Spyderbat continuously records ALL runtime context in an environment (from Kernel to Cloud) while providing causal linkage (recording both good & bad events alike). Alerts can then be traced along the resultant causal chain that's created. Normal behaviors can then be safely ignored, allowing practitioners to focus on more toxic combinations ONLY (i.e., Alerts-to-Traces).
Practitioners can then group behaviors for another order of magnitude reduction in alerts.
To do this, Spyderbat has developed the following algorithms:
Collectively this delivers on the value chain from causality through enforcement.