stops at your perimeter and never reaches a single machine.

✗Direct integration with the firewall you already own — no new hardware to buy
✗One block covers every machine behind it
✗Your own rules are never touched — only ours are managed
Strongest option. If you have the hardware, this is where we put the wall.
IF YOU DON'T

Then every machine gets the block itself.

No perimeter device required. GateCore writes the block to every device in your tenant — not only the machine that was attacked. The address that failed on one server is already shut out of the other forty-six.

✓Tenant-wide by default — the whole fleet learns from one attack
✓Stays applied — removed on a host, it comes back on its own
✓Works on machines nobody has logged into for months
Buying a firewall later? Switch the integration on and the same blocks move to the edge.

The source is blocked, not just the account

The moment a brute force pattern is recognised, the address behind it is cut off — so the next account on their list never even gets a knock at the door.

One attack, the whole fleet protected

The address is not blocked only where it was caught. It is shut out across the tenant — so an attacker who found one exposed server has already lost the rest of them.

Reversible, and never a mystery

Every blocked address is listed with when it was blocked and what triggered it. Blocked your own branch office by mistake? Release it in one click.

✗ ATTACKER
185.220.101.44
blocked
→
PERIMETER
Your firewall
first line
→
✓ YOUR FLEET
Never reached
47 devices
Blocked addresses
14 ACTIVE
185.220.101.44
14 failed logons · 14:32:04 · just now
PERIMETER Release
45.134.26.180
31 failed logons · 09:11 · RDP
PERIMETER Release
103.97.203.12
22 failed logons · yesterday · SRV-APP-01
HOST Release
91.240.118.73
17 failed logons · 2 days ago · RDP
PERIMETER Release
Perimeter and host blocks, one listAcross all tenants
🌙 WHILE NOBODY IS WATCHING

Attacks don't wait for office hours.

Most brute force traffic arrives at three in the morning, at the weekend, over the Christmas break — precisely when there is nobody to notice it. GateCore doesn't need anybody to notice it. Detection, lockdown, blocking and logging all happen without a human in the loop. You read about it over coffee.

03:47Repeated failed sign-ins on SRV-APP-01
03:47Account locked, source address identified
03:47Address blocked — 47 devices covered
03:48Alert queued for the admin console
08:15Admin reads it. Nothing to fix.
No one was awake. Nothing was missed.
⚠

And if it isn't working on a machine, you will know

Brute force detection depends on failed sign-ins being recorded on the host. If that recording is switched off anywhere in your fleet, that machine shows a red badge in the device list — because a control you think you have and don't is worse than no control at all.

⚡ INSTANT LOCK

One click. Any user.
Locked in seconds.

A laptop walks out the door. An RDP session looks wrong. A leaver still has access. Hit lock from the admin console and that user's screen is sealed instantly — at a desk, on RDP, or working remote. It works for every account, Active Directory or Entra.

✓Lock any session straight from the admin console
✓Desk, RDP or remote — sealed in seconds
✓Every account — AD and Microsoft Entra ID
Talk to sales →
Active sessions
20 online
JS
j.smith
RDP · 192.168.1.42
ACTIVE
MA
m.adams
Remote · Entra ID
LOCK NOW
TK
t.khan
Console · CONTOSO\t.khan
ACTIVE
GateCore
Screen locked
Locked by administrator.
Verify on your phone to continue.
DEVICE POSTURE

A machine with protection
switched off looks completely normal.

Until someone looks. GateCore looks at every endpoint, every day, and reports what is actually running on the host — not what a policy says should be running.

Endpoint posture · 47 devices
SORTED: WORST FIRST
34
SRV-FILE-02
RTP OFF TAMPER OFF AUDIT OFF HVCI OFF SB ON BL OFF
Defender
MANAGED
68
WIN-DESK-12
RTP ON TAMPER ON AUDIT ON HVCI PENDING REBOOT SB ON BL ON
Defender
MANAGED
72
SRV-APP-01
RTP N/A TAMPER N/A AUDIT ON HVCI ON SB ON BL ON
Third-party AV
VISIBLE
96
WIN-DESK-04
RTP ON TAMPER ON AUDIT ON HVCI ON SB ON BL ON
Defender
MANAGED
Read the second row from the left. On SRV-FILE-02, failed logon auditing is off — which means brute force detection is not running on that machine at all. It sits on the device row, in the list, without opening anything. That is the difference between having a control and knowing it works.
ONE PANEL

Every Defender setting,
on every machine, from here.

No Group Policy edits, no remote desktop sessions, no walking to a server room. Change it in the console and the fleet follows.

Protection

The controls that decide whether anything is being caught at all.

Real-time protection
Tamper protection
Cloud protection
Scan downloads
Behaviour monitoring
Unwanted app blocking
Network protection
SmartScreen

Platform security

The Windows hardening most fleets never switch on, tracked through the reboot it needs.

Memory integrity
↳ restart requiredPENDING
Kernel stack protection
LSA protection
Vulnerable driver blocklist
Secure Boot
BitLocker · OS volume

Scan & threats

Run it from here, and see what it actually found — including how long it really took.

Quick scanRUN NOW
Update signaturesRUN NOW
Last scan · 4m 12sCLEAN
Trojan:Win32/Wacatac
SRV-FILE-02 · quarantined
SEVERE
PUA:Win32/Presenoker
WIN-DESK-12 · removed
MODERATE
Reboot-dependent changes are followed through on their own.
The pending badge clears itself when the machine comes back and confirms the change stuck.
ATTACK SURFACE

The settings nobody checks
are the ones attackers count on.

Legacy protocols, forgotten accounts, exposed desktops, admin rights that quietly multiplied. Visible per machine, across every tenant.

● FOUND ON 3 MACHINES

SMBv1 enabled

A protocol retired years ago, still switched on and still exploited.

● FOUND ON 1 MACHINE

RDP without NLA

Remote desktop reachable without network-level authentication first.

● FOUND ON 2 MACHINES

Guest account active

An account nobody uses, nobody watches, and nobody disabled.

● 7 LOCAL ADMINS

Admin rights spread

Every extra administrator is another full set of keys to the machine.

● ALL MACHINES

Failed logon auditing

Without it, brute force detection has nothing to read. Checked on every host.

● POLICY-DRIVEN

Attack surface rules

Office macros, script abuse, credential theft — set per rule, applied per tenant.

● PER PROFILE

Firewall profiles

Domain, private and public — you see which profile is actually on.

● PERIMETER + HOST

Blocked addresses

Attackers blocked at the edge and on the machine, listed in one place.

FIREWALL RULES

Write the rule once.
It stays on every machine.

Adding a firewall rule normally means a script, a group policy, or a laptop-by-laptop afternoon. Here it's a form — and what you set is what the fleet keeps.

🏢

Pick how far it reaches

One machine, one organisation, or every tenant you manage. Block or allow, inbound or outbound, by port, address, program or network profile.

🔄

It doesn't stay deleted

Someone removes the rule on a machine — by accident, by script, or on purpose. It comes back on its own. The panel is the source of truth, not the host.

🛡

Edit or remove from the same place

Change a port, disable a rule, delete it entirely. The fleet follows the panel — there is nothing to undo machine by machine.

Firewall rules · Contoso Foods
ALL DEVICES
12
TOTAL
5
BLOCK
7
ALLOW
0
DISABLED
Block outbound 4444
TCP · remote port 4444 · all profiles
BLOCK
Block legacy file sharing
TCP · port 445 · removed on WIN-DESK-12
↻ BACK IN PLACE
Allow line-of-business app
TCP · local port 1433 · domain profile
ALLOW
Block outbound · unapproved app
any protocol · by program path
BLOCK
Scope: every host in the tenant+ Add rule
✓

The rules you already have are left alone

GateCore only manages the rules GateCore created. Everything your own team, your line-of-business software or your existing security tooling put on those machines is never edited, disabled or removed.

RESPONSE

Seeing it is half the job.

Three actions, all reversible, all logged — because production doesn't stop for a security decision.

Isolate host

A machine starts behaving wrong. Cut it off from the network in one click, keep the console connection, and decide what happens next without the rest of the fleet at risk.

ONE CLICK · REVERSIBLE

Exclude from scope

Domain controllers, backup and virtualisation hosts can be put fully out of scope. No collection, no enforcement, and isolation can never fire on them. Some machines must never be touched automatically.

CRITICAL SERVERS

Maintenance window

Doing planned work? Pause self-healing, alerts and isolation for ten minutes or an hour. It switches itself back on — nobody has to remember.

10 MIN · 1 HOUR
HONEST ABOUT WHAT IT ISN'T

Already running another antivirus?
Keep it.

GateCore is not an antivirus and doesn't try to replace one. It manages the Defender side and shows you the whole fleet either way.

DEFENDER-MANAGED HOSTS

Posture reportingFULL
Policy changes appliedYES
Scan & signature controlYES
Platform hardeningYES

THIRD-PARTY AV HOSTS

Posture reportingVISIBLE
Policy changes appliedNOT MANAGED
Scan & signature controlNOT MANAGED
Platform hardeningYES
Defender policy actions apply only to Defender-managed hosts. Machines running another antivirus stay visible, not managed — you still see their platform security, attack surface and firewall state next to everything else.
SELF-PROTECTING ARCHITECTURE

It watches itself,
so nothing can silence it.

Every layer of GateCore continuously verifies the others. If something is tampered with, the system reacts before it can be exploited. Silent failure isn't possible — and neither is a quiet bypass.

🔄

Continuous self-verification

The system checks its own integrity at every moment. There is no time window where protection is unwatched.

🛡

Tamper-proof by design

Stopping a service. Killing a process. Modifying a file. Every attempt is detected, blocked, and logged — even from administrators.

📡

Always-on telemetry

Every event flows to your admin console in real time. Silent failure is impossible.

Active monitoring
WIN-DESK-04 · Real-time
🛡
GateCore Core
● HEALTHY · SELF-MONITORING
Integrity check✓ PASSED
Tamper detection● ACTIVE
Server telemetry● CONNECTED
REMOTE DEPLOYMENT

Deploy. Update. Uninstall.
One click. Any device.

No more remote desktop sessions. No more on-site visits. From your admin console, you control every device's lifecycle — securely, instantly, with full accountability.

📦

Push to any device

Deploy new versions to one machine, a group, or your entire fleet — from a single click in the admin panel.

🔄

Update without disruption

Roll out updates silently in the background. Protection never drops — not even for a second.

🔐

Authorized uninstall only

Even uninstallation requires an admin-issued, one-time token. No one — including IT staff with admin rights — can remove protection without your approval.

Deployment console
SuperAdmin · 47 devices managed
📦Deploy v2.4.1
IN PROGRESS
Pushing to 12 devices · Marketing team
9 of 12 completed72%
🔄
Silent update applied
WIN-DESK-04 · v2.4.0 → v2.4.1
✓ SUCCESS
🔐
Uninstall token issued
SRV-OLD-01 · Single-use · 1h validity
AUTHORIZED
🛡
Unauthorized removal blocked
WIN-DESK-12 · No token · Admin alerted
BLOCKED
ENTERPRISE IDENTITY

It already speaks your directory.

On-prem Active Directory or Microsoft Entra ID — GateCore connects once and protects every sign-in. No migration, no schema changes, almost nothing for IT to do.

Active Directory
ON-PREMISES · AD CONNECTOR
Install the connector once. Your domain users are mapped to MFA automatically — hands-off.
✓Single setup, no migration
✓Domain accounts auto-mapped
✓Almost zero IT workload
Microsoft Entra ID
CLOUD · AZURE AD
Already on Microsoft 365? Users sign in with Microsoft and approve on their phone. Personal & guest accounts blocked.
✓Sign in with existing Microsoft account
✓Personal accounts blocked
✓Guest / B2B accounts blocked
One approval flow · every outcome
GateCore
Approve on your phone
Open GateCore Authenticator and enter this number to continue.
98
Expires in 00:27
Only approve if you started this sign-in.
GateCore
Sign-in denied
This request was denied on your phone.
Access was blocked
The sign-in attempt did not continue.
GateCore
Request expired
This sign-in request timed out. Please try again.
Expired in 00:00
No approval was given in time.
ZERO BYPASS

What attackers try.
What actually happens.

Every method an attacker might use to disable security — already accounted for.

⊘ What they try

✗Stop the protection service
✗Kill the running process
✗Uninstall with admin rights
✗Modify protection files
✗Quietly switch off real-time protection
✗Reboot in safe mode

✓ What actually happens

✓Service stop requires authorization — admin notified
✓Process kill detected instantly — auto-recovery
✓Uninstall requires server-issued one-time token
✓File integrity verified continuously, auto-restored
✓Protection switched back on and the change recorded
✓Protection persists across all boot modes
UNIQUE CAPABILITIES

Built differently.
So it works differently.

⚡

Sub-second response

From threat detection to full lockdown — measured in milliseconds, not seconds.

👤

Identity-aware

Every action, every session, every login — mapped to a real person. Always accountable.

🖥

Multi-session aware

Console, RDP, concurrent users — each session protected independently.

📊

Measured, not assumed

Protection state is read from the machine itself. What you see on the row is what is running on the host.

🏗

Worst machine first

A live score per device, sorted so the endpoint that needs you most is already at the top of the list.

🏢

Multi-tenant by design

Separate policy and configuration per tenant. Admins see their own; you see everything.

🔒

Cannot be disabled

Built on a self-protecting design. Even administrators can't bypass it without authorization.

📦

Remote deployment

Deploy, update, and uninstall — all from one admin console. No RDP, no on-site visits, no downtime.

👁

Complete telemetry

Every login. Every lockdown. Every setting change. Searchable, exportable, accountable.

Operations stay smooth.
Threats stay out.

Try GateCore Endpoint Protection today. Cancel anytime.