Our Annual Cybersecurity Assessment is out: 55% of security teams were told to keep a breach quiet. — See what else 1,200 pros revealed >>

92.8%

Attack reduction achieved by blocking tools unused by the management team

95.1%

Attack reduction achieved by allowing tools such as PowerShell to only take legitimate actions

99%

Of companies don’t use Bitsadmin, but have it enabled.

133

LOLBins in a fresh Windows 11 installation.

Stop Stealthy Ransomware Attacks

 

Ransomware groups abuse built-in tools like PowerShell, WMI, and PsExec to move laterally and deploy payloads before teams can investigate alerts and respond. PHASR stops this earlier: it restricts each tool to only the actions each user legitimately performs, removing the attack path before it can be used, regardless of which EDR or XDR your organization runs. In Bitdefender early adopter testing in customer production environments (2024), PHASR restricted 95.1% of attack surface abuse.

Reduce Risk Rapidly, Without Friction

Static hardening tools apply the same rules to every endpoint. PHASR generates a unique policy per user based on their actual behavior, the tools they use, and the attack techniques active in their industry. Policies update automatically as user behavior changes, without requiring IT to manage exceptions manually. With PHASR, organizations have reduced attack surface by 80% without impacting employee productivity.

Bolster Security Efficiency

 

Most EDR and XDR alerts involving trusted tools are hard to act on because the tool itself is legitimate. PHASR removes the ambiguity by restricting each tool to only what each user actually needs, so the alert never fires. In Bitdefender early adopter testing in customer production environments (2024), PHASR reduced investigation and response workloads by up to 50%, regardless of which EDR or XDR your organization runs.

Compromises Should Not Lead to Successful Ransomware and Data Breaches

PHASR’s dynamic attack surface reduction hardens your environment and stops attacks before they escalate.

Bitdefender PHASR Tailored Hardening

Tailored Hardening

PHASR uses AI algorithms to build risk profiles for each user‑endpoint combination, identifying unnecessary tools and tailoring hardening dynamically.

 

GravityZone Platform -  Attack surface exposure insights reports

Dynamic Attack Surface Reduction

PHASR continuously learns, adapting autonomously to changing behaviors and threat vectors, minimizing IT overhead.

GravityZone Platform - PHASER rules dashboard

Precise Control

PHASR allows granular restriction of risky behaviors within allowed tools—e.g., allowing PowerShell but blocking encrypted commands.

GravityZone Platform -  PHASR - LOLBins analysis dashboard

Application Risk Metrics

PHASR displays attack surface and risk reduction metrics associated with each recommendation, enabling better security posture tracking.

GravityZone Platform - PHASR Autopilot Protection setup view

Autopilot Protection

PHASR dynamically applies hardening recommendations as behaviors and threats evolve. Admins can also choose Direct Control mode.

GravityZone Platform - PHASR - Endpoint issues view

Simplified Deployment and Management

Seamlessly integrated within the GravityZone Platform. Existing customers can activate and start identifying risks in minutes.

simplify threat
"Bitdefender has consistently performed well in independent tests, including MITRE Engenuity and has introduced innovative features such as Deep Process Inspector and Advanced Reasoning. Most recently, in 2024, Bitdefender Proactive Hardening and Attack Surface Reduction (PHASR), a groundbreaking technology that transforms how defense-in-depth-security is applied and managed across businesses."

 

IDC, IDC ProductScape: Worldwide Small and Medium-Sized Business Endpoint Protection Market [2025].

dots
GravityZone Unified Cybersecurity Platform: Security - Risk - Compliance

Augment your GravityZone platform and any 3rd party EDR

Faster, AI-enabled attacks that hide behind trusted activity pose one of the most significant challenges to conventional security. Given the expanded attack surfaces that make compromises more likely, relying on detection and response to uncover and stop attacks is not sustainable, especially for lean IT and security teams.

 

Bitdefender GravityZone PHASR is a groundbreaking innovation that augments Bitdefender GravityZone and any 3rd party EDR/XDR solution. As part of the GravityZone unified security, risk, and compliance platform, PHASR helps lean teams proactively stop ransomware and data breaches, while eliminating complexity and improving security efficiency.

 

Bitdefender GravityZone PHASR is available as a standalone license, compatible with any 3rd party EDR/XDR tool and as an additional license to the Bitdefender GravityZone Enterprise package, MDR offerings, and the GravityZone Cloud MSP Security Solutions.

Security That’s Consistently Recognized Across Independent Evaluations

Top Protection. Lowest TCO AV-Comparatives 2025 EPR Test

Bitdefender achieved top breach prevention and lowest TCO and was the only vendor to block 100% of attacks during the first stage.

AV Comparatives

Best Protection. Best Performance for Business Users

Bitdefender GravityZone Endpoint Security received the AV-TEST Award 2023 for Best Protection and Best Performance in the business users category

Bitdefender Awards for Best Protection 2023

High Threat Visibility, Minimal Noise

Bitdefender achieved 100% analytical coverage for both Linux and macOS, with zero False Positives (FPs) in both cases.

Mitre

A Customers’ Choice in 2026 Gartner® Peer Insights™
Voice of the Customer for EPPs

 

 

 

Gartner Peer Insights

A Visionary in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection

gartner

Named a Strong Performer
in Forrester Wave 2024
EDR Platforms report

Forrester Wave Strong Performer 2024
GravityZone PHASR resources
Datasheet

GravityZone Security PHASR Datasheet

Read More
Read the Report Technical Explainer

Living off the Land Attacks

Read the Report
Read More TechZone Article

Proactive Hardening and Attack Surface Reduction (PHASR)

Read More
Watch now On-Demand Webinar

Shrinking the Attack Surface and Stopping Misuse of Legitimate Tools

Watch now

What are Living off the Land techniques and how do they bypass detection?

System tools, such as PowerShell or Bitsadmin on Windows, to achieve goals such as lateral movement, defense evasion, privilege escalation, data exfiltration. Because these tools are legitimate, EDR tools often cannot distinguish malicious use from normal use quickly enough. GravityZone PHASR restricts each tool to only the legitimate actions each user performs, so attackers cannot use those tools for malicious purposes even if they gain access to an endpoint.

How does GravityZone PHASR identify unnecessary, risky tools?

PHASR uses threat intelligence and ML algorithms to map user‑endpoint behavior, identifying risky, unused tools for restriction without impacting productivity.

What makes GravityZone PHASR unique?

It dynamically tailors security per user, restricting risky actions instead of blocking entire applications, maintaining usability and manageability.

How can I Get PHASR?

PHASR is available as an add-on license to Bitdefender GravityZone Business Security EnterpriseMDR offerings and the GravityZone Cloud MSP Security Solutions , and as a standalone product, compatible with 3rd party EDR/XDR tools.

How is GravityZone PHASR different from static application control or hardening tools?

Static hardening tools apply the same rules to every endpoint.  GravityZone PHASR generates a unique policy per user based on their actual behavior. If a user's behavior changes, PHASR updates their policy automatically. If a tool is used by some users but not others, it restricts it only for those who do not need it. This eliminates the manual exception management that makes static tools unsustainable for lean IT teams.

Does PHASR work with my existing EDR tool?

Yes. PHASR works alongside GravityZone Endpoint Detection and Response (EDR) and GravityZone Extended Detection and Response (XDR). It also supports third-party EDR tools from other vendors. PHASR reduces the attack surface that attackers exploit to evade EDR detection, making your existing EDR investment more effective. 

Does GravityZone PHASR impact user productivity?

No. GravityZone PHASR applies hardening based on each user's observed behavior, so restrictions only apply to tools and actions that user does not legitimately use. Users do not experience PHASR as a change to their working environment. IT teams do not need to manage exceptions manually because it updates policies automatically as user behavior changes. In early adopter testing, organizations reported no user productivity impact after GravityZone PHASR deployment.

Proven. Unsurpassed Cybersecurity Effectiveness.

We’re here to help you choose the solution or service that’s right for your business. See all products