Everything in one
intelligent platform

Six powerful pillars that work together to give you total visibility and control over every application on every Windows device you manage.

01 — Policy Engine

Drag, drop, and control what runs

Build application control policies visually. Drag apps from the pre-built library into your allow or deny list, organise them into groups, and assign policies to individual devices, device groups, or your entire estate. No command line. No XML. Just a clean, intuitive interface that your team will actually want to use.

  • Visual drag-and-drop policy builder
  • Assign policies to devices, groups, or all endpoints
  • Default-deny or default-allow modes
  • Audit log of every policy change
  • Near-instant propagation to endpoints (<1 second)

Rule examples

Publisher Microsoft Corporation Allow
Path C:\Tools\Admin\* Allow
Hash a1b2c3d4e5f6... Deny
Publisher Unsigned / Unknown Deny

02 — AI Decision Engine

90% of decisions, zero human effort

Toggle AI on or off per policy. When enabled, our decision engine automatically evaluates every application execution attempt against real-time threat intelligence, publisher reputation databases, code-signing validity, and behavioural heuristics. Most decisions are made in milliseconds. When the AI is uncertain, it escalates gracefully to your IT team — no false positives, no blocked workflows.

  • Enable or disable AI per policy
  • Real-time threat intelligence lookups
  • Code-signing certificate verification
  • User app request interpretation
  • Confidence-based escalation to humans

Live AI decisions

Zoom.exe
Zoom Video Communications — Trusted publisher
Allowed
nc.exe (Netcat)
Known Riskware
Denied
?
InternalTool.exe
Low confidence · Escalated to IT
Review

03 — Application Library

250+ apps, pre-classified and ready

Don't start from a blank slate. Cybrshield ships with a curated library of over 250 common Windows applications, pre-grouped into logical categories. Block known attack tooling from the first day. Allow your standard software stack in seconds. The library is continuously updated as new applications are classified.

  • 250+ pre-classified applications
  • 100+ high-risk tools blocked by default
  • Grouped by category for fast selection
  • Continuously updated threat catalogue

App categories

💬 Collaboration
Microsoft Teams, Slack, Zoom, Webex, Google Meet...
🎵 Media & Entertainment
Spotify, VLC, Windows Media Player, iTunes...
📁 File Transfer
WinSCP, FileZilla, OneDrive, Dropbox, Box...
🛠️ Development Tools
VS Code, Git, Node.js, Python, Docker Desktop...
🚨 Blocked by Default
Mimikatz, Netcat, PowerSploit, Metasploit, +100 more...

04 — Deployment & Multi-Tenancy

Built for one team or a thousand

Set up a tenant in minutes. Roll the agent out via the deployment channel that suits you — EXE for RMM tools or PowerShell for manual installs. Managed Service Providers and multi-site organisations can manage as many tenants as they need from a single login, each with its own policies, devices, API tokens, and audit trail. Nothing crosses the boundary.

  • EXE, GPO, Intune, and RMM deployment options
  • Strict per-tenant data isolation
  • Agents tied to each tenant
  • Bulk device enrolment with auto-generated install tokens
  • Single-pane tenant switcher for MSPs
  • SSO & SCIM provisioning on the roadmap

Tenants under one login

A
Acme Manufacturing
412 devices · 18 policies · Intune
Healthy
B
Bluefin Legal LLP
62 devices · 9 policies · GPO
Healthy
C
Coastline Charity
27 devices · 5 policies · RMM
3 to review
One login · isolated data · zero cross-tenant leakage

05 — Dashboard & Analytics

See every decision, in real time

The Cybrshield portal gives every tenant a live window into their estate. Watch verdicts stream in as they happen, drill into any allow or deny event, and export anything you need for audit. Every admin action is logged. Every policy change is timestamped. Nothing happens on your endpoints that you can't review or roll back.

  • Real-time event timeline with verdict reasoning
  • Per-policy allow / deny / review counters
  • Pending user requests queue with one-click approve / deny
  • Full audit log of every admin action
  • CSV and JSON export for compliance reporting
  • Monthly digest emails for tenant administrators

Today at a glance

2,841
Allowed today
147
Denied today
12
Pending review

Live event feed

14:02:11 FIN-LT-018 · chrome.exe Allow
14:02:08 HR-LT-002 · psexec.exe Deny
14:01:53 DEV-LT-041 · node.exe Allow

06 — Endpoint Agent

Invisible to users. Always watching.

The Cybrshield agent runs silently on every managed device as a lightweight Windows service. It enforces your policies in real time, streams execution events to the portal, and allows users to submit access requests — all while using minimal CPU and memory. Deploy EXE using PowerShell or via RMM solutions.

  • Supports Windows 11 x64
  • Low CPU and RAM footprint
  • Desktop app request prompt for end users
  • Real-time event streaming to the portal
  • Tamper-resistant service

Agent system requirements

OS Windows 11 (64-bit)
CPU overhead <0.5% average
RAM usage ~12 MB resident
Install size ~8 MB
Deployment EXE · GPO · Intune · RMM · PowerShell

Ready to take control of
every endpoint?

Start free today. No credit card, no commitment — just powerful app control from day one.