Full process lineage
Every process, its parent, its command line, its loaded modules, its network connections and its file writes — recorded continuously, not sampled, and retained for 365 days.
Endpoint protection & EDR
Guardian Sentinel's endpoint agent is a single 42 MB binary with a kernel-level sensor, on-device machine learning and a write journal that can reverse an attack's damage. It protects at full strength with no network connection, and it holds under 1.2% CPU on a five-year-old laptop.
Agent architecture
The sensor sits low enough to see everything a process actually does, while the decision logic runs in user space where it can be updated without a driver signing cycle or a reboot. Every layer is tamper-protected, including against local administrators.
Scroll horizontally to see the full diagram on a small screen.
EDR capabilities
Prevention stops the majority. EDR exists for the rest — and for the questions you will be asked afterwards by auditors, regulators and your own board.
Every process, its parent, its command line, its loaded modules, its network connections and its file writes — recorded continuously, not sampled, and retained for 365 days.
Query the fleet in Sentinel Query Language and get answers across 100,000 hosts in a median of 340 ms. Save a hunt as a scheduled detection in one click.
Isolate a host from everything except the Guardian management channel, so responders keep full remote investigation and remediation while the machine is quarantined.
A responder shell with per-command authorisation, full session recording and an allow-list of binaries. Every keystroke lands in the tenant audit log.
Triage packages, memory captures, prefetch, event logs, browser artefacts and registry hives collected on demand and hashed on the wire for chain of custody.
Continuous vulnerability and misconfiguration assessment from the same agent, prioritised by real exploitability on that specific host, not by CVSS alone.
Policy for USB mass storage, MTP devices, Bluetooth and printers, enforced per user, per site and per data classification rather than per machine.
Manage the native host firewall and verify BitLocker and FileVault state from the same policy surface, with drift alerting when something turns them off.
Reverse file encryption, deleted shadow copies, dropped persistence and altered registry keys using the agent's own write journal. No backup restore, no reimage.
Coverage
One agent, one policy model and one console across every platform below. Linux support uses eBPF where the kernel provides it and a signed module where it does not, so you are never blocked from patching a kernel.
| Platform | Supported versions | Sensor | Prevention | EDR | Rollback |
|---|---|---|---|---|---|
| Windows client | 11 (all channels), 10 21H2 and later, Windows on ARM64 | WFP + mini-filter | Full | Full | Full |
| Windows Server | 2025, 2022, 2019, 2016; Server Core and Nano | WFP + mini-filter | Full | Full | Full |
| macOS | 15 Sequoia, 14 Sonoma, 13 Ventura — Apple silicon and Intel | Endpoint Security framework | Full | Full | Full |
| Enterprise Linux | RHEL, Rocky, AlmaLinux 8–10; Oracle Linux 8–9 | eBPF (kernel 4.18+) | Full | Full | Full |
| Debian family | Ubuntu 20.04, 22.04, 24.04, 26.04 LTS; Debian 11–13 | eBPF (kernel 5.4+) | Full | Full | Full |
| SUSE | SLES 15 SP4–SP7, openSUSE Leap 15.5+ | eBPF or signed module | Full | Full | Full |
| Amazon Linux | Amazon Linux 2 and 2023, including Graviton | eBPF | Full | Full | Full |
| Container host OS | Bottlerocket, Flatcar, Talos, Container-Optimized OS | eBPF, DaemonSet delivery | Full | Full | Immutable host |
| Virtual desktop | Citrix, Omnissa Horizon, AVD, non-persistent pools | WFP + mini-filter | Full | Full | Session scope |
| Legacy (extended module) | Windows 7 SP1, Server 2012 R2, RHEL 7 | Legacy filter driver | Full | Reduced telemetry | Not available |
Scroll the table horizontally to see every column.
Operational technology and embedded platforms are covered by a separate read-only sensor. See energy & utilities for OT reference architectures.
Scroll horizontally to see the full chart on a small screen.
Offline protection
Cloud-dependent agents degrade to a signature file when connectivity drops. Sentinel's decision logic lives on the host, so an offline machine gets the same prevention and the same local response as one sitting in the office.
| Capability | Online | Offline | Behaviour when disconnected |
|---|---|---|---|
| Static and behavioural prevention | Yes | Yes | Models are resident on disk; inference is entirely local |
| Ransomware canary and rollback | Yes | Yes | Write journal is local; restore runs without the control plane |
| Process kill and quarantine | Yes | Yes | Local policy authorises the action, then logs it for later upload |
| Device and USB control | Yes | Yes | Last-known policy is cached and enforced indefinitely |
| Telemetry retention | Yes | Yes | Up to 14 days buffered on disk, compressed, then replayed on reconnect |
| Cross-surface correlation | Yes | Deferred | Runs on reconnect against the buffered timeline; nothing is lost |
| AI Analyst narrative and triage | Yes | Deferred | Incident is raised locally, enriched when the host comes back |
| Remote shell and forensic collection | Yes | No | Requires the management channel; queued for the next connection |
Scroll the table horizontally to see every column.
Fully disconnected estates are supported as a first-class deployment. Air-gapped tenants receive signed weekly content bundles and run the same on-device model set. See deployment options for the air-gapped architecture.
Rollback & remediation
The mini-filter journals every write a suspicious process makes before it is judged. When the verdict lands, the agent replays that journal in reverse — files, registry keys, scheduled tasks, services and shadow copies all return to their pre-attack state.
Rollback is scoped to the journalled activity of the offending process tree. Legitimate work saved by the user during the same window is preserved, and the operation is previewed file-by-file before it executes if you enable approval mode.
Database and hypervisor volumes are excluded by default; those are restored through their own consistent mechanisms.
The journal captures only writes attributable to processes under suspicion, which on a typical workstation is under 400 MB and is trimmed continuously. Retention is configurable from 12 hours to 7 days.
Automate rollback in a playbookDeployment & operations
The agent installs silently through the deployment tooling you already operate, coexists with the product you are replacing during migration, and needs no reboot on Windows or macOS.
Signed MSI, PKG, DEB, RPM and a Helm chart for container hosts, all carrying the tenant token so there is nothing to configure post-install.
Intune, SCCM, Jamf, Workspace ONE, Ansible, Chef, Puppet, Salt or a GPO startup script — whatever already reaches your fleet.
Coexistence mode keeps the incumbent product's exclusions honoured while Sentinel observes, so you can compare detections before you cut over.
Promote prevention ring by ring from the console. Every policy change is versioned and reversible in one action across the whole estate.
Coexistence mode is designed for exactly this window. Sentinel runs in observe-only, registers its filter at a compatible altitude and applies the incumbent's exclusion set automatically. Guardian validates coexistence against the twelve most common EPP and EDR products every release.
You control the version per device group, with N−2 support and an automatic channel if you want it. Upgrades are staged, resumable and reboot-free on Windows and macOS; on Linux a kernel-module deployment requires a reboot only when the kernel itself changes, and eBPF deployments never do.
No. Uninstall requires a time-bounded token issued from the tenant console and recorded in the audit log. Service stop, driver unload, file deletion and process termination are all blocked, and any attempt raises a tamper detection with the initiating identity attached.
Normalised metadata about process, file, registry, authentication and network events — never file contents or user documents unless you explicitly request a forensic collection. The full field list is published in the datasheet, and a per-host telemetry inspector in the console shows exactly what left that machine.
VDI mode assigns session-scoped identity rather than machine identity, deduplicates inspection across sessions from the same golden image, and reclaims licences automatically when a session is destroyed. Golden images are pre-baked with the agent in a dormant state that activates on first boot.
Yes, through the extended platform module. Prevention is full-strength; telemetry depth is reduced because the underlying OS does not expose the same kernel notifications, and rollback is unavailable. It is a bridge for estates in the middle of a migration, not a destination.
We put Sentinel on 18,000 machines in eleven days without a single reboot ticket. The performance number that mattered to me was not CPU — it was that the service desk never noticed the rollout had happened.
We will run a measured bake-off on your standard build — performance deltas, detection results and a coexistence plan for the product you are replacing.