Learns Normal. Catches the Unknown.
Patented Behavioral Anomaly Detection for the Threats Signatures Can’t See.
Behavioral Baseline for Every Host
Profiles Dozens of Behavioral Facets
Explainable Anomaly Scoring
Catches the Zero-Day, Insider, and Low-and-Slow Threats
U.S. Patent 9,866,578
See how Qato works.
A quick look at how Qato learns what’s normal for every host — and catches the zero-day, insider, and slow-moving threats signatures miss.
Signatures can’t catch what they’ve never seen.
Firewalls, antivirus, and intrusion detection are essential — but they all work the same way: matching activity against known attack signatures. That catches known threats. It leaves three blind spots.
Zero-day exploits
A brand-new exploit has no signature to match — so signature-based tools have nothing to compare it against.
Insider threats
An insider carrying valid credentials isn’t breaking any rule a signature would flag. The access looks legitimate.
Slow-moving APTs
An advanced threat that moves slowly enough blends into normal traffic and never trips a signature.
You know your network better than any attacker does.
Malicious activity almost always deviates from normal behavior. The hard part is seeing those deviations across an entire fleet, around the clock. Instead of cataloging every possible attack, Qato learns what each host does normally — across dozens of behavioral facets, with separate baselines for different times of day. No two hosts share the same profile.
An attacker can study a public signature database and design around it. They can’t study what Qato has learned about a specific server on your network.
From baseline to detection in four steps.
Qato learns what each host does normally, then watches for the deviations that signature-based tools can’t see — with the evidence to investigate every one.
Deploy
Lightweight agents install on Linux and Windows hosts and stream behavioral statistics to the Qato server — minimal footprint, no kernel modules.
- Lightweight agents on Linux & Windows — no kernel modules
- Collect connection counts, process activity, port usage, and authentication events
- Results stream to the Qato server
Learn
Qato builds rolling baselines for each host across dozens of behavioral facets, with separate profiles for different times of day. No two hosts share the same profile.
- Rolling baselines per host across dozens of behavioral facets
- Separate profiles for business hours, off-hours, and weekends
- Baselines sharpen over weeks as more data accumulates
Detect
When recent behavior deviates from baseline, Qato scores the anomaly — each facet weighted by importance — into an overall score with a full breakdown of what changed and by how much.
- Each facet scored for deviation, weighted by importance
- Overall anomaly score with a full breakdown vs. baseline
- Clusters anomalies into detections; flags correlated activity across hosts
Investigate
Every anomaly links to captured evidence — the actual processes, connections, and events from that time window. Analysts see what happened, not just that something happened.
- Every anomaly links to captured evidence
- The actual processes, connections, and events from the time window
- See what happened — not just that something happened
Two ways to defend. One of them sees the unknown.
Signature-based tools catch what they’ve already catalogued. Qato catches deviation from normal — known threat or not.
- DetectsKnown threats with an existing signature
- Zero-dayBlind until a signature is written
- Insider w/ valid credsLooks legitimate — nothing to flag
- Slow APTBlends into normal traffic
- EvasionAttacker studies the public signature set and designs around it
- DetectsDeviation from normal — known or unknown
- Zero-dayCaught as anomalous behavior, no signature needed
- Insider w/ valid credsFlagged when behavior deviates from that user’s baseline
- Slow APTSurfaces against the host’s own time-of-day baseline
- EvasionCan’t study a baseline private to your specific host
The detection gap the government named.
In February 2024, CISA, the NSA, and the FBI told defenders their tools share a blind spot: they can’t tell a real admin from an attacker using the same tools and stolen credentials. The fix they prescribed — baseline normal behavior and alert on the deviation — is exactly what Qato does.
Volt Typhoon operated inside U.S. critical infrastructure for more than five years — using valid credentials and built-in tools, evading signature-based detection the entire time.
The gap they named
Signature- and IOC-based tools — including EDR — miss attackers who use valid credentials and built-in admin tools. There’s no signature to match and nothing looks broken, because defenders have no baseline of what’s normal.
Baseline, then alert on the deviation
Their guidance: build or acquire automation that compares live activity against a behavioral baseline for each host — and alerts on the anomalies, not on known signatures.
Exactly what they said to deploy
Qato learns each host’s normal, flags what deviates, explains why, and forwards the detection into the SIEM you already run. It fills the detection gap the government named.
The people who track these threats keep saying the same thing.
Detecting these intrusions requires defenders to discern legitimate behavior from malicious behavior — and to conduct behavior analytics, anomaly detection, and proactive hunting.
CISA teams have found and eradicated Volt Typhoon intrusions across critical infrastructure — and what we’ve found to date is likely the tip of the iceberg.
Attackers are taking steps to evade detection and remain on systems for longer.
The one thing an attacker can’t study.
An attacker can read every public signature database and design around it — but they can’t study the behavioral baseline Qato has learned about your specific hosts. Qato augments the EDR, NDR, and SIEM you already run: it learns what’s normal, flags what deviates, explains why, and forwards the detection into your stack. Now in R&D testing with select customers; launching commercially in 2026.

