Skip to content

Corporate Security

Corporate security teams govern Capsem through signed profiles, enforcement packs, detection packs, telemetry configuration, and runtime evidence.

AreaWhere
Profile governanceCorporate Deployment
Profile format and pinsProfile Format
Signed catalog rolloutProfile Catalogs
Realtime blockingEnforcement
Detection and forensic searchDetection Format
VM health and metricsVM Health
Telemetry extension rulesExtending Telemetry
Admin CLI workflowscapsem-admin

Enforcement is synchronous and can allow, block, ask, or rewrite. Detection is finding generation and forensic analysis. Detection findings are attached to the resolved event before telemetry/logging/export sinks, but they do not silently become blocking decisions.

Runtime operators can validate, compile, backtest, install, list, delete, and inspect stats through /enforcement/* and /detection/*. Corp admins can validate and backtest packs offline with capsem-admin before publishing them through signed profiles.

Backtest and hunt return aggregate counts plus up to 100 matched event rows by default. Rows are deduplicated by evidence signature to show diversity. Local evidence is full-fidelity for users who can access Capsem. Export/support bundle redaction is an explicit separate flow.