Platform capability · ArmorPoint Agent

The ArmorPoint Agent is where your visibility starts.

Most of what the platform knows about your environment, it learns from this agent. One install on Windows, Linux, or macOS streams logs, events, processes, performance, and user activity into the same pipeline your SOC works from. The same install registers the machine as the authoritative record in your asset inventory and reports its vulnerabilities as CVEs every day, with no scanner appliance in the way.

ArmorPoint Agents
Live
142
Agents reporting
Windows 96 Linux 31 macOS 15
CVEs reported today · no scanner appliance
Critical6
High17
Medium33
Low24
Refreshed every 24 hours from the agent itself. Partners see every agent across every customer in one table.
What one install does

Four jobs that usually take four tools, done by the same agent.

Collection, inventory, vulnerability reporting, and deeper monitoring are not four products here. They are four outputs of one install, which is why there is no second agent to deploy and no scanner appliance to rack.

Collect

Telemetry the SOC runs on

Logs and operating system events, USB activity, system performance, and process-level behavior stream into one pipeline. This is the platform's primary source of environment data, not a supplementary feed.

Inventory

The authoritative asset record

Installing an agent populates the unified asset inventory automatically. Everything your other tools report is matched back against that record, so one machine never shows up as three assets.

Assess

Vulnerabilities without a scanner

The agent reports operating system and third-party application vulnerabilities on all three operating systems, as CVEs, checked daily, and drops them when the patch lands.

Monitor

Depth assigned by role

File integrity monitoring, user activity monitoring, Active Directory monitoring, and rogue device detection are switched on by the job a system does, not applied uniformly to everything.

Native vulnerability reporting

The agent that collects your logs also tells you what is unpatched on the machine.

The agent looks for missing patches and works backward to the vulnerability those patches close, and it inspects installed third-party applications for their own. Findings arrive as CVEs rather than scanner plugin identifiers, which means they read the same way your threat intelligence and your auditors do.

Vulnerability inventory filter · all sources
Finding Severity Source Affected
CVE-2026-21445 Critical ArmorPoint Agent 14 machines
CVE-2026-0198 High ArmorPoint Agent 3 machines
Plugin 189234 High Tenable Nessus 7 machines
CVE-2026-11007 Medium ArmorPoint Agent 22 machines
Agent findings arrive as CVEs. Scanner feeds keep their plugin grouping. Both live in one inventory.
  • Operating system and third-party application vulnerabilities, on Windows, Linux, and Mac
  • Checked daily, and a finding stops reporting once it is no longer there
  • Findings list per CVE with every affected machine grouped underneath
  • Consolidated with your existing scanners and EDR feeds in one inventory, filterable by source

If you already run Nessus, Qualys, or Rapid7, nothing gets thrown out. Their findings and the agent's land in the same inventory and the same report, and you can always see which source said what.

Source of truth

Every asset list you own gets checked against the agent's record.

Your EDR has a host list. Your identity provider has a device list. Your scanner has another. The platform reconciles them against the agent record on four attributes, and anything that does not line up cleanly waits in an unmatched view for a person to decide, rather than quietly becoming a duplicate asset.

Asset match

All four attributes match, so the records merge

One machine, reported by three tools, resolved to a single asset.

Hostname
WKS-4471
Domain
corp.internal
IP address
10.4.19.88
MAC address
3C:52:82:1A:9F:04

A partial match does not merge. It lands in the unmatched view, where you add it as new or link it to the asset you know it is.

Coverage

An asset counts as protected only when it runs the Agent and an EDR

The ArmorPoint Agent is a visibility layer, not a prevention layer, and the platform is built to say so. ArmorPoint does not make its own EDR. Blocking, quarantine, and isolation stay with CrowdStrike, SentinelOne, Cybereason, or Microsoft Defender, whichever you run.

Protected

Both halves reporting on the same asset record: the ArmorPoint Agent and any EDR.

Coverage gap

Either half missing. Overrides are supported with a documented reason.

Asset reviews run on a cycle you set, and the review history becomes compliance evidence without anyone assembling it.

Tags that travel

Tag a machine once by what it is worth, and every log it produces carries that context.

Business criticality usually lives in a spreadsheet nobody consults during an investigation. Here it is attached to the agent, so it rides along with the telemetry into dashboards, filters, alerts, and detection logic. An analyst seeing an alert knows immediately whether the host in it matters.

Tag the agent
WKS-4471 [ CRITICAL-ASSET ]
Every log it sends
process.create [ CRITICAL-ASSET ]
Every alert it raises
Suspicious execution [ CRITICAL-ASSET ]

Searchable in dashboards and filters, visible inside alerts, and usable in detections.

Monitoring depth

A domain controller and a shipping-floor workstation do not need the same agent behavior.

Capabilities are assigned by the role a system plays, so the machines that warrant deep inspection get it and the ones that cannot spare the overhead are not asked to. Every profile collects configuration data, performance, and operating system logs as a floor.

Process monitoring

Process-level behavioral monitoring on Windows systems.

User activity monitoring

What accounts are doing on the systems they touch.

File integrity monitoring

Changes to the files that are not supposed to change.

Audit monitoring

Linux AuditD events collected and searchable with everything else.

Active Directory monitoring

Synchronization and management activity on domain controllers.

Rogue device detection

Network scanning that surfaces devices running nothing at all.

Configuration data

Installed software, patches, services, and scheduled tasks.

Performance and OS logs

CPU, memory, and disk activity next to Windows events, Linux logs, and macOS logs.

Beyond the endpoints it is installed on

Turn a host into a syslog collector

Network gear, appliances, and anything else that speaks syslog can report through a machine already running the agent. No separate collector to buy, and switching a firewall vendor no longer means opening a ticket.

Agentless where you need it

Cover Windows systems through native forwarding

For machines that cannot take an install, the agent acts as a Windows Event Forwarding collector and picks up their events natively. Coverage does not have to stop at the systems you can touch.

Per-endpoint detail

Open any machine and the platform shows what is actually on it.

Eleven tabs per endpoint, each searchable, sortable, and exportable. This is the level of detail auditors ask for and the level engineers want before touching a production system.

Summary
Status, version, operating system, group, and registration.
Installed applications
Version, publisher, install date, and path.
Installed patches
What has been applied, with date and category.
Missing patches
What has not, with severity and CVE references.
Installed services
Display name, status, start type, and account.
Scheduled tasks
Status, last run, next run, and trigger.
Startup items
Entries from registry and folder locations.
Network interfaces
IP, MAC, status, gateway, and DNS configuration.
Local users
Status, last logon, and group memberships.
Audit policy settings
Policy categories and the flags configured.
Firewall rules
Direction, action, protocol, and profile.

Fleet-wide, the same data answers which version of an application is still deployed and where a patch has not landed.

Rollout

Start with a handful of machines, then broaden by role.

Deployment is deliberately unglamorous. Installers are a click away inside the platform, the fleet card confirms coverage as machines come online, and configuration follows the role a system plays rather than one setting applied to everything.

Install

One click, from the platform

Installers live in the Response Center panel, so a machine that needs coverage today gets it today.

Pilot

Prove it on a small set

Confirm collection and check for conflicts on a representative handful before the fleet-wide push.

Broaden

Configuration by role

Workstations, servers, and domain controllers each take the configuration that fits them, with lighter profiles for constrained systems.

Guided implementation is available if you would rather not run it yourself.

Onboarding covers profile design, phased rollout, and confirming that what should be reporting is reporting.

See Guided Implementation →
How the Agent fits with the rest

One source of truth, feeding everything else on the platform.

The agent's telemetry feeds detection and log search. Its inventory anchors the asset and identity surfaces. Its vulnerability findings consolidate with your scanners in one inventory, and its patch data proves remediation for audit. Everything else you connect, from EDR to firewall to cloud, is reconciled against the record the agent already established.

See it on your own endpoint

Bring one machine you think you already understand.

We will show you its installed software, its missing patches, its local accounts, and its open vulnerabilities, then show you the same telemetry landing in the Detection Hub live.