Detection and monitoring EU-developed
Exein Runtime
Embedded runtime security platform with on-device agents that monitor and block malicious behavior and send fleet telemetry for investigation.
By Exein S.p.A. · Italy
The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.
At a glance
Recorded facts- Response workflow
- Detection and monitoring
- Developer or maintainer
- Exein S.p.A.
- Recorded country
- Italy
- Product model
- Commercial
- Deployment
- SaaS
- Software license
- Proprietary
- Upstream status
- Active
- Evidence class
- EU-developed
What the sources establish
Origin noteExein's EULA names Rome-based Exein S.p.A. as developer and licensor of Exein Runtime; the company also has non-Italian offices.
Reported capabilities
- Kernel-level agents monitor and block suspicious behavior on embedded systems.
- Fleet console traces incidents and produces runtime evidence.
- Customer devices exchange information with Exein resources under the SaaS model in its EULA.
Scope and limits
Runtime runs an agent inside customer devices while the current EULA describes connected SaaS resources; offline behavior, tenancy and hosting region need contract-level verification. This is industrial/embedded detection rather than a general SOC EDR.
Inspect the research evidence 4 source observations
identity / capabilities
Product page identifies Runtime, kernel-native protection, fleet incident tracing, telemetry, and forensic reconstruction.
Read sourceorigin / country / license / deployment
Current EULA identifies Exein S.p.A. in Rome, expressly names Exein Runtime as a solution developed by Exein, calls operation SaaS with device-resource exchange, reserves proprietary IP, and prohibits copying, modification and source derivation.
Read sourcecountry
Company page identifies Rome headquarters and offices in Germany, Taiwan and the US, limiting any exclusive-Italian inference.
Read sourcemaintenance
23 September 2026 product article discusses Exein Runtime's current agent, rule rollout and evidence use; evidence of active product work, not an independent efficacy test.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.
From Sigma rule to a tested detection