Find AI agents, MCP infrastructure, keys, models and data paths across macOS and Linux, with Windows and Windows Server in beta, plus live AWS cloud discovery — with Azure and Google Cloud connectors on connect. Prioritize real exposure, govern approved-AI policy and stream governed evidence to your SOC. The discovery sensor is observe-only.
Discover shadow AI, place it in context, respond by real risk, test it before it ships, watch it at runtime, and govern it for conformity — then feed what you learn straight back into discovery.
The workload sensor supplies process, tool-scope and metadata-service context. A read-only AWS connector adds effective identity, policy and storage posture today, with Azure and Google Cloud connectors on the way. Araghatta correlates both into an evidence-backed attack path—without harvesting credentials or exploiting the environment.
01 · RUNTIMERunning AI agentProcess, service, container, owner, unattended state and available tools.02 · HOSTReachable preconditionsMetadata-service mode, network reachability and workload boundary.03 · IDENTITYEffective permissionsInstance role, managed identity or service account and privilege edges.04 · DATAReachable servicesAmazon S3 today (Azure Storage and Google Cloud Storage on connect) and other sensitive resources.05 · ACTIONPrioritised remediationBreak the shortest path, route evidence and verify the fix.Built and proven on real client engagements — delivered through two partners across multiple clients.
Client names are held under NDA. We'll walk you through the real engagements and provide references in the meeting.
Sources: 1 IBM, Cost of a Data Breach 2025 (63% of breached orgs lacked AI-governance policies). 2 Cyberhaven, 2025 AI Adoption & Risk Report. 3 Reco, State of Shadow AI. Methodology and further sources in our research.
Network traffic is only one of them. One lightweight sensor sweeps every endpoint — and mobile, and cloud servers — because the coding agent installed from a website, the API key in a shell profile, or the MCP server wired into an IDE never shows up in a firewall log.
Outbound calls to LLM APIs and agent web apps — matched by hostname (DNS/SNI), not shared CDN IPs.
real-time · eBPF (Linux)Every MCP server with its package, version, source repo — and the exact fs / shell / network tool scope it was granted.
provenance · privilegeProvider keys in env, .env files, and shell profiles — the strongest proof of use. Fingerprinted, never exfiltrated.
highest signalDesktop LLM runtimes, coding-agent CLIs, and import openai-style SDK use in running code.
on-deviceCopilot, Cursor, Cody, Continue, Amazon Q — installed as IDE plugins, with the signed-in account and version.
by marketplace IDDownloaded SKILL.md and agent skills — executable instructions, tied to their unverified source repo.
provenanceRepositories where AI wrote the code — Cursor / Copilot / Claude footprints reaching production without review.
by projectOrchestrators running with AI — LangChain, CrewAI, AutoGen, MCP loops — flagged when they run unattended.
behaviourEvery extension enumerated by stable ID — AI assistants flagged, nothing quietly filtered out.
by IDAI apps discovered on iOS and Android — by account type — for the devices your fleet forgets.
mobileCorrelates a running AI agent with metadata-service posture, effective workload identity, reachable storage and cloud-service configuration. Findings model plausible exposure paths without requesting credentials or exploiting the workload.
CSPMA full inventory is table stakes. The hard part is telling your team what's actually dangerous, keeping that judgement current as the world changes, and catching the agent that goes rogue on its own.
Two independent severities, each on its own capability-specific rubric: operational risk — "how bad if misused" — and active threat — "how likely and dangerous is exploitation right now." ChatGPT on 200 laptops is high risk, low threat; one malicious MCP server is the reverse. Your team works what's dangerous, not just what's numerous.
A background engine pulls live vulnerability intelligence — NVD, CISA KEV, OSV — plus curated agent TTPs, and correlates it against your real inventory. "You run Vercel AI SDK vX — it matches this flow CVE." Every exposure carries the real-world AI incidents behind it — Hugging Face malicious models, ShadowRay, torchtriton — so your team sees not just the CVE but how it has already been used. New high or critical exposures alert the affected team on Slack and email, same cycle.
Unattended orchestrators with code-exec, network and live credentials; unexpected HuggingFace model pulls; confused-deputy MCP abuse; skills loaded from unverified repos — detected on the host, mapped to MITRE ATLAS & ATT&CK, and alerted on the next collection cycle — sub-second on Linux via eBPF.
Anyone can list the AI on your fleet. The hard part is deciding what's actually exploitable here, and showing how a handful of small problems become a breach — in plain language your board can follow.
A true AI-BOM: each third-party AI library and its exact installed version, matched against live OSV, NVD and CISA-KEV feeds — real advisories with real severity and the fixed version, not a guess. You see the library, the CVE, and whether a patch exists.
The same CVE isn't equally dangerous everywhere. Our AI re-weights each advisory against what the host actually presents — is the vulnerable library even loaded, is there a live credential, an autonomous agent, no EDR — and tells you whether it's truly Critical or effectively Medium here, with the reasoning and the exploit pre-conditions shown. Advisory only; it never overwrites the official CVE.
An executive view of how small findings chain — a reused key, an outdated library and a missing EDR become foothold → credential theft → privilege escalation → lateral movement → data exfiltration. The connected device → agent → MCP → credential → egress path, with a step-by-step "how this attack happens." Reasoned from what we observed — never exploited.
Ten stages, one platform — from seeing an asset to deciding on a leak. Built like an EDR, not a scanner script.
Risks are scored, explained, and ranked — vulnerable MCP versions, typosquats, secrets, unverified provenance — each with the machine, the person, and the fix attached.
| Severity | Class | Risk | Machine | Owner | Status |
|---|---|---|---|---|---|
| critical | Typosquat | @modelcontextprotocol/server-filesystem | WIN-4471 | j.smith | open |
| high | Vulnerable | server-filesystem@0.3.1 · SHAI-2026-001 | MAC-0192 | r.patel | open |
| high | Secret | Plaintext Anthropic API key | MAC-0192 | r.patel | open |
| medium | Provenance | Skill from github.com/randomuser/pdf-skills | LNX-0088 | k.chen | open |
| info | Sanctioned | Claude Code (approved) | MAC-0192 | r.patel | sanctioned |
Illustrative console view — sample data, not a real customer's fleet. Book a demo to see it on your own. (For findings from real engagements, see customer engagements.)
Detection is table stakes. Araghatta adds a server-side content-DLP policy engine and a console response channel, so a finding becomes a governed decision — not just another alert. The endpoint sensor stays observe-only; enforcement is opt-in and fully audited.
Submit content to the inspection API and the policy engine classifies secrets, PII, PCI (payment-card) and PHI (health) data, and source code, then returns a per-class decision — block, redact or warn — with a monitor-first rollout mode, set per tenant and per crown-jewel machine. It reasons about AI context a generic CASB/SASE rule set doesn't. Inline in-browser enforcement — blocking before the prompt sends — is on the roadmap.
Pause a sensor's collection, or hard-revoke a stolen or rogue device — its token is rejected server-side and it can't re-enroll, so it stops reporting to the platform. This revokes the sensor's access — it reduces what a rogue device can do through Araghatta, but it does not contain or isolate the host itself. Every sensor is attested against the published release binaries, and runs as a tamper-resistant service a standard user can't stop or uninstall (full removal needs admin/MDM). All operator-authorised, with a tamper-evident audit trail. Killing a rogue agent process and inline traffic blocking remain on the roadmap.
They hunt malware and misconfigured cloud. Neither inventories the AI your people actually adopted — the coding agents, MCP servers, and keys sitting on laptops. We do that one job, and we run alongside what you already have.
Built to catch malicious behaviour. It flags a suspicious binary — it won't tell you that binary is an unsanctioned coding agent talking to an LLM API with a plaintext key in a dotfile, or that an unpinned MCP server is wired into it.
Built for cloud posture — configs, workloads, IaC. But shadow AI gets adopted first on laptops: the MCP configs, the .env keys, the browser extensions, the local model runtimes. Your CNAPP never looks there.
A live AI Bill of Materials across the fleet: every agent, SDK, MCP server (package, version, provenance), key, and egress path — attributed to a machine and a person, risk-scored, and mapped to the EU AI Act, NIST AI RMF and ISO 42001.
We don't replace your EDR or CNAPP — we answer the AI-governance question they were never built for: what AI is running, is it sanctioned, how risky is it, and can you prove it to an auditor?
Every risk auto-maps to the frameworks your board reports against, across ten standards. Generate a report and it's registered and HMAC-signed — an auditor verifies its authenticity by Report ID. Export an AI Bill of Materials per host and hand the assessor a live inventory — the evidence pack that otherwise takes analysts weeks.
Not a roadmap. Live in the product today — the identity, policy, evidence, and governance a Fortune-1000 rollout depends on, every capability deployed and covered by an automated test suite.
OIDC single sign-on — Okta, Entra ID, Google, Auth0 — with SCIM user provisioning and group-to-role mapping. No admin-issued passwords; your identity provider owns the lifecycle. Local access stays as break-glass.
Board-ready evidence with document-control metadata and a prioritised remediation plan (POA&M) — each report registered and HMAC-signed, so an auditor can verify authenticity and integrity by Report ID.
Block, redact, or warn on secrets, PII, PCI, PHI, and source code per data class — with a monitor-first rollout mode, set per tenant and per crown-jewel machine — through the inspection API you deploy and control. The endpoint sensor stays observe-only; inline in-browser enforcement is on the roadmap.
Per-tenant data retention with preview-then-purge, right-to-erasure, and a tamper-evident audit trail. Every tenant is isolated at the app layer and with PostgreSQL row-level security.
Stream findings as OCSF Detection Findings to Amazon Security Lake — plus Splunk, Microsoft Sentinel, IBM QRadar, Elastic, and Google Chronicle. Outbound is SSRF-guarded and per-tenant.
Agent-version spread against the current release, last-check-in coverage gaps, and honest hardware-deduplicated device counts — manage a fleet of thousands, not a device list.
We never read your prompts or chats. The endpoint sensor is observe-only; content inspection happens only through the content-DLP policy engine's API that you deploy and control (inline in-browser enforcement is on the roadmap).
One static binary per OS — a real-time eBPF tracer on Linux, scheduled collection on macOS & Windows — feeding a central engine that scores, correlates, and governs. Designed to fail visibly, never silently.
Beyond the platform, we run fixed-fee engagements that turn AI risk into audit-ready evidence: EU AI Act readiness, adversarial red teams, shadow-AI discovery, and continuous testing — delivered with the same tooling, published openly.
Article 9 & 55 evidence, populated — not a template.
2–3 WEEKS · FLAGSHIPAdversarial testing of one LLM app or agent.
2 WEEKS · + RE-TESTApp, RAG and agent layers — including chained paths.
4 WEEKS · DEEPWhat unapproved AI is running right now.
1–2 WEEKSKeep the harness running as models change.
ROLLINGOwn your AI risk programme without a hire.
ONGOINGAgents got hands — MCP and tool-calling turned chatbots into systems that read files, run code, and hold credentials. Regulation entering enforcement now requires organisations to document where AI-processed data flows and prove control over it.
Most teams still can't answer the first question an auditor asks: which AI agents and MCP tools are running in your network right now, unapproved? This answers it in minutes, not quarters.
Start with a free Shadow AI Assessment — run the sensor across your fleet and get an AI risk report and an AIBOM, at no cost, typically within a week.
AI assistant — answers about Araghatta only and may be imperfect. For anything specific, contact us.