Фон
/products/endpoint/MaxPatrol EDR
/products/mp-vm/MaxPatrol VM
/products/mpsiem/MaxPatrol SIEM

Endpoint agent

A technology that provides continuous monitoring and analysis of system events on endpoint devices, such as employee laptops, company computers and servers, and virtualized workstations

Overview

A unified software component installed on protected devices (computers, laptops, servers, and virtual workstations) that enables continuous monitoring and analysis of system events, detects attacks at early stages, and simplifies vulnerability detection.

Key agent capabilities
1

Collection of system events

The agent locally collects data about events on the endpoint device and sends it to detection modules. When forwarding events to a SIEM system, the agent normalizes them to reduce the load.

2

Detection of complex attacks at early stages

The agent performs static and behavioral threat analysis using an expert set of correlation rules and YARA rules.

3

Stopping malicious actions on nodes

The agent provides a wide range of actions for both predefined and interactive responses on the endpoint device.

4

Autonomous operation

The agent can analyze threats and automatically respond without internet access or communication with the management server, which is crucial for supporting remote devices and nodes with intermittent network connectivity.

5

Support for a wide range of OSs

The agent supports a wide range of international and country-specific operating systems, including Windows, Linux, and macOS. It can also operate in VDI environments.

6

Local device auditing for vulnerability detection and inventory

A single agent collects telemetry, configuration, and inventory data without requiring privileged accounts from the IT department. It then forwards this data to MaxPatrol VM for vulnerability detection. If MaxPatrol VM is not used, the agent still enables asset creation in the system.

Why use host agents?

Сформирована программа трансформации ИТ для построения результативной кибербезопасности.

Endpoint devices are a common attack vector

Attackers use phishing along with application and OS vulnerabilities to initiate attacks. Detecting such events early, before they spread across the network, is critical for organizational cyber resilience.

Распространение шифровальщиков, инфостилеров, вайперов, ВПО для удаленного управления

Spread of ransomware, infostealers, wipers, and RATs

Attackers use increasingly sophisticated tools designed to bypass traditional host-based defenses (such as AV and EDR). Static methods (for example, file signature analysis) are no longer sufficient. Attackers abuse legitimate tools (PowerShell, bash) to hide their tracks, persist in the network, and achieve their goals.

Контролирует полноту данных об активах

Security and IT teams rely on fragmented tools

Some systems require WinEventLog collectors, others need AuditD, and some demand additional accounts for data collection. This fragmentation requires time and expertise for setup, maintenance, and integration with monitoring systems.

Часть устройств находится вне сети или домена, вне зоны видимости средств защиты

Some devices are outside the network or domain, beyond security visibility

Devices of remote or traveling employees, as well as unmanaged devices, operate beyond IT visibility and do not send data to SIEM systems or vulnerability scanners.

Positive Technologies endpoint agent

More than just a sensor

Flexible configuration

Broad OS support

Delivery and installation modules

Collection modules

Detection modules

Response modules

Agents in Positive Technologies products

Thinking about the best way to protect your company?

Contact us.

During the consultation we'll propose a solution precisely tailored to your organization.

 

General questions
We're happy to answer any questions you may have.
Partnership
Join us in making the world a safer place.
Request a pilot
Test drive our solutions with a customized pilot program.