So that anyone can detect cyber threats...
The Polvo Project develops a lightweight agent program, reducing the fatigue of security officers. It collects, analyzes, and abstracts various system logs into 'actions' (technically called 'traces') in real-time.
Traditional blue-team security software is primarily focused on collecting raw system logs, storing them in a database, and visualizing them on sophisticated dashboards. This led to the entire observation system being unobservable and overly complicated; ultimately, it failed to satisfy the needs of the people in the field, suggesting valuable information that could be used to take action. We aim to directly address this issue by providing real insights with actionable steps.