Endpoint agent

One agent. Lightweight. Outbound only.

The agent runs as a system service, connects outbound over TLS, and gives the analyst a live console on the host. It collects security telemetry, brings in your endpoint protection's detections, and acts when a detection fires.

A capture of the XenXDR console running on demo data.

Facts

What you install.

About 12 MB

Installed as a Windows service or a systemd unit by a one-shot script, ready without a reboot.

Windows and Linux

Windows 10 and 11, Windows Server 2016 and later. Linux on amd64 and arm64 with systemd.

Outbound only

The agent connects out over authenticated TLS, so the endpoint's inbound firewall stays closed.

Signed updates

Self-update verified against a key pinned at install time. Only builds signed by FluenceSecurity are applied.

Telemetry

What it collects.

Everything the agent collects lands in the same normalised store as the rest of your sources.

  • Windows: Event Log channels including Security, System and PowerShell, Sysmon, and Microsoft Defender detections.
  • Linux: journald, sshd and sudo authentication, and auditd.
  • Fleet policy per organization decides what each host collects and which security tools must be present on the host.
  • Security Tool Availability checks raise an event when a required tool goes down or comes back.

Response

What it can do when a detection fires.

Network isolation

Five containment modes from full lockdown to per-process, lease-based so you keep control of the host, surviving reboot, with tamper detection.

Processes

List, kill, suspend and resume, on Windows and Linux.

Files and hashes

Browse and preview the filesystem, hash files with MD5, SHA-1 and SHA-256, detect type by content, and collect a file off the host into a password-protected archive.

Live shell

An interactive terminal on the host, opened with a short-lived ticket bound to a named operator.

Application control

Block or unblock an application by image or hash, enforced with the strongest option each host supports.

Quick triage

One-shot snapshot of the places that matter: connections, scheduled tasks, services, autoruns, logins, fresh droppers.

Support tiers

Capabilities by platform.

TierPlatformsWhat you get
AWindows 10 1809+ and Server 2019+; Linux 5.8+Collection, response, isolation, application control, triage, self-update.
BWindows 10 1507–1803 and Server 2016; older Linux kernelsCollection, response, isolation, triage and self-update, with a core telemetry set.
CEarlier Windows releasesLog forwarding by syslog or Beats, with search and detection.

See XenXDR on your own telemetry.

A 30-minute walkthrough on fictional data, then a pilot in your environment. No slides, no pressure.