Endpoint discovery (EDR)Overview

EDR Discovery

EDR Discovery imports read-only AI agent evidence from CrowdStrike and SentinelOne into AgentKeeper AI Discovery.

EDR Discovery imports read-only AI agent evidence from CrowdStrike and SentinelOne into AgentKeeper AI Discovery.

Use it when you want a quick inventory of installed or recently observed AI agents before every workstation has runtime hooks, browser extension capture, or gateway routing.

Where It Appears

Configure the connector in Settings -> Connectors -> Endpoint Discovery (EDR).

Review results in AI Discovery:

  • Catalog shows known AI agents AgentKeeper recognizes.
  • Discovered shows EDR-observed agents with endpoint, user, confidence, source, and last-seen context.
  • Review uses the same approval, unsanctioned, accepted-risk, and not-AI workflow as other AI Discovery sources.

Inventory stays focused on workstation and asset posture. EDR agent discoveries enrich AI Discovery rather than changing the Inventory tabs.

Supported Providers

ProviderSetup guidePrimary evidence
CrowdStrikeCrowdStrike EDR DiscoveryFalcon hosts, optional application inventory, and read-only RTR scan paths
SentinelOneSentinelOne EDR DiscoveryEndpoint seed data, optional installed applications, and Singularity Data Lake events

What AgentKeeper Stores

AgentKeeper stores normalized security evidence only:

  • provider name;
  • endpoint ID, hostname, platform, last user, and last-seen time;
  • recognized AI agent name and catalog slug;
  • evidence type, such as installed application, package, file, or process;
  • evidence indicator, version when available, confidence, and timestamps;
  • scan run counts and error classes.

AgentKeeper does not store prompt content, file contents, raw Real Time Response output, raw Singularity Data Lake payloads, API tokens, client secrets, or bearer tokens.

Scan Behavior

V1 supports manual sync from Settings. Scheduled sync should be enabled after sandbox validation.

Each sync:

  1. Tests encrypted provider credentials server-side.
  2. Reads endpoint inventory from the provider.
  3. Attempts provider application inventory where available.
  4. Uses provider-specific discovery paths for AI agent indicators.
  5. Upserts normalized observations.
  6. Marks missing observations stale instead of deleting them.
  7. Emits low-volume promptless Activity events for new or changed discoveries.

Agent Catalog

The V1 catalog recognizes common AI agent and AI productivity surfaces, including Claude Code, Claude Desktop, Cursor, Codex, Gemini CLI, GitHub Copilot, Microsoft Copilot, Windsurf, Antigravity, Kiro, ChatGPT, Claude.ai, DeepSeek, Cohere, OpenClaw, and Anthropic SDK evidence.

Troubleshooting

SymptomCheck
Test failsConfirm provider credentials, region or console URL, API scopes, and outbound access from AgentKeeper to the provider API.
Sync imports endpoints but no agentsConfirm the provider account has application inventory or event-search coverage for the selected hosts. Some SentinelOne Data Lake evidence depends on recent activity.
Hosts are missingCheck the optional host filter. Start without a filter, then narrow it once data appears.
Status is partialSome endpoints were offline, failed, or the optional application inventory API was unavailable. Review the last run counts in Settings.
Results are staleRun manual sync again and confirm the EDR still reports the endpoint and indicator.