Threat-Driven Application Control

YourTrustedToolsAreanAttacker'sBestWeapon

MagicSword is threat‑driven application control that blocks the abuse of legitimate tools, the #1 way attackers breach networks today.

Agentless Or With Agent48-Hour DeploymentAutonomous Triage

Powered by research alongside

Elastic
Splunk
Microsoft
CrowdStrike
CISA
Elastic
Splunk
Microsoft
CrowdStrike
CISA
Elastic
Splunk
Microsoft
CrowdStrike
CISA
Elastic
Splunk
Microsoft
CrowdStrike
CISA
The Problem
0%

of detections
were malware-free

EDR, XDR, MDR, and SIEM detect these attacks, but do not prevent them

CrowdStrike 2026 Global Threat Report
Hundreds of Millions in Losses · Without Malware
2021

Kaseya

RMM tool weaponized to deploy REvil ransomware across 1,500+ companies

RMM abuse

$500M+

downstream impact

2025

Mark & Spencer's

Scattered Spider used legitimate admin tools to breach retail systems

SimpleHelp RMM abuse

£700M+

market value lost in days

2024

Change Healthcare

ALPHV/BlackCat exploited remote access tools affecting millions

LOLBAS abuse

$2.2B

remediation costs

Architecture · Where We Fit

MagicSword + EDR. Same Endpoint. Same Telemetry. Different Problems.

Your EDR and MagicSword live in the same place, see the same things, and solve different problems.

Your organization
people, data, systems
56 ENDPOINTS · 1 HIGHLIGHTED
Zoom in ↓
One endpoint
laptop, server, workstation
EDR / XDR
Detects & responds
what's malicious by nature
MagicSword
Prevents & controls
what's malicious by use
Telemetry
processes · files · software inventory

Your EDR sees the threat. MagicSword stops it.

Circle 01
EDR / XDR

Detects what's malicious by nature.

  • Malware & trojans
  • Ransomware payloads
  • C2 & beaconing
  • Infostealers & RATs
  • Exploit payloads
  • Lateral movement
Shared
Same telemetry
Process eventsFile systemSoftware inventory
+ AMSI hooks+ Spawn Ctrl rules+ Built-in detections
Circle 02
MagicSword

Prevents what's malicious by use.

  • RMM abuse
  • BYOVD / drivers
  • LOLBAS / dual-use
  • Signer abuse
  • Browser extensions
  • EDR killers

On average, a 1,000-endpoint company sees a 208% ROI. Calculate yours

Threat-Driven · Updates Every 2 Hours

Your Policy Knows What to Block Before You Deploy It

Backed by 17+ threat intelligence feeds, updated every 2 hours, that automatically generate enforcement-ready rules. You start protected, not from scratch.

Learn how our threat intelligence works
0+

Remote Management Tools

The #1 vector in major breaches. Blocked by default, allow only what you use.

0+

Living-off-the-Land Binaries

PowerShell, PsExec, Sysinternals: controlled, not banned.

0+

Vulnerable Drivers

BYOVD attacks stopped at the kernel level. No EDR tampering.

0%

Your Environment Data

Collect audit logs, auto-allow what your teams need. Nothing else.

Deployment · 3 Simple Steps

From Policy to Enforcement in 48 Hours

Three simple steps to go from zero to fully enforced application control. Create your policy, deploy in audit mode, then analyze and enforce, all in under 48 hours.

1

Create Your Policy

Create a policy in minutes. Choose a profile, describe what your teams use, and MagicSword automatically builds your rules, pulling from live intelligence on abused RMM tools, Windows binaries, Sysinternals misuse, and known-bad driver publishers.

Unlike static allowlists, MagicSword refreshes every 2 hours.
magicsword — policy wizard
MagicSword policy creation wizard showing intel sources, AI-generated rules, and coverage summary
2

Deploy in Audit

Deploy with our lightweight agent or go agentless via PowerShell, GPO, SCCM, or Microsoft Intune. Run in Audit for 24–48 hours to learn what your endpoints actually use before enforcement.

Learn your environment without breaking workflows.
magicsword — deploy policy
MagicSword deployer showing policy selection, target machines, and audit mode deployment
3

Analyze & Enforce

Investigate everything running across your fleet. Software inventory, parent-child process trees, filesystem scanning, and AI-powered risk analysis give you full visibility. Auto-tune your policy with one click, then enforce when you're ready.

Deep visibility with zero complexity. Nothing is enforced without your approval.
magicsword — investigate
MagicSword investigate dashboard showing 63K events, process trees, software inventory, and AI-powered analysis

Works with your stack

Windows
macOS
Linux
PowerShell
Defender
Slack
Teams
Syslog
Email
Webhooks

What Security Leaders Say

Trusted by Teams Who Refuse to Wait for the Breach

We tried to build application control ourselves with native Windows tooling. We understood the technology, we just couldn't figure out how to deploy it across 1,250 endpoints without breaking things or creating a maintenance nightmare. MagicSword gave us enterprise-grade application control without hiring a full-time person to maintain it.

Director of Security

Fortune 500 Financial Services Firm

1,250 endpoints protected

Being agentless is a real differentiator. We didn't want to deploy another agent. We deployed through our existing RMM, tested across departments, and were enforcing policies within weeks. The open source reputation is what got us in the door, the product is what made us stay.

IT Security Lead

Major European City Government

1,100 endpoints protected

Compliance Frameworks Supported
Frequently Asked Questions

Everything You Need to Know

Prevention Lab Weekly

Stay Ahead of Emerging Threats

Weekly threat intelligence, RMM abuse trends, and application control strategies delivered to your inbox.