How it works
- Connect your EDR: provide a read-only API key to your EDR platform. Oso uses this to pull data from your endpoints.
- Automatic scanning: Oso scans managed devices for known agent software from the agent catalog, including desktop apps, CLI tools, and background processes.
- Continuous discovery: scanning runs continuously, so new installations are detected as they appear.
What it detects
Oso scans for agent binaries, NPM packages, and OS-packaged software across known installation paths:Desktop apps
Claude Desktop, Cursor, Antigravity, OpenClaw, Microsoft Copilot, GitHub Copilot, Kiro, WindsurfCLI tools
Claude Code, Codex, Gemini CLISupported platforms
EDR
- CrowdStrike
MDM
- JAMF
Support for additional EDR and MDM platforms is planned. If you use a platform not listed here, reach out to us to discuss your needs.
What appears in the inventory
Agents discovered via EDR appear in the same agent inventory as browser and proxy-discovered agents:| Column | Description |
|---|---|
| Agent | The agent name and environment type (Terminal, Desktop) |
| Devices | Which devices the agent was found on |
| Users | Users associated with those devices |
| Last Seen | When the agent was last detected on the endpoint |