Aegis

Aegis inventory, enrollment, and health.

Aegis

Aegis is an endpoint daemon inside your network so Guard can see internal assets (Active Directory, internal services, file shares). It is not Hannibal; hunt testing logs live under Attacks.

Empty state: No Aegis Endpoints Found. Description: Install the Linux agent on a host, then approve its enrollment code. CTA Set Up Endpoint requires manage_endpoints.

When the table has rows, use Add Endpoint (same entitlement). Manage Credentials is outline and only appears when rows exist.

Endpoints table with Add Endpoint and mixed Aegis V1 rows (dark mode)

Install: Aegis Installation.

Connection for V2: online, not_connected, or revoked. Health summaries come from the server (healthy / warning / unknown). Click a V2 row for Overview and Health. Control and revoke are Praetorian-only.

V2 inventory is not gated on being a Praetorian user. Anyone with read access can see the table.

Legacy Velociraptor (Aegis V1) rows can still appear in the same table. Do not use V1 installers for new hosts. V1 installers do not install V2.