Containment that does not wait for a change window
Isolating a host, killing a process or quarantining a file happens over the same channel the telemetry arrived on. No one has to find the machine, and nothing waits on a firewall request.
Deep endpoint visibility and on-box response, from a lightweight native agent.
The GuardsArm agent supplies the high-fidelity signal the detection engine runs on, and executes response actions locally — including when the endpoint is off the corporate network.

What is at stake
Detecting an intrusion on a host you cannot reach is a notification, not a defence — and the gap between the two is measured in how long the attacker keeps working.
Isolating a host, killing a process or quarantining a file happens over the same channel the telemetry arrived on. No one has to find the machine, and nothing waits on a firewall request.
Disabling endpoint security is an early step in a great many intrusions. Self-healing tamper protection means the attempt both fails and raises a high-value alert.
Process ancestry, file changes and configuration drift are what an incident report is built from, and what an insurer or regulator asks to see afterwards.
Who carries this
Incident response owns it. In practice it is also what the business continuity conversation rests on, because containment speed determines blast radius.
The problem
Perimeter and network monitoring answer one question well: what crossed a boundary. They answer almost nothing about what happened afterwards. Once an attacker is executing on a host, their activity is process creation, registry writes, scheduled tasks and file modification — none of which is visible from a span port, and most of which is indistinguishable from administration unless you can see the sequence and the parentage.
The second half of the problem is response. Detecting an intrusion on a host you cannot reach is an alert, not a defence. Containment that depends on someone finding the machine, or on a firewall change that takes a change window, is slower than the thing it is containing.
The GuardsArm agent is both sensor and actuator for this reason. It collects at kernel-grade fidelity and it executes response in place, over the same authenticated channel.
An agent an attacker can switch off is a log source, not a control.
Capabilities
Process, network and persistence events collected continuously, forming the backbone of behavioural detection.
Real-time change detection on sensitive paths, with the hash of changed files checked against threat intelligence and malware databases.
Policy and benchmark checks run on the endpoint, so configuration drift surfaces as a finding rather than waiting for an audit.
Installed packages, listening ports, running processes and hardware and OS facts — the asset picture vulnerability management and incident scoping both depend on.
Kernel-level visibility on Windows and Linux. These are the signals that make process ancestry and injection detection possible.
Dual guardian processes detect and reverse attempts to disable the agent, with a fail-open clean uninstall so legitimate removal still works.
YARA runs on the endpoint and feeds the Malware Center, where quarantine is controlled from the console.
How it fits the platform
The agent is both sensor and actuator. Telemetry flows up for detection; response actions flow back down, which is what closes the loop from a correlated incident to an isolated host.
How it works
Six stages. All of them terminate inside your perimeter — the agent talks to your the platform and nothing else.
The agent registers through a public enrolment endpoint using an expiring token. No static secret is baked into an installer, which is what makes a leaked image a non-event rather than an incident.
The endpoint joins a group, and the group carries its configuration. Changing what a hundred servers collect is one change to one group rather than a hundred edits or a configuration-management run.
Process, network and persistence events stream up alongside FIM changes, SCA results and inventory. On Windows this draws on kernel-level Windows telemetry; on Linux, kernel-level Linux telemetry.
YARA runs on the agent, so a file can be matched where it sits rather than being shipped somewhere to be examined. Hits feed the Malware Center with quarantine controls attached.
Actions flow back down the same channel: isolate the host, kill a process, quarantine a file, block an address. Windows containment uses WFP-based network isolation, and response actions are proven to survive a reboot.
Agents pull signed content updates without a full reinstall, distributed through signed APT and YUM repositories and a hosted Windows installer. Uninstall is clean and fail-open.
Telemetry
Kernel-grade sources on both platforms, plus the cross-platform modules that run everywhere.
The modules, explained
Endpoint security is unusually dense with jargon. These are the four that decide whether the agent is useful to you.
Watches sensitive paths for change in real time and records who changed what, when. It is both a detection source and, for PCI DSS and HIPAA, a control an auditor will ask you to evidence directly.
Checks the host against policy and benchmark baselines and reports where it drifts. This is the difference between knowing a server was built correctly and knowing it still is.
Continuously maintained software, hardware, port and process inventory. The vulnerability scanner reads it directly, which is why vulnerability findings and detections resolve to the same asset.
Dual self-healing guardians detect and reverse attempts to disable the agent. Disabling endpoint security is an early step in a great many intrusions, so the attempt itself is a high-value signal — and it is raised as one.
Platforms
Stated plainly, including what is not generally available yet.
Background
Plain explainers on the underlying ideas, written for someone evaluating rather than buying.
Questions
Dual guardian processes detect and reverse attempts to disable it, and the design is fail-open for a clean uninstall so legitimate removal still works.
Linux as .deb and .rpm, Windows as a signed .msi, and ARM64 for both Linux package formats. macOS is on the roadmap — the code is ready, pending a signed and notarized build — and is not yet generally available.
Yes. Windows and Linux response actions are proven to persist across endpoint restarts, so containment is not undone by a user power-cycling the machine.
Process, network and persistence events, file integrity changes on sensitive paths, configuration assessment results, and system inventory. On Windows that includes kernel-level Windows telemetry; on Linux, kernel-level Linux telemetry.
Works with
Every module runs in the same self-hosted stack and shares the same telemetry, severity model and response engine.
We will walk through the console, the deployment model and what it takes to stand it up in your environment.