Perseus is an AI agent. The software agent is the program installed on
the host. Perseus drives that software agent to investigate and act — the two
share the word “agent” but are not the same thing.
Investigating a Host
Perseus can look closely at a single machine to understand what’s really happening on it — the running processes and their relationships, network connections, files, and the events the host has recorded. This is the detail you need to confirm whether an alert is real and to understand its scope before you respond.Response Actions
Once you know what you’re dealing with, Perseus carries out the response — always with your approval:Isolate the host
Cut a device off from the network to contain an incident while you work it.
Quarantine
Contain a malicious or suspicious file so it can no longer run.
Kill a process
Terminate a running process on the host.
Remediate
Clean up and apply fixes — run commands, manage services and users, and more.
Harden
Tighten a host’s configuration against best practice, feeding
Security Posture.
AI Proposes, You Approve
Anything Perseus does that changes a host is proposed for your approval first. You ask in chat — scoping to the machine with an@-mention — Perseus explains what it intends to do, and nothing runs on your device until you say so.
Perseus vs. Brontes
Perseus and Brontes are the two endpoint agents:- Perseus acts — investigates a host in depth and runs response actions on it.
- Brontes manages — tracks the health, configuration, and installed software of your registered assets.
Where to Go Next
Agent capabilities
The telemetry and response actions the software agent provides.
Device details & actions
Where you run and review actions on a single host.
Brontes
The endpoint manager that tracks your assets.
Centurion
The orchestrator that brings Perseus in.