Overview
NPAV EDR provides advanced endpoint protection for both workstations and server operating systems, combining signature-based and signature-less detection technologies to identify and stop known, unknown, and emerging cyber threats.
To enhance endpoint security, NPAV EDR includes Memory Scanning for Windows systems and Kernel-Level Memory Scanning for Linux systems. These capabilities enable the solution to detect malware that resides in system memory or attempts to operate at the operating system kernel level, where traditional file-based detection may not be sufficient.
Memory Scanning
The Memory Scanning feature continuously monitors active processes and system memory to detect malicious code executing in memory without relying solely on files stored on disk. This helps identify advanced threats such as:
- Fileless malware
- Memory-resident malware
- Process injection attacks
- Code injection techniques
- Reflective DLL injection
- Advanced Persistent Threats (APTs)
Memory scanning allows NPAV EDR to detect suspicious activities in real time and automatically initiate appropriate response actions before the threat can compromise the endpoint.

Kernel-Level Memory Scanning
For Linux environments, Kernel-Level Memory Scanning provides deep inspection of kernel memory and operating system components to detect sophisticated attacks targeting the Linux kernel.
The feature helps identify:
- Kernel rootkits
- Kernel module manipulation
- Privilege escalation attempts
- Unauthorized kernel modifications
- Hidden malicious processes
- Advanced Linux malware
By monitoring kernel-level activities, NPAV EDR strengthens endpoint protection against attacks that attempt to evade conventional security controls.

Key Benefits
- Supports Windows workstations, Windows servers, and Linux endpoints.
- Signature-based and signature-less malware detection.
- Real-time memory scanning for Windows systems.
- Kernel-level memory scanning for Linux systems.
- Detects fileless attacks and memory-resident malware.
- Protects against rootkits, kernel exploits, and advanced persistent threats.
- Centralized configuration and monitoring through the NPAV EDR Management Console.