The ArmorPoint Agent is where your visibility starts.
Most of what the platform knows about your environment, it learns from this agent. One install on Windows, Linux, or macOS streams logs, events, processes, performance, and user activity into the same pipeline your SOC works from. The same install registers the machine as the authoritative record in your asset inventory and reports its vulnerabilities as CVEs every day, with no scanner appliance in the way.
Four jobs that usually take four tools, done by the same agent.
Collection, inventory, vulnerability reporting, and deeper monitoring are not four products here. They are four outputs of one install, which is why there is no second agent to deploy and no scanner appliance to rack.
Collect
Telemetry the SOC runs on
Logs and operating system events, USB activity, system performance, and process-level behavior stream into one pipeline. This is the platform's primary source of environment data, not a supplementary feed.
Inventory
The authoritative asset record
Installing an agent populates the unified asset inventory automatically. Everything your other tools report is matched back against that record, so one machine never shows up as three assets.
Assess
Vulnerabilities without a scanner
The agent reports operating system and third-party application vulnerabilities on all three operating systems, as CVEs, checked daily, and drops them when the patch lands.
Monitor
Depth assigned by role
File integrity monitoring, user activity monitoring, Active Directory monitoring, and rogue device detection are switched on by the job a system does, not applied uniformly to everything.
The agent that collects your logs also tells you what is unpatched on the machine.
The agent looks for missing patches and works backward to the vulnerability those patches close, and it inspects installed third-party applications for their own. Findings arrive as CVEs rather than scanner plugin identifiers, which means they read the same way your threat intelligence and your auditors do.
| Finding | Severity | Source | Affected |
|---|---|---|---|
| CVE-2026-21445 | Critical | ArmorPoint Agent | 14 machines |
| CVE-2026-0198 | High | ArmorPoint Agent | 3 machines |
| Plugin 189234 | High | Tenable Nessus | 7 machines |
| CVE-2026-11007 | Medium | ArmorPoint Agent | 22 machines |
- Operating system and third-party application vulnerabilities, on Windows, Linux, and Mac
- Checked daily, and a finding stops reporting once it is no longer there
- Findings list per CVE with every affected machine grouped underneath
- Consolidated with your existing scanners and EDR feeds in one inventory, filterable by source
If you already run Nessus, Qualys, or Rapid7, nothing gets thrown out. Their findings and the agent's land in the same inventory and the same report, and you can always see which source said what.
Every asset list you own gets checked against the agent's record.
Your EDR has a host list. Your identity provider has a device list. Your scanner has another. The platform reconciles them against the agent record on four attributes, and anything that does not line up cleanly waits in an unmatched view for a person to decide, rather than quietly becoming a duplicate asset.
All four attributes match, so the records merge
One machine, reported by three tools, resolved to a single asset.
A partial match does not merge. It lands in the unmatched view, where you add it as new or link it to the asset you know it is.
An asset counts as protected only when it runs the Agent and an EDR
The ArmorPoint Agent is a visibility layer, not a prevention layer, and the platform is built to say so. ArmorPoint does not make its own EDR. Blocking, quarantine, and isolation stay with CrowdStrike, SentinelOne, Cybereason, or Microsoft Defender, whichever you run.
Both halves reporting on the same asset record: the ArmorPoint Agent and any EDR.
Either half missing. Overrides are supported with a documented reason.
Asset reviews run on a cycle you set, and the review history becomes compliance evidence without anyone assembling it.
Tag a machine once by what it is worth, and every log it produces carries that context.
Business criticality usually lives in a spreadsheet nobody consults during an investigation. Here it is attached to the agent, so it rides along with the telemetry into dashboards, filters, alerts, and detection logic. An analyst seeing an alert knows immediately whether the host in it matters.
Searchable in dashboards and filters, visible inside alerts, and usable in detections.
A domain controller and a shipping-floor workstation do not need the same agent behavior.
Capabilities are assigned by the role a system plays, so the machines that warrant deep inspection get it and the ones that cannot spare the overhead are not asked to. Every profile collects configuration data, performance, and operating system logs as a floor.
Process monitoring
Process-level behavioral monitoring on Windows systems.
User activity monitoring
What accounts are doing on the systems they touch.
File integrity monitoring
Changes to the files that are not supposed to change.
Audit monitoring
Linux AuditD events collected and searchable with everything else.
Active Directory monitoring
Synchronization and management activity on domain controllers.
Rogue device detection
Network scanning that surfaces devices running nothing at all.
Configuration data
Installed software, patches, services, and scheduled tasks.
Performance and OS logs
CPU, memory, and disk activity next to Windows events, Linux logs, and macOS logs.
Turn a host into a syslog collector
Network gear, appliances, and anything else that speaks syslog can report through a machine already running the agent. No separate collector to buy, and switching a firewall vendor no longer means opening a ticket.
Cover Windows systems through native forwarding
For machines that cannot take an install, the agent acts as a Windows Event Forwarding collector and picks up their events natively. Coverage does not have to stop at the systems you can touch.
Open any machine and the platform shows what is actually on it.
Eleven tabs per endpoint, each searchable, sortable, and exportable. This is the level of detail auditors ask for and the level engineers want before touching a production system.
Fleet-wide, the same data answers which version of an application is still deployed and where a patch has not landed.
Start with a handful of machines, then broaden by role.
Deployment is deliberately unglamorous. Installers are a click away inside the platform, the fleet card confirms coverage as machines come online, and configuration follows the role a system plays rather than one setting applied to everything.
One click, from the platform
Installers live in the Response Center panel, so a machine that needs coverage today gets it today.
Prove it on a small set
Confirm collection and check for conflicts on a representative handful before the fleet-wide push.
Configuration by role
Workstations, servers, and domain controllers each take the configuration that fits them, with lighter profiles for constrained systems.
Onboarding covers profile design, phased rollout, and confirming that what should be reporting is reporting.
One source of truth, feeding everything else on the platform.
The agent's telemetry feeds detection and log search. Its inventory anchors the asset and identity surfaces. Its vulnerability findings consolidate with your scanners in one inventory, and its patch data proves remediation for audit. Everything else you connect, from EDR to firewall to cloud, is reconciled against the record the agent already established.
Bring one machine you think you already understand.
We will show you its installed software, its missing patches, its local accounts, and its open vulnerabilities, then show you the same telemetry landing in the Detection Hub live.