How Rased works: from the device to the alert and the fix

Linking a device takes one command and an installer that explains each step as it goes. Here is everything that is watched, how an alert reaches you, and the plain limits of what we do.

How

Three steps from device to alert

  1. Add the device and copy one command

    In the portal you add and name the device and get a ready-to-copy install command for Windows or Linux. The command works once and is valid for 60 minutes.

  2. Run it as administrator

    The installer scans the device: application names, open ports and hardware, with no files and no passwords. It sends the result to Rased over an encrypted connection (HTTPS), receives keys for this device alone, and installs the protection (SOC) and monitoring (NOC) agents.

  3. The device shows as connected and watching begins

    Within minutes the device shows as “connected” and a Telegram message arrives. The device then refreshes its inventory of applications, ports and hardware automatically every 15 minutes.

The Rased agent runs on 64-bit Windows and on Debian and Ubuntu Linux. Network equipment, such as routers and firewalls, runs no agent: its logs are analysed when you upload them.

1 · Start

   Network and security monitoring
   by DNR ENGINEERING WORKS

  ==================================================================
  ========================================

Welcome to Rased, and thank you for choosing us.

This installer links this device to your Rased account so that its
availability and security can be watched and shown in your portal.

Your files, documents and passwords are never collected, and everything
this device sends travels over an encrypted connection.

The steps run in order and take a few minutes. Please keep this window
open until the completion message appears.

  ==================================================================
  ========================================

- Preview: sample data only. Nothing was installed or sent.

2 · Six steps

[Rased] Step 1 of 6: Scanning your device: the applications running on it, its open ports and hardware details. No files or passwords are collected.
   - Applications found: iis mssql
   - Open ports: 80 443 1433 3389
   - Web applications: aspnet
   - Device: Example Vendor Model A (desktop)

[Rased] Step 2 of 6: Sending the scan result to Rased servers and receiving your device's own linking keys, over an encrypted channel (HTTPS).
   [Done] The scan data was received on Rased servers, encrypted and securely, and linking keys were issued for this device alone.
   - Your device name in Rased: acme-pc01

[Rased] Step 3 of 6: Installing the protection agent (SOC). It may take a minute or two.
   - The protection agent will also watch the IIS logs and the website folder.
   [Done] The protection agent is installed.

[Rased] Step 4 of 6: Installing the monitoring agent (NOC).
   [Done] The monitoring agent is installed.

[Rased] Step 5 of 6: Turning on the automatic hardware and software update every 15 minutes.
   [Done] The protection agent inventory now runs every 15 minutes.
   [Done] Hardware, software and ports refresh automatically every 15 minutes.

[Rased] Step 6 of 6: Checking that the agents are running.
   [Done] Protection agent (SOC): running
   [Done] Monitoring agent (NOC): running

3 · Result

   Network and security monitoring
   by DNR ENGINEERING WORKS

  ==================================================================
  ========================================

Results

[Done] Your device name in Rased: acme-pc01

[Done] Protection agent (SOC): running

[Done] Monitoring agent (NOC): running

[Done] Hardware, software and ports refresh automatically every 15 minutes.

- Preview: sample data only. Nothing was installed or sent.

Your device is now linked to Rased.

Your device data was received on our servers, encrypted and securely.

It appears in the Rased portal within minutes and refreshes every 15 minutes.

We wish you a service that pleases you. - The Rased team

  ==================================================================
  ========================================

4 · If it fails

   Network and security monitoring
   by DNR ENGINEERING WORKS

  ==================================================================
  ========================================

Results

[Warning] The token was already used or has expired (valid for one hour). Generate a new command from the Rased portal.

The linking did not finish. Send what appeared in this window to the support team.

  ==================================================================
  ========================================

Illustrative exampleThe Windows installer screen as it appears in a PowerShell window, in English only so it renders correctly in every console. The device names are invented and nothing was installed. The command line itself is never shown here. When something fails, the screen turns yellow and asks you to send what appeared in the window to support.

What is watched, and how alerts reach you

What Rased watches

  • Devices: status, metrics, services, hardware and connection.
  • The applications and open ports on each device.
  • The accounts on the device and their applications, with an alert when a new administrator or a new remote-control tool appears.
  • File deletions in folders you choose (file names only, never their contents). The file guard reports; it does not prevent deletion.
  • The attacks on your devices and their sources.
  • The known vulnerabilities in the software on your devices.

How an alert reaches you

  1. Your devicesProtection and monitoring agents
  2. Rased analysisMerges related signals
  3. One cardPer device and type of issue
  4. YouOn Telegram and in the portal
  • Critical failures reach you at once; medium ones after a short wait if they persist, so a momentary blip does not reach you.
  • A morning summary at 8 am in your country's time, which you can move or switch off, and which is not sent when nothing happened.
  • Card buttons: details, acknowledge, mute for 24 hours, how to fix it.

Security and access: who sees what

Sensitive actions pass an approval gate, and technical support only comes in with your permission. The amber dot in the figure is a sensitive request waiting for your approval.

123
  1. Roles for every organisationEach organisation has its own users and roles: manager, editor (read and write) and viewer (read-only). The assistant inside the portal answers about the asker's own organisation only.
  2. Approval for sensitive actionsSuch as changing a password or switching on the file guard: a 6-digit verification code sent to your Telegram, valid for 10 minutes and for five attempts only. You can also protect the chat with a 4 to 6 digit PIN entered with buttons so it never appears as text, and authorise a delegate.
  3. Technical support only with your permissionTechnical support sees your data only with your approval, read-only and for a limited time (30 minutes by default). You receive a report of everything that was read and can end the session at any moment.

What we gather from your device

Application names, open ports and hardware details, without files or passwords. The file guard watches file names and paths only, and data travels to Rased servers over an encrypted connection (HTTPS).

Your logs: masked before analysis

Passwords and keys are masked before sending, the raw log is not stored, and the report is deleted automatically after 7 days.

Log analysis

Upload a log from a device or a network appliance. Passwords and keys are masked, the right engine reads it, and you get a report ordered by what matters most: causes, fixes and commands you can copy. Every finding carries its source and its licence, and says when it might be a false alarm wherever that information is available; each of the 21 rules the platform wrote itself carries a false-alarm note. The report ends with a section on the integrity of the log itself.

  1. Upload the logFor a product you pick from the list
  2. Masking secretsPasswords and keys
  3. Four enginesNetwork devices, Linux, Windows and general
  4. Ranked reportMost serious first, printable
88products and platforms built in, in 16 categoriesAs of 3 October 2026
21rules written by the platform itself, each with its source and a false-alarm noteAs of 3 October 2026
500+open-source detection rules, refreshed daily with an integrity check on every fileAs of 2 October 2026
The honest limits
  • A file of up to about 1.3 MB is accepted.
  • 6 analyses an hour per user, 20 a day per organisation and 3 at the same time.
  • The report is deleted automatically after 7 days, so download it if you want to keep it.
  • A finding may be a false alarm. We say when that can happen wherever the information is available, and it is always given for the 21 rules the platform wrote itself.

When you use the log analyser, a cleaned summary, after passwords and keys are masked, is sent to an AI analysis service run by an outside provider. We do not keep the raw log.

Integrations: Telegram and reports

The Rased bot on Telegram

A permanent menu so you never need to type, cards that update in place, and linking in one tap or by scanning a QR code. It works in Arabic and English and follows your language.

Ready-made reports

Four kinds of device report (full, security, hardware and availability) and one for the organisation. Open them in the browser, then print or save as PDF.

A guide that updates itself

A usage guide built automatically from Rased's current features, so every new feature appears in it as soon as it is added.

Ready to link your first device?

Request to join: the Rased team reviews your request and the platform manager approves it.