EDR Discovery
EDR Discovery imports read-only AI agent evidence from CrowdStrike and SentinelOne into AgentKeeper AI Discovery.
EDR Discovery imports read-only AI agent evidence from CrowdStrike and SentinelOne into AgentKeeper AI Discovery.
Use it when you want a quick inventory of installed or recently observed AI agents before every workstation has runtime hooks, browser extension capture, or gateway routing.
Where It Appears
Configure the connector in Settings -> Connectors -> Endpoint Discovery (EDR).
Review results in AI Discovery:
- Catalog shows known AI agents AgentKeeper recognizes.
- Discovered shows EDR-observed agents with endpoint, user, confidence, source, and last-seen context.
- Review uses the same approval, unsanctioned, accepted-risk, and not-AI workflow as other AI Discovery sources.
Inventory stays focused on workstation and asset posture. EDR agent discoveries enrich AI Discovery rather than changing the Inventory tabs.
Supported Providers
| Provider | Setup guide | Primary evidence |
|---|---|---|
| CrowdStrike | CrowdStrike EDR Discovery | Falcon hosts, optional application inventory, and read-only RTR scan paths |
| SentinelOne | SentinelOne EDR Discovery | Endpoint seed data, optional installed applications, and Singularity Data Lake events |
What AgentKeeper Stores
AgentKeeper stores normalized security evidence only:
- provider name;
- endpoint ID, hostname, platform, last user, and last-seen time;
- recognized AI agent name and catalog slug;
- evidence type, such as installed application, package, file, or process;
- evidence indicator, version when available, confidence, and timestamps;
- scan run counts and error classes.
AgentKeeper does not store prompt content, file contents, raw Real Time Response output, raw Singularity Data Lake payloads, API tokens, client secrets, or bearer tokens.
Scan Behavior
V1 supports manual sync from Settings. Scheduled sync should be enabled after sandbox validation.
Each sync:
- Tests encrypted provider credentials server-side.
- Reads endpoint inventory from the provider.
- Attempts provider application inventory where available.
- Uses provider-specific discovery paths for AI agent indicators.
- Upserts normalized observations.
- Marks missing observations stale instead of deleting them.
- Emits low-volume promptless Activity events for new or changed discoveries.
Agent Catalog
The V1 catalog recognizes common AI agent and AI productivity surfaces, including Claude Code, Claude Desktop, Cursor, Codex, Gemini CLI, GitHub Copilot, Microsoft Copilot, Windsurf, Antigravity, Kiro, ChatGPT, Claude.ai, DeepSeek, Cohere, OpenClaw, and Anthropic SDK evidence.
Troubleshooting
| Symptom | Check |
|---|---|
| Test fails | Confirm provider credentials, region or console URL, API scopes, and outbound access from AgentKeeper to the provider API. |
| Sync imports endpoints but no agents | Confirm the provider account has application inventory or event-search coverage for the selected hosts. Some SentinelOne Data Lake evidence depends on recent activity. |
| Hosts are missing | Check the optional host filter. Start without a filter, then narrow it once data appears. |
| Status is partial | Some endpoints were offline, failed, or the optional application inventory API was unavailable. Review the last run counts in Settings. |
| Results are stale | Run manual sync again and confirm the EDR still reports the endpoint and indicator. |