
Stealth-Driven Endpoint Defense That Conceals Data and Stops Ransomware at Runtime
Arms Cyber builds endpoint security software aimed at organizations that treat ransomware and uncontrolled AI tool use as availability problems rather than alerting problems. The company was founded in 2020 by twin brothers Brad and Tim Potteiger together with entrepreneur Michael Bryant, growing out of Brad's work on offensive cyber techniques for the U.S. Intelligence Community. Its stated customers sit in critical infrastructure, finance, healthcare, and technology, where encrypted data or disabled backups translate directly into operational downtime.
The product is Raven, a single lightweight sensor covering Windows, Linux, and macOS workstations, servers, and virtual machines, with three modules riding on one agent. AI Ransomware Protection applies automated moving target defense, morphing runtime memory and using system polymorphism so exploit paths cannot be reused, alongside stealth directories, decoy files, and entropy-based monitoring of mass-encryption behavior. AI Data Resilience conceals restoration points and blocks attempts to unhook backups, while AI Policy Enforcement governs which AI models and credential stores endpoint processes may reach. Telemetry lands in a native console or an existing SIEM.
Positioning leans on preemption rather than post-breach response: the vendor frames its approach as conceal, adapt, restore, and markets Raven as an overlay that runs beside CrowdStrike, Microsoft Defender, or SentinelOne instead of replacing them. Published claims include roughly one-minute installation, under one percent runtime overhead, and recovery measured in seconds. That places the company in the small automated moving target defense niche, where the competitive argument is that memory randomization and deception close gaps signature- and behavior-detection stacks leave open.



