WYBOT Cybersécurité
FR / EN
BOOK A MEETING →
100% FRENCH SOLUTION · SOVEREIGN

100% of traffic.
100% of machines.
Zero blind spots.

Wybot detects the invisible threats that firewalls let through and neutralises them in real time.

WYBOT://LIVE
TRAFFIC ANALYSED
100%
THREATS DETECTED / YR*
0
MONITORING
24/7
STATUS
SECURE
◦ HELPS YOU MEET NIS 2 & ISO 27001 REQUIREMENTS◦ 100% FRENCH solution◦ PATENTED TECHNOLOGY◦ 20+ YEARS OF EXPERTISE◦ INDEPENDENT from foreign technologies
// THE WYBOT PROBE

End-to-end monitoring of your entire network

Eight advanced analysis engines for 360° protection coverage
+
[ NDR// FUNCTION · NDRNDR — Network Detection & ResponseThe NDR analyses 100% of network traffic to reveal the malicious behaviour that firewalls and antivirus let through. It handles:North-south & east-west flow inspectionDetection of advanced threats and illegitimate flowsAnalyse protocolaire & applicative (moteur nDPI)Malicious IPs & domain names, including the DarknetDetection of lateral movementRecognition of attack signaturesBandwidth monitoring & exfiltrationVIEW THE NDR PAGE → ]
Network

Network analysis

100% of traffic inspected continuously to detect intrusions and the invisible threats that firewalls let through.

North-south & east-west traffic inspection
Detection of advanced threats and illegitimate flows
Protocol & application analysis 
+
[ AGENT// FUNCTION · AGENTThe Agent, protection at endpoint levelThe Agent extends the probe all the way to the endpoints. It protects machines even when they leave the company network (remote work, travel, mobility), where network monitoring no longer covers them. It handles:Real-time monitoring of every endpoint and serverDetection & termination of dangerous processesChecks that protections (antivirus and firewall) stay activeUSB device monitoringOS update monitoring Protection on the move, outside the company networkVIEW THE AGENT PAGE → ]
Endpoint

Endpoint protection

Every machine and application is monitored in real time to identify and stop dangerous processes.

Real-time monitoring of every endpoint
Detection of suspicious behaviour & processes
Health check of connected equipment
+
[ SCAN// PRINCIPLE · THE SCANWhat is a vulnerability scan?A vulnerability scan is an automated inspection of the network: the probe queries every connected device to assess its security, with no manual intervention and without disrupting activity. In practice, the scan:Découvre all the IP devices present (PCs, servers, printers, IoT…).Identifie systems, software versions and open ports/services.Compare ces éléments aux vulnérabilités connues (CVE).Note each flaw by criticality (CVSS score).VIEW THE SCANNER PAGE → ]
Scanner de vulnérabilités

Vulnerabilities

Detects flaws on every connected device: a full scan of the estate every three days.

Scan of every IP device on the network
Prioritisation of critical flaws
Regular compliance tracking
+
[ ACTIVE// FUNCTION · ACTIVE RESPONSEActive response: from flagging to blockingBy default, the probe detects and alerts. Active response is the blocking process you enable on the probe: once switched on, Wybot no longer just warns, it acts to stop the threat. It allows:Detection of an illegitimate flowAutomatic blockingNeutralisation of the threat before it spreadsEnabled in line with your security policyREQUEST A TEST → ]
Réponse active

Active response

Wybot does not just alert: it blocks and neutralises threats before they strike.

Detection of an illegitimate flow
Automatic blocking
Instant alert: notification, e-mail & mobile app
Physical or virtualised appliance · port mirroring from the switch or firewall · no impact on network performance
// NDR & EDR

Why NDR is essential, even with EDRs

The EDR protects endpoints; the NDR watches the network. An attacker can disable or bypass an EDR, but cannot move across the network without leaving a trace: that is the moment the NDR detects them.

THE FINDING

No EDR on the market can block 100% of attacks.

Every year, MITRE// REFERENCE · MITREMITRE and the ATT&CK frameworkMITRE is a US non-profit organisation of public interest, recognised worldwide in cybersecurity research. It maintains ATT&CK, the reference knowledge base of attacker tactics and techniques, and each year runs independent, transparently published evaluations of security solutions.ATT&CK knowledge base of attack techniquesIndependent annual evaluations of solutionsRésultats publics et neutres, référence du marchéLEARN MORE → runs evaluations that put the market's best EDRs through real-world attack scenarios: none of them blocks every attack. Relying on EDR alone means accepting blind spots. Wybot's NDR covers precisely what the EDR lets through.
 The MITRE evaluation reports, available at this link, demonstrate it.

Only network activity betrays the intrusion.

EDR · ENDPOINT

On the machines

Sees what runs on each endpoint
Blocks malicious processes locally
Blind if the agent is missing, disabled or bypassed
Cannot see agentless devices (IoT, printers…)
NDR · NETWORK

On the flows

Sees 100% of traffic, with nothing installed on endpoints
Detects an attacker's lateral movements
Covers agentless devices (IoT, OT, guests)
Stays effective even if an endpoint is compromised

Wybot combines both: the Agent on endpoints and the NDR on the network, leaving no blind spot.

The MITRE ATT&CK evaluations confirm it every year: no EDR blocks 100% of attack scenarios.

// REAL-TIME THREAT INTELLIGENCE

While you read this page

ACTIVE MONITOR

Around 450,000 new malicious programs appear worldwide every day (source: AV-TEST). Wybot continuously detects and blocks the malicious files, domains and IP addresses targeting your network.

MALWARE CREATED WORLDWIDE · TODAY
0
▲ ~5 / seconde
MALICIOUS DOMAIN NAMES · TODAY
0
▲ ~1 / seconde
MALICIOUS IP ADDRESSES · TODAY
0
▲ ~3 / seconde
* Estimates calculated by extrapolating the average volumes observed across the Wybot probe fleet and public data (AV-TEST).
WYBOT://THREAT-FEED LIVE
WYBOT://ORIGIN-OF-FLOWS MALICIOUS FLOWS
TOP SOURCE COUNTRIES
Russie24 %
China19 %
United States13 %
North Korea9 %
Iran8 %
Brésil6 %
Autres21 %
Source: aggregated telemetry from the Wybot probe fleet.
Your network protected · France
// PILOTAGE

Real time for your teams, reports for your leadership

Wybot dashboard — real-time monitoring VIEW THE DASHBOARD →
[ DASHBOARD ]

Your threats, 24/7

A clear, friendly dashboard to see the state of your network without being a cybersecurity expert. Your teams get an at-a-glance view of detected threats and probe activity.

360° view of the network, flows and equipment
Threats and vulnerabilities shown live, 24/7
Alerts also available from the mobile app
[ REPORTING ]

Reports for leadership & the executive committee

The probe produces concise security reports designed for senior management and executive committees: a clear read on the risk level, without technical jargon, to make informed decisions.

Summary of the risk level and key indicators
Periodic reports ready to present to the executive committee
Concrete support for your NIS 2 & ISO 27001 requirements
Confidentiality preserved: report generation never passes through any artificial intelligence or third-party service.
// MOBILE APP

Your security alerts, wherever you are

Real-time notifications and e-mails: check the state of your network and detected threats straight from your smartphone. The Wybot app is available on iOS and Android.

Push alerts the moment a threat is detected
Network and equipment status, 24/7
Incident history at your fingertips
Download on the App Store Get it on Google Play
9:415G
9:41
Monday 13 July
W
Threat blockednow
Malicious IP neutralised · botnet C2
W
Data leak detected2 min ago
Exfiltration blocked · endpoint 192.168.1.42
STEP 01

Installation

In a few minutes, via port mirroring.

STEP 02

360° monitoring

Network and endpoints, 24/7.

STEP 03

Real-time alert

Notification, e-mail & mobile app.

STEP 04

Managed defence

Our experts neutralise the intrusion.

// BANDWIDTH MONITORING

A data leak always leaves a trace in the traffic

Wybot continuously analyses the bandwidth and volumes exchanged on your network. Any abnormal transfer, a sudden spike, a massive outbound send, an unusual destination, is detected and flagged in real time, before your data leaves the company.

Measurement of inbound and outbound flows, 24/7
Detection of abnormal data spikes and volumes
Instant alert on any form of exfiltration
WYBOT://BANDWIDTH · OUTBOUNDEXFILTRATION
normal traffic▲ spike · 4.2 GB to external IP
// USB DEVICE SECURITY

The threat also fits on a USB stick

A simple USB stick can bypass firewalls and antivirus by physically entering the network. It is one of the most underestimated attack vectors, and one of the most effective for attackers.

RISK 01

Malware & ransomware

An infected stick runs its code the moment it is plugged in and spreads a virus or ransomware across the whole network, like Stuxnet// CAS D'ÉCOLE · STUXNETStuxnet, the virus introduced by USB stickDiscovered in 2010, Stuxnet is one of the most famous pieces of malware in history. This highly sophisticated worm targeted the industrial systems (Siemens controllers) of the centrifuges in Iran's nuclear programme.What makes it notable: the targeted network was isolé d'Internet. Stuxnet spread through simple clés USB : proof that no network, not even an air-gapped one, is safe from a booby-trapped removable device., introduit par USB.

RISK 02

Booby-trapped device (BadUSB// THREAT · BADUSBBadUSB: when the device lies about what it isRevealed in 2014, the BadUSB flaw exploits the firmware of USB devices. An attacker reprograms the chip of a stick (or a cable, a charger, etc.) so that it declares itself as a different device — most often a keyboard.Once plugged in, it types commands on its own: opening a terminal, downloading malware, remote access, all in a few seconds.The danger: no file is copied and the behaviour looks legitimate. Only behavioural monitoring of the endpoint can detect it.)

A reprogrammed device poses as a keyboard and injects commands without the user's knowledge, leaving no detectable file.

RISK 03

Data exfiltration

Mass, discreet copying of sensitive data onto removable media: information leaks, intellectual property theft, GDPR non-compliance.

RISK 04

The “dropped” stick

A stick left in a car park or at reception: out of curiosity, an employee plugs it in and opens the door to the attacker themselves.

PROFESSIONAL KEYS: A CRITICAL ISSUE

Some professional-use USB keys grant access to highly sensitive systems. Diverted or hacked, they expose their holder to a very real risk: identity theft, misappropriation of funds, fraudulent legal acts, access to confidential data.

RÉAL key
Notaries

Electronic signature of authenticated deeds and access to the Réal network: a diversion would allow fraudulent deeds to be signed.

Lawyer key (RPVA)
Lawyers

Access to e-Barreau, electronic signature and court proceedings: a compromise exposes confidential case files.

Certificats CSign / SignExpert
Chartered accountants

Signing of tax and social declarations and online procedures on behalf of clients.

RGS / eIDAS certificates
Commercial court clerks

Authentication and signature on the court registry's professional applications.

Professional certificates
Judicial officers

Access to business platforms and signing of deeds: fraudulent access would compromise official proceedings.

Carte CPS
Healthcare professionals

Authentication on healthcare systems and signing of care sheets: access to sensitive medical data.

Carte CPS / CPE
Pharmacists

Authentication and signature in the pharmacy's business software.

SIV key
Car dealers

Access to the Vehicle Registration System (SIV): a hack opens the way to fraudulent registrations and titlesfrauduleux// FRAUDES AU SIVWhen the SIV key is hijackedThe SIV key gives direct access to the French national vehicle registration database. Once compromised, it becomes a weapon for fraudsters:Fausses cartes grises : certificates issued for stolen or disguised vehicles.Blanchiment de véhicules volés : reassignment of a "clean" identity.Usurpation de plaques (cloned plates): fines and offences redirected to a third party.Responsabilité du professionnel : as the holder of the authorisation, they are legally exposed and accountable to the Prefecture for registration documents issued fraudulently in their name.PROTÉGER MON ACCÈS SIV →.

WHAT WYBOT DOES · PATENTED TECHNOLOGY

Wybot strengthens USB device security

Thanks to its patented technology, Wybot detects when removable media are plugged in and alerts in real time to regain control of the endpoint before an incident occurs.

USB MONITORING · 24/7
// NIS 2 COMPLIANCE

Meet the requirements of the NIS 2 Directive

The European NIS 2// RÉGLEMENTATION · NIS 2What is the NIS 2 directive?NIS 2 (Network and Information Security 2) is a European directive that strengthens the cybersecurity of organisations. It considerably widens the entities concerned — companies, mid-caps, local authorities and public bodies — well beyond critical operators alone. It requires:Cyber risk governance driven by executive managementContinuous supervision of the information systemDetection and notification of incidentsThe ability to account for your security posturePRENDRE RDV → extends cybersecurity obligations to thousands of companies and local authorities. Beyond the technical side, it imposes exigences de gouvernance : connaître son niveau de risque, superviser son système d'information et pouvoir en rendre compte.

The Wybot probe provides concrete tooling for this governance: it gives leaders continuous visibility over cyber risk and the evidence expected by the regulation.

GET A GOVERNANCE REPORT TEMPLATE →
RISK
Continuous analysis and mapping of the network and vulnerabilities.
DETECTION
24/7 monitoring and real-time incident detection.
NOTIF.
Immediate alerts to react within the mandated deadlines.
EVIDENCE
Documented reports for leadership and compliance audits.
// PHISHING

With Wybot, detect phishing

Phishing remains the number-one entry point for cyberattacks. A booby-trapped e-mail, a clicked link, and the attacker gains a foothold on the network. Message filtering never blocks everything, and once the click has happened, only network activity betrays the intrusion.

The Wybot probe detects the malicious activity that follows a phishing attack: connection to a fraudulent domain, contact with a command-and-control server, an attempt at exfiltration or propagation, even when the message slipped through the filters.

Detection of connections to phishing domains & IPs
Spotting of contact with a command-and-control server (C2)
Instant alert before exfiltration or encryption
From the very first click!

Phishing attempts that reach your network are automatically detected by Wybot. Rather than relying solely on awareness campaigns, whose simulations only identify a fraction of the users likely to be caught, investing in Wybot means ensuring continuous protection of the company. Even when an employee clicks a malicious link in a real situation, Wybot steps in to limit the risk and protect your environment.

WYBOT://POST-PHISHINGINTRUSION
14:02E-mail click · external linkobserved
14:02Fraudulent domain · login-office365.helpblocked
14:03C2 server contact · 185.220.101.44alert
14:03IT team notified · endpoint flaggedhandled
// SHADOW IT

The governance solution against Shadow IT & Shadow AI

Cyber threats don't always come from outside.

Shadow IT// RISQUE · SHADOW ITWhy monitor Shadow IT?Shadow IT covers the applications, devices and services used without IT approval. Convenient day to day, they escape security controls and become blind spots that attackers exploit:Porte d'entrée : unauthorised remote-control software can offer a privileged entry point into the information system.Data leak : using a personal cloud service, or one that does not comply with the information system security policy, can compromise the confidentiality of company data.Absence de mises à jour : these tools, outside IT's management scope, are generally neither patched nor supervised, increasing their exposure to vulnerabilities.Non-conformité : their use can lead to gaps against regulatory and standards requirements, notably NIS 2 and ISO 27001.REQUEST A TEST → " refers to all the devices, applications and services used on the network without IT's approval: a personal computer plugged in, software quietly installed, a connected object, an undeclared cloud service. So many entry points that nobody is watching.

Information-security governance begins with the ability to know, control and manage all of the organisation's software and applications. This control is the foundation of any effective security policy. Wybot addresses these challenges.

You can only protect what you can see: Wybot makes the invisible visible.

WYBOT://NETWORK-APPS6 UNAUTHORISED
Microsoft 365 · business useauthorised
!AnyDesk · remote controlshadow IT
!Personal OneDrive · file transfershadow IT
!Tor · anonymised trafficshadow IT
!BitTorrent · P2P sharingshadow IT
!ChatGPT · data sent onlineshadow AI
!DeepSeek · AI hosted outside the EUshadow AI
!Browser AI extension · not vettedshadow AI
// SOVEREIGNTY & HOSTING

Sovereign hosting, controlled end to end

01

French & European jurisdiction

Infrastructure operated exclusively under French and European jurisdiction.

02

No extraterritorial dependency

No dependency on cloud services operated by providers subject to extraterritorial legislation.

03

Outside the CLOUD Act

Sovereign hosting, operated in France, with no infrastructure services subject to the CLOUD Act// LEGISLATION · CLOUD ACTWhat is the CLOUD Act?The CLOUD Act (Clarifying Lawful Overseas Use of Data Act) is a 2018 US law that lets US authorities compel a provider subject to US law to hand over the data it hosts, anywhere in the world, including in Europe. Relying on such a provider therefore exposes European data to extraterritorial legislation..

04

Chain controlled end to end

A hosting chain controlled end to end, operated by an independent company governed exclusively by French and European law.

// DEPLOYMENT & INTEGRATION

A probe that fits your infrastructure

APPLIANCE

Physical appliance

A ready-to-use appliance, connected via port mirroring, up to 10,000 devices.

VIRTUALISED

Virtual machine (VM)

Deploy the probe as a VM in your existing environment, with no extra hardware and no device limit.

API

Open integrations

An API lets you connect Wybot to your other systems (SIEM, ticketing, monitoring) to automate exchanges.

Wybot detects attacker behaviour that your EDR and SIEM cannot see: lateral movements and attack signatures across every device on the network.

+
01

SMEs & mid-caps

Enterprise-grade security, with no cyber expertise required.

+
02

Industry

Protect OT networks and critical industrial systems.

+
03

Local & central government

Sovereignty for public services and data.

+
04

Regulated professions

Protect professional confidentiality.

// RESELLER PROGRAMME

Become a Wybot reseller and stand out

Offer your clients a French cybersecurity solution that is simple to deploy and highly value-adding. A product that demonstrates itself in 20 minutes and generates recurring revenue.

01

A differentiating product

A French probe: a strong sovereignty argument against conventional EDR solutions.

02

Recurring revenue

A licence-and-subscription model: predictable, recurring revenue on every equipped client.

03

A demo that converts

100% of installed probes trigger an alert within 20 minutes: the product sells itself.

04

Simple deployment

Installed in a few minutes with no expertise required and little support to provide.

05

All your clients

Physical appliance or virtualised version: address small businesses and large accounts alike.

06

Support

Training, pre-sales support and technical assistance. The SOC service can also be resold as an add-on.

// ONE-OFF AUDIT

Offer turnkey cybersecurity audits

The probe is not sold only on subscription: deploy it for the length of a mission to run a full diagnostic of your client's network and leave with a white-label security report, ready to present.

A billable audit service, on top of the licence sale
Full network diagnostic in just a few days
No heavy investment: the probe is enough, no expert needed
The audit creates the need and turns into a recurring subscription
WHITE-LABEL REPORT

A complete report published under your company's name. You deliver it, you showcase your expertise.

Network mapping
Malicious IPs
Malicious domain names
Network applications
Network anomalies
Bandwidth
Vulnerability inventory
Countries
Endpoint health
VIEW A SAMPLE REPORT →

Join our partner network

We are building our partner network — let's discuss your territory and terms.

BECOME A PARTNER →

100% of installed probes trigger an alert within 20 minutes of going live

Discover your attack surface during a test

REQUEST A TEST →
// DASHBOARD ACCESS

The dashboard is best seen in a demo

To see the Wybot dashboard in real conditions, our experts will walk you through it in a personalised demonstration. Book your slot — no commitment.