The product creates threat events when it identifies malware or potentially unwanted programs on devices. The solution analyzes process behaviors in real-time and can identify potential threats, including previously unknown ones. It layers behavioral detections over static file analysis and checksum-based detections. The system leverages Apple's Endpoint Security framework to evaluate each process before execution, with the Kandji Agent processing events in real-time entirely on the device, ensuring protection even when offline. When threats are detected, the product can terminate malicious processes and quarantine files by moving them to a location from which they cannot run. The product offers Protect Mode which terminates malicious processes and quarantines files, and Detect Mode which provides observability without enforcement. File allow/block controls operate by hash, path, or publisher, with blocked items triggering detection and quarantine. Severity scoring includes five levels: Critical, High, Medium, Low, and Informational. Event streaming to Amazon S3 enables SIEM ingestion and analysis. The product runs on the Kandji Agent and is managed through Kandji's web application alongside device management.