Reagent Docs

EDR

Connect CrowdStrike, SentinelOne, or Microsoft Defender for Endpoint so Reagent can see the AI apps, local models, coding agents, and MCP servers running on managed devices, and contain a host when it has to.

EDR is the second recommended connection after identity. Endpoint telemetry is the only place several AI surfaces are visible at all: installed AI desktop apps, local LLM runtimes, IDE coding agents and the MCP servers they spawn, AI libraries imported by first-party code, agent skills, and local model weight files. On the Connections page, EDR is section 02. Connect whichever of the three tiles below matches your endpoint platform.

CrowdStrike

Connector: crowdstrike-falcon-v3 · Auth: OAuth 2.0 client credentials · Requires: any Falcon tenant. The shadow-AI endpoint discovery signals need the Falcon Discover scope where your tenant is licensed for it. Flight Control is needed only on MSSP parents.

Reagent reads host and application inventory from Falcon and runs read-only Real Time Response sweeps across managed devices to find AI software that is not visible anywhere else. It also reads Falcon alerts for correlation in Monitor and can contain a host when you ask it to.

Lights up: AI Desktop Apps, Local LLM Runtimes on Hosts, IDE Coding Agents, MCP Servers (Local), Embedded AI SDKs & Frameworks, Agent Skills, Agent Startup Context Ledger, Agent Configuration Posture, Local Model Artifacts, AI IDE Extensions, AI CLI Tools. Reagent can also contain a host as a response action from Monitor.

All of these signals come from Real Time Response sweeps. Each sweep ships as a template pack. It deploys paused and does not run until it is confirmed for your environment. A sweep reads the process and application inventory, installed Python and Node package names, SKILL.md paths, config-file hashes, model-weight file hashes, extension directory names, and bin directory names. It never reads file contents.

The sweeps are read-only on the host, but they need a Write tick in Falcon: the batch RTR script runs under Real time response (admin), which has no Read tick, plus Read and Write on Real time response. An API client with only Read on the RTR rows produces no shadow-AI signals.

Before you start

  • You need the manage integrations permission in Reagent (Administrator, MSSP Admin, or a custom role with it).
  • You need administrative credentials for the Falcon console to create an API client.
  • Any Falcon tenant works. If you are licensed for Falcon Discover, tick its scope so the shadow-AI endpoint discovery signals have inventory to read.
  • MSSP / Flight Control parents only: create the API client on the parent CID with the Flight Control scope, then either leave Member CID blank to authenticate as the parent or set it to a child CID.

Setup

  1. Log in to falcon.crowdstrike.com with administrative credentials.
  2. Go to Support and resources > API Clients and Keys.
  3. Note the Base URL shown above the API Clients table. You will pick the matching value in the API URL dropdown in Reagent.
  4. Click Add new API client. Set a name (for example Zaun API) and a description.
  5. Assign the API scopes (see Permissions below), then click Add or Create.
  6. Copy the Client ID and Client Secret immediately. The secret is shown only once.
  7. In Reagent, open Connections, click the CrowdStrike tile, select the API URL that matches your Base URL, paste the Client ID and Client Secret, and save.

Leave Member CID blank for a single-tenant setup. Set it only when you are authenticating against a specific child tenant from an MSSP / Flight Control parent.

Pick the API URL that matches your Falcon console region. It must match the Base URL shown above the API Clients table.

API URLRegion
api.crowdstrike.comCommercial US
api.us-2.crowdstrike.comCommercial US-2
api.eu-1.crowdstrike.comEU
api.laggar.gcw.crowdstrike.comUS GovCloud
api.us-gov-2.crowdstrike.milUS Gov-2

Permissions

CrowdStrike enforces scopes per endpoint family. A missing scope returns 403 access denied, scope not permitted only on the affected operations. Everything else keeps working, so gaps are easy to miss. Tick the full list on the first pass.

The rows below are in the same order the Falcon "Add new API client" scope table shows them. Go straight down that table and tick Read and Write where marked. Any scope not listed can be left unchecked. Rows marked with a dagger only appear in the Falcon scope search if your tenant is licensed for that module, and the Connections page hides them until then.

GroupScope (Falcon label)ReadWriteUsed for
Required, coreAlertsYesYesTriage alerts; update status, tags, and assignment
Recommended †Configuration AssessmentYesNoConfiguration-posture enrichment
Required, coreDetectionsYesYesRead detections; update detection status
Recommended †Device control policiesYesNoDevice-control policy context
Required, coreEvent streamsYesNoReal-time alert streaming
Required for Shadow-AI †Falcon DiscoverYesNoShadow-AI discovery: installed AI apps and local LLM runtimes
Recommended †Falcon External Attack SurfaceYesNoExposure Management and external assets
RecommendedFirewall managementYesNoFirewall-policy context
MSSP only †Flight ControlYesNoEnumerate child tenants from an MSSP parent
RecommendedHost groupsYesNoHost-group context in investigations
Required, coreHostsYesYesDevice inventory and details; network containment and lift
Required, coreIncidentsYesYesRead incidents and behaviors; status, assignment, comments
Required, coreIOC ManagementYesYesCustom IOC API
Required, coreIOCs (Indicators of Compromise)YesNoLegacy IOC scope: ran-on and process pivots
RecommendedPrevention policiesYesNoPrevention-policy lookup
RecommendedQuarantined FilesYesYesInspect and release or delete quarantined files
Required, coreReal time responseYesYesRTR sessions and commands (evidence, response)
Required for Shadow-AIReal time response (admin)NoYesBatch RTR: the shadow-AI endpoint sweep and batch response
RecommendedResponse policiesYesNoResponse-policy lookup
OptionalSensor DownloadYesNoSensor downloads (rarely used by Reagent)
RecommendedSensor update policiesYesNoSensor-update-policy lookup
Recommended †Spotlight vulnerabilitiesYesNoVulnerability enrichment for affected hosts
Required, coreThreatgraphYesNoProcess-tree, lateral-movement, and entity-graph pivots
Required, coreUser managementYesNoResolve assignee and commenter identities
RecommendedZero Trust AssessmentYesNoZero Trust host-posture scores
  • Falcon Discover. Powers shadow-AI endpoint discovery. It appears in the Falcon scope search only if your tenant is licensed for it.
  • MSSP only. Flight Control lets Reagent enumerate child tenants. It appears in the scope search only on an MSSP / Flight Control parent CID. Single-tenant setups can ignore this row.
  • Least privilege. Skip any Recommended or Optional scope you will not use. Only its own endpoints return 403; unrelated operations keep working.
  • Changes are immediate. Scope changes take effect as soon as you save them in Falcon. You can add a scope later without regenerating the secret.

What Reagent reads

  • Host inventory and device details.
  • Application and process inventory, including Falcon Discover data where licensed.
  • Read-only Real Time Response sweep output: package names, file paths, directory names, and hashes as listed above. Never file contents.
  • Falcon alerts, for correlation in Monitor.
  • Host containment, as a response action you trigger from Monitor.

The Client Secret is shown only once, when the API client is created. Copy it immediately. Scope changes never require a new secret, so add scopes to the existing client rather than recreating it.


SentinelOne

Connector: sentinelone · Auth: API token in the Authorization header (ApiToken <token>) · Requires: any tenant. On MSP or Pax8-managed tenants, add-on roles must be requested through the MSP.

Reagent reads the endpoint and installed-application inventory from your SentinelOne console and queries Deep Visibility process and module telemetry for AI frameworks. With Remote Script Orchestration it can run a read-only package-inventory script instead. It also reads threats and can isolate an endpoint or mitigate a threat when you ask it to.

Lights up: AI Desktop Apps (from application inventory), and Local LLM Runtimes on Hosts and Embedded AI SDKs & Frameworks (from the read-only package-inventory sweep that Remote Script Orchestration runs). Every SentinelOne signal ships as a template pack: it deploys paused until confirmed for your environment. Reagent can also isolate endpoints and mitigate threats as response actions from Monitor when the token user holds the IR Team or Admin role.

Before you start

  • You need the manage integrations permission in Reagent (Administrator, MSSP Admin, or a custom role with it).
  • A SentinelOne user with at least the Viewer role. For response actions you need IR Team or Admin.
  • Recommended: a dedicated Service User rather than a personal token. Ask your SentinelOne admin to create one under Settings > Users > Service Users with the appropriate role.
  • Your management console URL. It is the domain you use to log in.
  • MSP or Pax8-managed tenants (usea1-pax8-*): request add-on roles through the MSP. Direct console role edits are usually disabled.

Setup

  1. Log in to your SentinelOne management console.
  2. Click your username (top-right) > My User.
  3. Scroll down to the API Token section.
  4. Click Generate (or Regenerate if a token already exists).
  5. Copy the token immediately. It is shown only once.
  6. In Reagent, open Connections, click the SentinelOne tile, enter the Management Console URL and the API token, and save.

Enter the console URL with or without https://. Common formats:

Console URLRegion
usea1-xxx.sentinelone.netUS East
usea1-xxx-mssp.sentinelone.netMSSP
euce1-xxx.sentinelone.netEU Central
apne1-xxx.sentinelone.netAP Northeast

Reagent sends the token as ApiToken <your-token> in the Authorization header.

Permissions

RolePurpose
ViewerMinimum for monitoring and investigation.
IR Team or AdminRequired for response actions: isolate endpoints, mitigate threats.

Add-on scopes are not included in Viewer, IR Team, or Admin by default. Grant them explicitly.

Add-on scopePurpose
Deep Visibility - ViewDeep Visibility queries (/dv/* endpoints) for threat-storyline correlation, and for embedded AI library discovery (process and module telemetry for AI frameworks). Missing it returns 403.
Application Risk / Application Inventory (read)Lists installed applications (applications.list). Feeds AI Desktop Apps and Local LLM Runtimes on Hosts. Usually included in Viewer; grant explicitly if your role is scoped down.
Remote Script Orchestration (RSO)Only needed for the clean embedded-AI-library endpoint walk: a read-only package-inventory script, the SentinelOne equivalent of CrowdStrike Real Time Response. Without it, library discovery falls back to the Deep Visibility query.
Threat IntelligenceIOC list and upload. A tenant-specific type enum applies; some tenants reject sha256, sha1, and ip with 400.

What Reagent reads

  • Agent and endpoint inventory.
  • Installed applications (applications.list).
  • Deep Visibility process and module telemetry, filtered for AI frameworks.
  • Read-only package inventory through Remote Script Orchestration, when granted.
  • Threats, for correlation in Monitor.
  • IOC lists, when Threat Intelligence is granted.

The API token is shown only once, when you generate it. Copy it immediately. On MSP or Pax8-managed tenants (usea1-pax8-*), direct console role edits are usually disabled, so request add-on roles through the MSP before you connect.


Microsoft Defender for Endpoint

Connector: microsoft-graph · Auth: shared with Microsoft Graph · Requires: a Defender for Endpoint license: Microsoft 365 Business Premium, E5, or E3 with a Defender for Endpoint P2 or Defender for Business add-on (the "Microsoft 365 with Defender" tier)

This tile uses the same credential as Microsoft Graph. It shows connected whenever Microsoft Graph is connected, on any tier. What needs the Defender license and permission is the software-inventory read behind the discovery signal: without them the tile still shows connected and the signal returns nothing.

Reagent reads the Defender software inventory for your managed devices and lists the AI desktop apps installed on them.

Lights up: AI Desktop Apps, via the Defender software inventory. This signal is live-validated.

Before you start

  • You need the manage integrations permission in Reagent (Administrator, MSSP Admin, or a custom role with it).
  • A Microsoft 365 license that includes Defender for Endpoint: Business Premium, E5, or E3 with a Defender for Endpoint P2 or Defender for Business add-on. Defender for Endpoint P1, included in E3, has no EDR or alert API surface. On the Business Standard tier the tile shows connected but the AI Desktop Apps signal returns nothing.
  • If you bring your own Azure app, a Global Administrator to run the generated setup script and to grant admin consent.

Setup

  1. Open the Identity provider page and follow the Microsoft Graph steps there. The same connection serves both tiles.
  2. Zaun-managed app: choose the Microsoft 365 with Defender tier when you grant consent.
  3. Bring your own Azure app: include the Defender capabilities when you select capabilities. The generated script requests the Defender read permissions (Machine.Read.All, Alert.Read.All, Vulnerability.Read.All). The software-inventory read behind the AI Desktop Apps signal also needs the WindowsDefenderATP application permission Software.Read.All, which the capability picker does not include. Add it in the Azure Portal under the app's API permissions (the "Prefer to configure manually?" section on the Connections page links there), then grant admin consent again.
  4. Save the Microsoft Graph connection. The Microsoft Defender for Endpoint tile reads the same credential. There is nothing to enter on this tile.

To change the permission tier or capabilities later, delete the existing Microsoft Graph credential and reconnect. Activating a new app replaces the environment's existing Microsoft Graph connection.