A cloud-managed endpoint protection and detection agent that inspects files and process behaviour on the devices it is installed on. It blocks known-malicious files by reputation, watches running activity for attack patterns, and continuously records endpoint telemetry so an analyst can reconstruct what a threat did after the fact. Detections, investigation, and response actions such as host isolation are driven from a cloud console.