Endpoint protection & EDR

One agent that prevents, detects, contains and puts the machine back

Guardian Sentinel's endpoint agent is a single 42 MB binary with a kernel-level sensor, on-device machine learning and a write journal that can reverse an attack's damage. It protects at full strength with no network connection, and it holds under 1.2% CPU on a five-year-old laptop.

42MB Single installer covering prevention, EDR, device control and rollback
1.2% Median CPU at steady state, measured across 3.1 million managed hosts
1.9s Median time to kill and quarantine a ransomware process tree, on device
0 Reboots required for install, upgrade or policy change on Windows and macOS
100% Of on-device detection logic remains active when the host is offline

Agent architecture

Kernel visibility, user-space intelligence, self-protection throughout

The sensor sits low enough to see everything a process actually does, while the decision logic runs in user space where it can be updated without a driver signing cycle or a reboot. Every layer is tamper-protected, including against local administrators.

PROTECTED HOST USER SPACE Prevention Behaviour Device control Exposure Static classifier Exploit mitigation Script inspection Sequence models Lineage scoring Canary monitor USB and media Bluetooth policy Peripheral rules Vuln assessment Misconfig checks Software inventory Agent core Policy engine · local model runtime · telemetry bus · response executor Self-protection: signed, sealed, uninstallable only with a tenant token KERNEL SPACE Process & thread File system Network flow Creation, injection and handle events Mini-filter with write journalling eBPF on Linux, WFP on Windows Kernel components are versioned independently and fail open to logging, never to a stop error. mTLS pinned Guardian control plane Cross-surface correlation Attack-graph reasoning Sentinel AI Analyst Model & content delivery Fleet policy and audit Offline? The host keeps protecting and queues. Outbound only, port 443. No inbound listener is ever opened on a protected host.

Scroll horizontally to see the full diagram on a small screen.

EDR capabilities

Everything an investigation needs, without a second console

Prevention stops the majority. EDR exists for the rest — and for the questions you will be asked afterwards by auditors, regulators and your own board.

Full process lineage

Every process, its parent, its command line, its loaded modules, its network connections and its file writes — recorded continuously, not sampled, and retained for 365 days.

Live and historical hunting

Query the fleet in Sentinel Query Language and get answers across 100,000 hosts in a median of 340 ms. Save a hunt as a scheduled detection in one click.

Network isolation with a lifeline

Isolate a host from everything except the Guardian management channel, so responders keep full remote investigation and remediation while the machine is quarantined.

Remote shell, scoped and audited

A responder shell with per-command authorisation, full session recording and an allow-list of binaries. Every keystroke lands in the tenant audit log.

Forensic collection

Triage packages, memory captures, prefetch, event logs, browser artefacts and registry hives collected on demand and hashed on the wire for chain of custody.

Exposure management

Continuous vulnerability and misconfiguration assessment from the same agent, prioritised by real exploitability on that specific host, not by CVSS alone.

Device and media control

Policy for USB mass storage, MTP devices, Bluetooth and printers, enforced per user, per site and per data classification rather than per machine.

Firewall and disk-encryption control

Manage the native host firewall and verify BitLocker and FileVault state from the same policy surface, with drift alerting when something turns them off.

One-click rollback

Reverse file encryption, deleted shadow copies, dropped persistence and altered registry keys using the agent's own write journal. No backup restore, no reimage.

Coverage

Supported operating systems

One agent, one policy model and one console across every platform below. Linux support uses eBPF where the kernel provides it and a signed module where it does not, so you are never blocked from patching a kernel.

Support matrix for agent release 2026.7. Versions reach end of support 90 days after the vendor's own end-of-support date unless an extended module is licensed.
Platform Supported versions Sensor Prevention EDR Rollback
Windows client 11 (all channels), 10 21H2 and later, Windows on ARM64 WFP + mini-filter Full Full Full
Windows Server 2025, 2022, 2019, 2016; Server Core and Nano WFP + mini-filter Full Full Full
macOS 15 Sequoia, 14 Sonoma, 13 Ventura — Apple silicon and Intel Endpoint Security framework Full Full Full
Enterprise Linux RHEL, Rocky, AlmaLinux 8–10; Oracle Linux 8–9 eBPF (kernel 4.18+) Full Full Full
Debian family Ubuntu 20.04, 22.04, 24.04, 26.04 LTS; Debian 11–13 eBPF (kernel 5.4+) Full Full Full
SUSE SLES 15 SP4–SP7, openSUSE Leap 15.5+ eBPF or signed module Full Full Full
Amazon Linux Amazon Linux 2 and 2023, including Graviton eBPF Full Full Full
Container host OS Bottlerocket, Flatcar, Talos, Container-Optimized OS eBPF, DaemonSet delivery Full Full Immutable host
Virtual desktop Citrix, Omnissa Horizon, AVD, non-persistent pools WFP + mini-filter Full Full Session scope
Legacy (extended module) Windows 7 SP1, Server 2012 R2, RHEL 7 Legacy filter driver Full Reduced telemetry Not available

Scroll the table horizontally to see every column.

Operational technology and embedded platforms are covered by a separate read-only sensor. See energy & utilities for OT reference architectures.

Host impact, indexed to legacy EPP = 100 (lower is better) Legacy EPP Point-tool EDR Guardian Sentinel 0 25 50 75 100 31 38 46 22 18 CPU steady state Peak CPU during scan Resident memory Boot time delta App launch delay Measured on a 2020-vintage 4-core laptop image, 200 samples per configuration, March 2026.

Scroll horizontally to see the full chart on a small screen.

Offline protection

Air-gapped, on a plane, or behind a failed VPN — still protected

Cloud-dependent agents degrade to a signature file when connectivity drops. Sentinel's decision logic lives on the host, so an offline machine gets the same prevention and the same local response as one sitting in the office.

What the agent can do without any connection to the control plane.
Capability Online Offline Behaviour when disconnected
Static and behavioural prevention Yes Yes Models are resident on disk; inference is entirely local
Ransomware canary and rollback Yes Yes Write journal is local; restore runs without the control plane
Process kill and quarantine Yes Yes Local policy authorises the action, then logs it for later upload
Device and USB control Yes Yes Last-known policy is cached and enforced indefinitely
Telemetry retention Yes Yes Up to 14 days buffered on disk, compressed, then replayed on reconnect
Cross-surface correlation Yes Deferred Runs on reconnect against the buffered timeline; nothing is lost
AI Analyst narrative and triage Yes Deferred Incident is raised locally, enriched when the host comes back
Remote shell and forensic collection Yes No Requires the management channel; queued for the next connection

Scroll the table horizontally to see every column.

Fully disconnected estates are supported as a first-class deployment. Air-gapped tenants receive signed weekly content bundles and run the same on-device model set. See deployment options for the air-gapped architecture.

Rollback & remediation

Undo the attack, not just stop it

The mini-filter journals every write a suspicious process makes before it is judged. When the verdict lands, the agent replays that journal in reverse — files, registry keys, scheduled tasks, services and shadow copies all return to their pre-attack state.

Ransomware event, single host clean encrypted restored T−00:30 T+00:00 T+00:12 T+02:43 T+03:09 Journalling active Suspicious process starts 8,412 files encrypted Killed and isolated Restore complete One restore action — 8,412 files reversed in 26 seconds
Reconstructed from a customer incident. Total business impact: no data loss, no reimage, host returned to service in under four minutes.

What rollback reverses

  • Encrypted, overwritten and deleted files
  • Registry keys and values, including run keys
  • Scheduled tasks, services and cron entries
  • Deleted volume shadow copies
  • Dropped binaries and injected modules

What it deliberately does not touch

Rollback is scoped to the journalled activity of the offending process tree. Legitimate work saved by the user during the same window is preserved, and the operation is previewed file-by-file before it executes if you enable approval mode.

Database and hypervisor volumes are excluded by default; those are restored through their own consistent mechanisms.

Journal cost and retention

The journal captures only writes attributable to processes under suspicion, which on a typical workstation is under 400 MB and is trimmed continuously. Retention is configurable from 12 hours to 7 days.

Automate rollback in a playbook

Deployment & operations

Rolled out at 25,000 endpoints in nine days, median

The agent installs silently through the deployment tooling you already operate, coexists with the product you are replacing during migration, and needs no reboot on Windows or macOS.

Package once

Signed MSI, PKG, DEB, RPM and a Helm chart for container hosts, all carrying the tenant token so there is nothing to configure post-install.

Ship through your existing tooling

Intune, SCCM, Jamf, Workspace ONE, Ansible, Chef, Puppet, Salt or a GPO startup script — whatever already reaches your fleet.

Run side by side

Coexistence mode keeps the incumbent product's exclusions honoured while Sentinel observes, so you can compare detections before you cut over.

Cut over by ring

Promote prevention ring by ring from the console. Every policy change is versioned and reversible in one action across the whole estate.

Will it conflict with the EDR we already run?

Coexistence mode is designed for exactly this window. Sentinel runs in observe-only, registers its filter at a compatible altitude and applies the incumbent's exclusion set automatically. Guardian validates coexistence against the twelve most common EPP and EDR products every release.

How are agent upgrades handled?

You control the version per device group, with N−2 support and an automatic channel if you want it. Upgrades are staged, resumable and reboot-free on Windows and macOS; on Linux a kernel-module deployment requires a reboot only when the kernel itself changes, and eBPF deployments never do.

Can a local administrator remove the agent?

No. Uninstall requires a time-bounded token issued from the tenant console and recorded in the audit log. Service stop, driver unload, file deletion and process termination are all blocked, and any attempt raises a tamper detection with the initiating identity attached.

What does the agent send back, and can we see it?

Normalised metadata about process, file, registry, authentication and network events — never file contents or user documents unless you explicitly request a forensic collection. The full field list is published in the datasheet, and a per-host telemetry inspector in the console shows exactly what left that machine.

How does it behave on non-persistent VDI?

VDI mode assigns session-scoped identity rather than machine identity, deduplicates inspection across sessions from the same golden image, and reclaims licences automatically when a session is destroyed. Golden images are pre-baked with the agent in a dormant state that activates on first boot.

Do you support Windows 7 and Server 2012 R2?

Yes, through the extended platform module. Prevention is full-strength; telemetry depth is reduced because the underlying OS does not expose the same kernel notifications, and rollback is unavailable. It is a bridge for estates in the middle of a migration, not a destination.

We put Sentinel on 18,000 machines in eleven days without a single reboot ticket. The performance number that mattered to me was not CPU — it was that the service desk never noticed the rollout had happened.
Deepa Krishnan Director of End User Computing, Arbor Manufacturing Group

Test it against your own gold image

We will run a measured bake-off on your standard build — performance deltas, detection results and a coexistence plan for the product you are replacing.