Endpoint agent
One agent. Lightweight. Outbound only.
The agent runs as a system service, connects outbound over TLS, and gives the analyst a live console on the host. It collects security telemetry, brings in your endpoint protection's detections, and acts when a detection fires.
Facts
What you install.
About 12 MB
Installed as a Windows service or a systemd unit by a one-shot script, ready without a reboot.
Windows and Linux
Windows 10 and 11, Windows Server 2016 and later. Linux on amd64 and arm64 with systemd.
Outbound only
The agent connects out over authenticated TLS, so the endpoint's inbound firewall stays closed.
Signed updates
Self-update verified against a key pinned at install time. Only builds signed by FluenceSecurity are applied.
Telemetry
What it collects.
Everything the agent collects lands in the same normalised store as the rest of your sources.
- Windows: Event Log channels including Security, System and PowerShell, Sysmon, and Microsoft Defender detections.
- Linux: journald, sshd and sudo authentication, and auditd.
- Fleet policy per organization decides what each host collects and which security tools must be present on the host.
- Security Tool Availability checks raise an event when a required tool goes down or comes back.
Response
What it can do when a detection fires.
Network isolation
Five containment modes from full lockdown to per-process, lease-based so you keep control of the host, surviving reboot, with tamper detection.
Processes
List, kill, suspend and resume, on Windows and Linux.
Files and hashes
Browse and preview the filesystem, hash files with MD5, SHA-1 and SHA-256, detect type by content, and collect a file off the host into a password-protected archive.
Live shell
An interactive terminal on the host, opened with a short-lived ticket bound to a named operator.
Application control
Block or unblock an application by image or hash, enforced with the strongest option each host supports.
Quick triage
One-shot snapshot of the places that matter: connections, scheduled tasks, services, autoruns, logins, fresh droppers.
Support tiers
Capabilities by platform.
| Tier | Platforms | What you get |
|---|---|---|
| A | Windows 10 1809+ and Server 2019+; Linux 5.8+ | Collection, response, isolation, application control, triage, self-update. |
| B | Windows 10 1507–1803 and Server 2016; older Linux kernels | Collection, response, isolation, triage and self-update, with a core telemetry set. |
| C | Earlier Windows releases | Log forwarding by syslog or Beats, with search and detection. |
See XenXDR on your own telemetry.
A 30-minute walkthrough on fictional data, then a pilot in your environment. No slides, no pressure.