OmniProtect delivers world-class threat detection and response at a fraction of the cost. Full data sovereignty. Deploy anywhere in under 30 minutes.
24
Clients
1,847
Agents
3
Open Incidents
1
Critical
48
Detection Rules
12
MITRE Tactics Covered
4
Supported Platforms
<1s
Alert Latency
100%
Open Source
Platform Capabilities
Purpose-built for Managed Security Service Providers delivering EDR to multiple clients from a single pane of glass.
LangGraph multi-agent correlation engine connects disparate events across endpoints to surface attack campaigns that rule-based systems miss.
≤4% CPU and ≤80 MB RAM steady-state. eBPF collectors on Linux, ESF on macOS, ETW on Windows — deep visibility without the performance tax.
Schema-per-tenant PostgreSQL isolation. Provision clients in seconds, drill into any tenant console from the MSP portal, generate enrollment tokens on demand.
Automated IOC ingestion from CISA KEV, MalwareBazaar, AlienVault OTX, and MISP. LMDB-backed local store delivers sub-millisecond IOC lookups.
Interactive heatmap shows exactly which ATT&CK techniques are covered per tenant. Identify detection gaps and prioritize rule development with data.
Apache 2.0 licensed — use it, fork it, sell it. Full Helm chart for RKE2/K3s, a typed Python integration SDK, and sovereign CI via Forgejo Actions.
Getting Started
No 6-week onboarding, no professional services engagement. Self-hosted, self-managed, fully yours.
Run `make dev-up` or apply the Helm chart to your K3s/RKE2 cluster. The full platform — API, Kafka, Keycloak, PostgreSQL, Redis — is up in under 5 minutes.
helm install omniprotect helm/omniprotect/ \
--set keycloak.enabled=true \
--set kafka.enabled=trueCreate tenants in the MSP portal, generate enrollment tokens, and deploy the Rust agent to endpoints. One command installs and enrolls automatically.
curl -fsSL https://get.omniprotect.io/agent \
| ENROLLMENT_TOKEN="tok_xxx" bashLive threat intelligence populates the IOC store. Behavioral rules fire. The AI correlation engine links events into campaigns. Respond with one-click isolation.
POST /api/v1/agents/{id}/isolate
POST /api/v1/correlation/analyzeTechnology
Every component chosen for performance, security, and long-term maintainability.
Rust 1.77
Agent runtime
FastAPI
Platform API
Next.js 14
Console
PostgreSQL 16
Schema-per-tenant
Kafka 3.8
Event streaming
Keycloak 26
Identity & SSO
Redis 7
Cache layer
Claude Opus 4.6
AI correlation
Helm / K3s
Deployment
Why OmniProtect
Compare against leading enterprise EDR vendors on the market.
Get Started Today
Deploy in under 30 minutes. No sales call, no contract negotiation, no per-seat fees. Full source code included.
Apache 2.0 Licensed · Full source at github.com/OCSGroup101/Business_AIProtector