Skip to content
The endpoint sensor

The EDR for AI

One lightweight agent that discovers, attributes and scores unsanctioned AI on every laptop and server — the AI layer your EDR and DLP can't see.

Traditional EDR and DLP watch processes and files. They are blind to the AI layer — they can't tell you that a laptop is running an unsanctioned AI agent, leaking an API key to an LLM, or shipping code a developer never actually reviewed. Araghatta is the EDR for AI: a single lightweight agent that discovers, attributes and scores unsanctioned AI across every endpoint — macOS, Linux and Windows — and streams the evidence straight into your SIEM.

What the sensor sees

AI CLIs & agents

Claude Code, Ollama, LangChain/agent runtimes and other AI CLIs on PATH or running.

Provider API keys

OpenAI / Anthropic / etc. keys in env, .env files and shell profiles — fingerprinted at the source.

MCP servers & tool scope

MCP config parsed for servers, packages, versions, pins — and the fs / shell / network tool scope granted.

IDE AI assistants

Copilot, Cursor, Cody, Continue, Amazon Q, Tabnine — enumerated by marketplace ID, with account and version.

Skills files & provenance

Downloaded SKILL.md and agent skills — executable instructions, tied to their unverified source repo.

LLM SDK usage

openai / anthropic / langchain SDKs imported in running processes and manifests.

Installed AI apps

Desktop AI apps (Cursor, ChatGPT, Monica, …) present on the device.

Browser AI extensions

Chromium & Firefox extensions flagged as AI by id/keyword.

Egress to AI endpoints

Live connections to AI/LLM services — matched by host, process and resolved IP.

Autonomous agents

Orchestrators running with AI — LangChain, CrewAI, AutoGen, MCP loops — flagged when they run unattended.

Vibe-coded repos

Repositories where AI wrote the code — Cursor / Copilot / Claude footprints reaching production without review.

Non-human identities

Agent & service credentials, and offboarded users still holding live AI access.

Why now

AI adoption outran governance. Claude Code, Cursor and Copilot are now on a large share of developer machines; employees run local models, wire up MCP servers and paste data into LLMs — all outside any policy. Security teams have no inventory of it, and regulators (EU AI Act, NIST AI RMF, DPDP) increasingly require one. Whoever owns AI visibility on the endpoint owns the category.

Find the AI users your EDR isn't protecting

The sensor detects whether an endpoint has EDR running — CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint, Carbon Black, Cortex XDR and more — and crosses it with AI usage to answer the single most useful question in one view: “which machines are running AI tools with no endpoint protection?” — a coverage gap you can close immediately.

Detect → Attribute → Report to your SIEM

Detection is the start. Every finding is attributed to a device, user and account, scored separately on risk and threat, and streamed to your SIEM with full context — so it lands in the workflow your SOC already lives in. The sensor is observe-only by design; a coarse host/process deny-list is available opt-in (off by default, advanced), and AI-aware host/agent blocking plus inline browser DLP are on the roadmap.

Splunk

HTTP Event Collector (HEC)

Microsoft Sentinel

Log Analytics connector

IBM QRadar

syslog / LEEF

Elastic Security

Elasticsearch / ECS

Google Chronicle

ingestion API

Any SIEM

generic syslog / CEF + webhook

Govern your AI-generated code — “Vibe Coding”

Developers now build by prompting AI — “vibe coding” — and ship code they never fully reviewed. The sensor detects AI coding tools (Claude Code, Cursor, Copilot, Windsurf, Codeium, aider…) and flags the repositories and files that were AI-generated. A dedicated Vibe Coding view shows which developers and repos are AI-heavy and their review status — then routes flagged code straight into security review (SAST + secrets + AI-security checks) for an engineer sign-off.

The loop nobody else closes: the platform detects the AI code → reviews it → an engineer approves it. AI-generated code, governed end-to-end.

Cloud-server CSPM: connect the AI agent to the cloud blast radius.

On EC2, Azure VMs and Google Compute Engine, the self-contained sensor identifies the AI process or autonomous agent, its user or service identity, tool scope, network context and access to local workload services. A least-privilege, read-only AWS connector supplies control-plane evidence today; Azure and Google Cloud connectors are being brought online. The platform joins the two views instead of treating a host finding and a cloud misconfiguration as unrelated alerts.

Runtime

Agent capability

Process, parent, package, service/container, unattended state, shell or code-execution tool scope, network access and credential references—with usable secret values excluded.

Workload boundary

Metadata and identity

IMDSv1/IMDSv2 posture on AWS today — with managed-identity metadata on Azure and service-account metadata on Google Cloud as those connectors come online — and the effective permissions attached to the workload.

Attack path

Reachable data and services

Correlates the runtime with Amazon S3 today (Azure Storage and Google Cloud Storage on connect) and other authorised resources to identify the shortest defensible remediation path.

Safe by design: attack paths are inferred from observed configuration and authorised read-only APIs. The sensor does not retrieve workload credentials, read customer objects or execute an exploit. Review the Cloud CSPM capability →

Capabilities

CapabilityWhat it delivers
Full-surface AI detectionEleven signal classes — AI CLIs & agents, keys, MCP & tool scope, IDE assistants, skills, SDKs, apps, extensions, egress, vibe-coded repos, cloud-server CSPM — one normalized platform
Cross-platform + mobileWindows, macOS and Linux from a single self-contained binary (Windows Server in beta); iOS & Android AI-app discovery alongside
Two-axis severityOperational risk and active threat scored separately, each on a capability-specific rubric
Continuous threat intelNVD · CISA KEV · OSV + curated agent TTPs correlated to your fleet — Slack & email alerts on new exposures
Rogue-agent detectionUnattended orchestrators, HuggingFace pulls, confused-deputy MCP abuse — mapped to MITRE ATLAS & ATT&CK
Cloud-server CSPM & agent attack pathsCorrelates AI runtime and tool scope with metadata-service posture, effective workload identity, cloud policies and reachable storage/services — AWS today; Azure & Google Cloud on connect
Risk posture & AI-BOMPer-host risk score plus a complete AI Bill-of-Materials, with vulnerable AI components matched against CISA KEV / NVD / OSV
Supply-chain provenanceWhere each MCP server / skill came from — official registry vs unofficial Git vs unknown — so governance is by source + scope, not an impossible allow-list
Device trust & responseRevoke a stolen/rogue device (server-enforced cutoff), attest the sensor binary against releases, tamper-resistant service, remote-pause — all operator-authorised and audited
EDR-coverage gapSurface every endpoint running AI with no endpoint protection
Report & streamEvery finding to Splunk, Sentinel, QRadar, Elastic, Chronicle — plus Jira, Slack and OCSF / Amazon Security Lake
AI-code governanceDetect AI-generated code and route it for security review
Privacy-first deploymentObserve-only by default, MDM install, secrets masked on the endpoint
Compliance evidenceAI-BOM and governance exports mapped to EU AI Act and NIST AI RMF

What runs on which OS — honestly.

Discovery is identical everywhere. Real-time tracing differs by platform, and active enforcement is still on the roadmap — we'd rather tell you than let you find out. The sensor is observe-only today; when enforcement ships it will be opt-in and fully audited.

CapabilityWindowsmacOSLinux
AI discovery — 11 signal classes, AI-BOM, risk + threat scoringGAGAGA
Real-time exec & connect tracingscheduledscheduledeBPF · GA
Inline AI-DLP (browser) — block secrets/source before sendroadmaproadmaproadmap
Policy enforcement — host/process deny-list (opt-in, off by default, advanced)opt-inopt-inopt-in
AI-aware enforcement — block a denied AI host / quarantine an agentroadmaproadmaproadmap
Remote pause — stop a sensor’s collection from the consoleGAGAGA
Device revocation — cut off a stolen/rogue device (token rejected server-side, re-enroll blocked)GAGAGA
Device attestation — sensor binary verified against the published releasesGAGAGA
Tamper-resistant service — runs as a system service a standard user can’t stop or uninstall (removal needs admin/MDM)GAGAGA
Compliance evidence + SIEM streamingGAGAGA

Real-time exec/connect tracing is Linux-first (eBPF) and expanding to macOS & Windows. Today the only enforcement is an opt-in, off-by-default host/process deny-list (advanced, root-required, not AI-aware); AI-aware host/agent blocking and inline browser DLP are on the roadmap. Discovery, attribution, scoring and evidence are identical across all three platforms today.

Deploys in minutes. Observe-only by default.

One self-contained binary

A single self-contained agent per OS, pushed via your MDM (Intune, Jamf, …), verified by SHA-256 checksum. No agent sprawl, no dependencies.

Privacy-first

Observe-only by default. Secrets are masked on the endpoint; key values never leave the device. When enforcement ships it will be opt-in and fully audited.

Your data, encrypted

TLS in transit, encrypted at rest, per-device enrolment tokens.

Evidence for auditors

Export an AI-BOM and governance evidence mapped to EU AI Act and NIST AI RMF.

See every AI tool — and every line of AI-generated code — on your fleet.

Start a free trial  Book a 30-min demo