Endpoints
The Endpoints page: Aegis inventory, enrollment, and health.
Endpoints
Endpoints (sidebar) is the Aegis page. It is a single table of V1 and V2 endpoints. There are no Aegis V1 / Aegis V2 page tabs.
Aegis is not the AI assistant. It is a Linux daemon on a host you control so Guard can reach assets its own compute cannot: private networks, internal DNS, Active Directory, file shares. The host still needs outbound Guard HTTPS and Cloudflare 7844 — see Aegis V2 Installation. Planning stays in Guard; execution runs on the endpoint. It is not Hannibal; hunt testing logs live under Attacks.
Use Aegis when the target is unreachable from Guard compute. If Guard can already reach the asset, you do not need an endpoint.
The daemon is outbound-only (no inbound ports). It pulls digest-pinned capability containers with short-lived credentials and can self-update from Guard (atomic swap, previous binary kept for rollback).
Once enrolled, Guard can run internal work through that host: Internal Hunt (Hannibal — pick the endpoint when you create the hunt), Resolver (DNS via the host’s resolver, including private addresses), Titus (secrets inside the perimeter), plus fingerprinting, Nuclei, and AD reconnaissance.
Empty state: No Aegis Endpoints Found. Description: Install the Linux agent on a host, then approve its enrollment code. CTA Set Up Endpoint requires manage_endpoints.
When the table has rows, use Add Endpoint (same entitlement). Manage Credentials is outline and only appears when rows exist.

Connection for V2: online, not_connected, or revoked. Health summaries come from the server (healthy / warning / unknown). Click a V2 row for Overview and Health. Control and revoke are Praetorian-only.
V2 inventory is not gated on being a Praetorian user. Anyone with read access can see the table.
Legacy Velociraptor (Aegis V1) rows can still appear in the same table. Do not use V1 installers for new hosts. V1 installers do not install V2.