R-Vision Endpoint by R-Vision is a key component of the R-Vision EVO ecosystem, enhancing the capabilities of other technologies and providing additional benefits from their use. It consists of a management server and agents installed on endpoints, such as workstations and servers, regardless of the operating system type. Agents collect information from hosts and execute commands from the management server. The management server is the single point of integration with other products in the R-Vision EVO ecosystem. R-Vision Endpoint enhances the inventory capabilities of R-Vision SOAR and R-Vision SGRC by allowing the obtaining of information about changes in hardware and software configurations of devices without privileged access, promptly transmitting information about changes on endpoints to the server automatically, and expanding the range of inventory assets by searching and inventorying devices, including those outside of NAT/VPN. All information security events, application software events, system events, and related telemetry are transmitted from endpoints to R-Vision Log Management (R-Vision LM) for normalization, analysis, and storage. Events that utilized specific techniques and tactics from the MITRE ATT&CK matrix are tagged to expedite the investigation process. Events related to system and user behavior are sent to R-Vision User and Entity Behavior Analytics (R-Vision UEBA) to identify violations in the state of IT and information security systems. Information about vulnerable software collected from endpoints is sent to R-Vision Vulnerability Management (R-Vision VM) for prioritization and remediation control of vulnerabilities. Hash sums of malicious files on hosts are compared with the database of indicators of compromise from R-Vision Threat Intelligence Platform (R-Vision TIP), enriched with additional context related to the malicious entity, and transmitted to R-Vision SOAR for response actions. R-Vision SOAR simplifies incident response on hosts with R-Vision Endpoint, enabling manual and automated actions on endpoints. Technical audit of information security with R-Vision SGRC collects security parameter settings from operating systems and application software automatically for compliance auditing with information security standards. R-Vision Endpoint supports checks for most popular OS types (Windows, Linux, MacOS) and software. R-Vision Endpoint allows deploying decoys created in R-Vision Threat Deception Platform (R-Vision TDP) agent-based, regardless of the type of operating systems on the endpoint. Baits can include configuration files of popular administration utilities, data files, user accounts, saved credentials in browsers, SSH keys, and database connection credentials. Agents installed on protected hosts will simplify the management of false infrastructure, transmit data for analyzing the actions of attackers to R-Vision TDP, and carry out the process of digital hygiene on end devices.