One agent, not four
A single 42 MB binary delivers prevention, EDR, device control, vulnerability assessment and network sensing. No plug-in chains, no conflicting drivers, no second reboot cycle.
Inside the agentThe Guardian Sentinel platform
Guardian Sentinel replaces a shelf of disconnected point products with a single agent, a single data layer and a single console. Telemetry from endpoint, network, cloud, identity and data is normalised once, reasoned over by the same models, and acted on in a median of 3.8 seconds — without an analyst having to stitch four tools together first.
Deployed in 142 countries · 6,800+ organisations · 43 of the Fortune 100
Architecture
Most security “platforms” are four products in a shared invoice: four agents, four schemas, four consoles, and a correlation problem the customer inherits. Guardian Sentinel is a single vertically integrated pipeline — collection, normalisation, reasoning and response are stages of one system, written by one engineering organisation, shipped on one release train.
Scroll horizontally to see the full diagram on a small screen.
A single 42 MB binary delivers prevention, EDR, device control, vulnerability assessment and network sensing. No plug-in chains, no conflicting drivers, no second reboot cycle.
Inside the agentEvery event — a process launch, a TLS handshake, an AssumeRole, a mailbox rule —
lands in the same OCSF-aligned record shape with the same entity keys. Joins are free.
Detection and response are not separate products handing each other tickets. The engine that scores the behaviour is the engine that authorises containment, under one policy grammar.
Response & automationUnified data layer
Detection quality is bounded by how well your telemetry joins. Guardian Sentinel resolves every observation to a durable entity — a person, a device, a workload, a data object — the moment it is written, so a question that used to take four consoles and a spreadsheet becomes one query against one graph.
Scroll horizontally to see the full chart on a small screen.
Modules
Enable what you need today and switch on the rest without a new agent, a new contract vehicle or a new data pipeline. Every module writes into the same fabric, so coverage you add on Monday improves detections everywhere else by Tuesday.
Behavioural models, sequence analysis and attack-graph correlation that surface real intrusions in seconds and suppress the rest. 214 MITRE ATT&CK techniques covered.
Explore threat detectionPrevention, EDR, device control and one-click rollback in a single agent that holds under 1.2% CPU at steady state and keeps protecting when the device is offline.
Explore endpoint securityNetwork detection and response with true east-west visibility, encrypted traffic analysis without decryption, and inline blocking at the sensor or the firewall.
Explore network securityCNAPP across AWS, Azure and Google Cloud: posture, entitlements, workload runtime, Kubernetes and infrastructure-as-code scanning in the developer's pull request.
Explore cloud securityCredential theft, Kerberos abuse, token replay and privilege escalation caught at the directory and the identity provider, with session revocation in under two seconds.
Explore identity protectionClassification that follows the object rather than the location, with movement monitoring across endpoints, SaaS, email and cloud stores — and containment before exfiltration completes.
Explore data protectionPlaybooks written in plain policy, executed at machine speed, with an approval model that lets you keep humans in the loop exactly where you want them.
Explore automationGuardian Labs tracks 340 named adversary groups and pushes new detection logic to every tenant continuously — no content packs to import, no rule tuning weekend.
Explore threat intelligence400+ certified connectors for SIEM, SOAR, ITSM, identity providers, ticketing and data lakes, plus a documented REST and streaming API with parity to the console.
Explore integrationsDeployment
The same code, the same detections and the same console ship in four deployment shapes. Tenants can move between them without re-instrumenting endpoints or losing history.
The default for most organisations. Fully managed across 14 regions, with per-tenant encryption keys, hardware-backed key custody and a 99.99% availability commitment. New detection content reaches your tenant within four hours of publication.
A dedicated control plane and dedicated storage inside a jurisdiction you nominate, operated by Guardian but isolated from the multi-tenant fleet. Built for regulated workloads under DORA, NIS2, national banking rules and public-sector frameworks.
Deploy the full control plane into your own EKS, AKS, GKE or OpenShift cluster with a signed Helm chart. You own the infrastructure, the storage tier and the upgrade cadence; Guardian ships releases and detection content you pull on your schedule.
For classified networks, defence programmes and operational-technology environments that cannot route to the internet. Detection content, models and platform updates arrive as signed offline bundles verified against an offline root of trust.
Mixed estates are normal. Many customers run Guardian Cloud for corporate IT and an air-gapped enclave for OT or classified networks, federated into one reporting view. See energy & utilities and government & defence for reference designs.
Comparison
A side-by-side against the two architectures most enterprises are running today: a legacy antivirus plus SIEM stack, and a best-of-breed collection of modern point tools.
| Capability | Legacy AV + SIEM | Best-of-breed point tools | Guardian Sentinel |
|---|---|---|---|
| Agents on the endpoint | 3–5, often conflicting | 3–4, one per vendor | 1 |
| Telemetry schema | Vendor-specific, parsed downstream with fragile regex | Per-product schemas, joined manually in the SIEM | One OCSF-aligned schema, resolved to entities on write |
| Detection logic | Signatures plus hand-written correlation rules | Per-surface models with no shared context | Cross-surface behavioural models over a shared entity graph |
| Mean time to detect | Hours to days | 14–40 minutes | Under 5 seconds |
| Mean time to contain | Manual, measured in hours | Semi-automated, 8–25 minutes | 3.8 seconds, autonomous |
| Analyst alerts per 10k endpoints, per day | 1,900+ | 380 | 27 |
| Retention economics | Per-gigabyte ingest billing; teams drop telemetry to control cost | Mixed; hot windows typically 30–90 days | 365 days hot, included per endpoint |
| Cloud and container runtime coverage | None or agent-only | Separate CNAPP vendor and separate console | Native CSPM, CWPP, CIEM, KSPM and IaC scanning |
| Identity signal in endpoint detections | Not correlated | Correlated after the fact, if at all | Native — identity is a first-class entity in the graph |
| Rollback of encrypted or altered files | Restore from backup | Partial, endpoint only | One-click, per-host or per-incident |
| Time to full deployment, 25k endpoints | 6–12 months | 10–16 weeks | 9 days median |
| Three-year total cost of ownership | Baseline | −12% vs baseline | −41% vs baseline |
Scroll the table horizontally to see every column.
Figures are medians from Guardian deployment telemetry and customer-reported finance data. Your results will vary with estate composition and starting maturity — ask for a modelled estimate against your own environment.
Adoption path
Nobody flips autonomous response on across 40,000 endpoints on day one. Guardian's rollout model earns trust in measurable steps, and every stage is reversible.
Deploy the agent in detect-only mode to a pilot ring. Sentinel builds per-entity baselines, inventories the estate and reports what your current stack is missing. No enforcement, no user impact.
Turn on prevention for the highest-confidence classes — known-malicious execution, credential dumping, ransomware canaries. Typical false-positive rate at this stage is under 0.2%.
Enable containment playbooks with approval gates for the actions you consider disruptive. The AI Analyst writes the incident narrative; your team approves the action in one click.
Move proven playbooks to fully autonomous execution and keep humans on the exceptions. Most customers reach this stage on their top ten detection classes within 90 days.
We removed four products and a full-time SIEM engineer's worth of rule maintenance. What surprised us was not the consolidation — it was that our detection coverage went up while our alert volume fell by an order of magnitude.
Measured after 12 months, 31,400 endpoints
Northlane consolidated endpoint, network and cloud detection onto Sentinel in three waves over nine weeks, retiring a legacy EPP, a standalone NDR appliance fleet, a CSPM tool and 62% of their SIEM ingest volume.
Read the full case studyPlatform questions
No. Sentinel streams normalised OCSF records to Splunk, Microsoft Sentinel, Elastic, Chronicle, Snowflake and S3-compatible lakes, so your SIEM keeps its compliance and log-of-record role. In practice most customers reduce SIEM ingest by 50–70% because the raw endpoint and network firehose no longer needs to land there to be useful.
The on-device models — static classification, behavioural sequence analysis, ransomware canary monitoring and script-behaviour analysis — run entirely locally and can block and quarantine with no network at all. Cross-surface correlation and the AI Analyst narrative require the control plane, and queue locally until the host reconnects. See endpoint security for the full offline behaviour matrix.
Yes. Custom detections are authored in Sentinel Query Language, version-controlled in your own Git repository and promoted through dev, staging and production tenants via the API. Sigma rules import natively, and you can unit-test detections against recorded telemetry before promotion.
You can export the full normalised fabric as OCSF-formatted Parquet at any time, at no charge, through the bulk export API. Guardian does not hold your telemetry hostage as a retention mechanism — the contractual export window is 90 days after termination.
Every model release is shadow-scored against 30 days of your own telemetry before it takes effect, and the projected change in alert volume is shown in the console prior to promotion. You choose automatic, staged or manual promotion per detection family, and can roll back to any prior model version for 180 days.
Yes. Guardian MDR operates the platform on your behalf with a three-minute triage SLA and named analysts, and incident response is available on retainer with a one-hour engagement commitment. Both operate inside your tenant, so you keep full visibility of every action taken.
More answers in the support FAQ and the security glossary.
A 45-minute technical walkthrough with a Guardian solutions architect — architecture, detection quality, deployment shape and a modelled cost comparison against what you run today.