SOC 2 Readiness
24/7 Security Monitoring
Canadian-Based SOC
GuardsArm Platform · Detect

EDR — Endpoint Detection & Response

Deep endpoint visibility and on-box response, from a lightweight native agent.

The GuardsArm agent supplies the high-fidelity signal the detection engine runs on, and executes response actions locally — including when the endpoint is off the corporate network.

  • Kernel-level telemetry
  • Self-healing tamper protection
  • On-box response
A lightweight endpoint agent collecting process, file and network telemetry from a workstation and receiving a containment action in return

What is at stake

Detecting an intrusion on a host you cannot reach is a notification, not a defence — and the gap between the two is measured in how long the attacker keeps working.

Containment that does not wait for a change window

Isolating a host, killing a process or quarantining a file happens over the same channel the telemetry arrived on. No one has to find the machine, and nothing waits on a firewall request.

The control survives contact with the attacker

Disabling endpoint security is an early step in a great many intrusions. Self-healing tamper protection means the attempt both fails and raises a high-value alert.

Endpoint evidence is there when you need to reconstruct

Process ancestry, file changes and configuration drift are what an incident report is built from, and what an insurer or regulator asks to see afterwards.

Who carries this

Incident response owns it. In practice it is also what the business continuity conversation rests on, because containment speed determines blast radius.

The problem

Network telemetry stops exactly where the interesting part starts

Perimeter and network monitoring answer one question well: what crossed a boundary. They answer almost nothing about what happened afterwards. Once an attacker is executing on a host, their activity is process creation, registry writes, scheduled tasks and file modification — none of which is visible from a span port, and most of which is indistinguishable from administration unless you can see the sequence and the parentage.

The second half of the problem is response. Detecting an intrusion on a host you cannot reach is an alert, not a defence. Containment that depends on someone finding the machine, or on a firewall change that takes a change window, is slower than the thing it is containing.

The GuardsArm agent is both sensor and actuator for this reason. It collects at kernel-grade fidelity and it executes response in place, over the same authenticated channel.

An agent an attacker can switch off is a log source, not a control.

Capabilities

What the endpoint agent does

Native endpoint telemetry

Process, network and persistence events collected continuously, forming the backbone of behavioural detection.

File integrity monitoring

Real-time change detection on sensitive paths, with the hash of changed files checked against threat intelligence and malware databases.

Security configuration assessment

Policy and benchmark checks run on the endpoint, so configuration drift surfaces as a finding rather than waiting for an audit.

System inventory

Installed packages, listening ports, running processes and hardware and OS facts — the asset picture vulnerability management and incident scoping both depend on.

Kernel-grade telemetry

Kernel-level visibility on Windows and Linux. These are the signals that make process ancestry and injection detection possible.

Tamper protection that self-heals

Dual guardian processes detect and reverse attempts to disable the agent, with a fail-open clean uninstall so legitimate removal still works.

On-agent YARA scanning

YARA runs on the endpoint and feeds the Malware Center, where quarantine is controlled from the console.

How it fits the platform

The agent is both sensor and actuator. Telemetry flows up for detection; response actions flow back down, which is what closes the loop from a correlated incident to an isolated host.

How it works

The agent lifecycle, from enrolment to response

Six stages. All of them terminate inside your perimeter — the agent talks to your the platform and nothing else.

  1. Enrolment

    The agent registers through a public enrolment endpoint using an expiring token. No static secret is baked into an installer, which is what makes a leaked image a non-event rather than an incident.

  2. Group assignment

    The endpoint joins a group, and the group carries its configuration. Changing what a hundred servers collect is one change to one group rather than a hundred edits or a configuration-management run.

  3. Collection

    Process, network and persistence events stream up alongside FIM changes, SCA results and inventory. On Windows this draws on kernel-level Windows telemetry; on Linux, kernel-level Linux telemetry.

  4. Local scanning

    YARA runs on the agent, so a file can be matched where it sits rather than being shipped somewhere to be examined. Hits feed the Malware Center with quarantine controls attached.

  5. Response

    Actions flow back down the same channel: isolate the host, kill a process, quarantine a file, block an address. Windows containment uses WFP-based network isolation, and response actions are proven to survive a reboot.

  6. Self-update

    Agents pull signed content updates without a full reinstall, distributed through signed APT and YUM repositories and a hosted Windows installer. Uninstall is clean and fail-open.

Telemetry

What the agent actually collects

Kernel-grade sources on both platforms, plus the cross-platform modules that run everywhere.

Windows

  • kernel-level telemetry
  • Event Log (eventchannel)
  • ETW
  • Registry
  • WFP network isolation

Linux

  • kernel audit
  • kernel telemetry
  • systemd journal
  • Process & network events

Cross-platform modules

  • File integrity monitoring
  • Security configuration assessment
  • System inventory
  • YARA scanning
  • Active response

Continuous system inventory

Software

  • Installed packages
  • Versions
  • Patch state

Network

  • Listening ports
  • Open connections
  • Interfaces

Runtime

  • Running processes
  • Users
  • Groups

Hardware & OS

  • CPU and memory facts
  • OS build
  • Architecture

The modules, explained

Four acronyms worth unpacking

Endpoint security is unusually dense with jargon. These are the four that decide whether the agent is useful to you.

FIM — File Integrity Monitoring

Watches sensitive paths for change in real time and records who changed what, when. It is both a detection source and, for PCI DSS and HIPAA, a control an auditor will ask you to evidence directly.

SCA — Security Configuration Assessment

Checks the host against policy and benchmark baselines and reports where it drifts. This is the difference between knowing a server was built correctly and knowing it still is.

Continuous asset inventory

Continuously maintained software, hardware, port and process inventory. The vulnerability scanner reads it directly, which is why vulnerability findings and detections resolve to the same asset.

Tamper protection

Dual self-healing guardians detect and reverse attempts to disable the agent. Disabling endpoint security is an early step in a great many intrusions, so the attempt itself is a high-value signal — and it is raised as one.

Platforms

Where the agent runs

Stated plainly, including what is not generally available yet.

  • Linux — Debian / Ubuntu (.deb)ShippedFull EDR, file integrity monitoring, configuration assessment, inventory and response.
  • Linux — RHEL / Rocky (.rpm)ShippedFull parity with the Debian package.
  • Windows — signed .msiShippedCode-signed, with kernel-level telemetry, on-agent tamper protection and network isolation for host containment.
  • ARM64 — Linux .deb and aarch64 .rpmShippedFor ARM servers and edge deployments.
  • macOS (.pkg)RoadmapCode is ready; pending a signed and notarized build. Not yet generally available.

Background

Understand the concept first

Plain explainers on the underlying ideas, written for someone evaluating rather than buying.

Questions

Common questions

What happens if someone tries to kill the agent?

Dual guardian processes detect and reverse attempts to disable it, and the design is fail-open for a clean uninstall so legitimate removal still works.

Which platforms does the agent support?

Linux as .deb and .rpm, Windows as a signed .msi, and ARM64 for both Linux package formats. macOS is on the roadmap — the code is ready, pending a signed and notarized build — and is not yet generally available.

Do response actions survive a reboot?

Yes. Windows and Linux response actions are proven to persist across endpoint restarts, so containment is not undone by a user power-cycling the machine.

What telemetry does it actually collect?

Process, network and persistence events, file integrity changes on sensitive paths, configuration assessment results, and system inventory. On Windows that includes kernel-level Windows telemetry; on Linux, kernel-level Linux telemetry.

See EDR running on your own infrastructure

We will walk through the console, the deployment model and what it takes to stand it up in your environment.