Complete Endpoint Inventory, Collected Automatically
Hardware, software, browser extensions, repositories, and dependencies - refreshed on a schedule with no manual scanning and no agent configuration.
Hardware and Software, Every Six Hours
Hardware collection covers CPU model, core count, total RAM, total disk, serial number, OS version, boot time, and every network interface with MAC address and IP assignment - collected automatically, with no extra tooling required.
Software sources by platform
| Platform | Sources |
|---|---|
| macOS | Installed applications plus Homebrew packages |
| Windows | Every installed program, 64-bit and 32-bit |
| Linux | dpkg, RPM, or snap - whichever is present |
Device identity and multi-user hosts
Devices are identified by a stable hardware ID, so reinstalling the agent does not create a duplicate device record. Adoption and merge flows reconcile records created before hardware identity existed, and collectors are multi-user aware - a root-service agent captures AI sessions for every user account on the host, not just the service account's home directory.
Risk-Classified by Permission Surface
Chrome, Edge, Brave, Arc, and Firefox extensions are scanned every two hours and classified by the permissions they request.
| Risk | What the extension can do |
|---|---|
| HIGH | Read or modify data on every site, intercept network traffic, or control the browser |
| MEDIUM | Access cookies, browsing history, the clipboard, or downloads |
| LOW | Everything else |
- Fleet view lists every extension with browser, risk badge, device count, and permission breakdown
- Extensions can be marked Allowed, Under Review, or Blocked
- Alerts fire automatically the first time a HIGH-risk extension appears anywhere in the fleet
Attribute AI Activity to a Repo
Git repositories on managed endpoints are discovered and mapped to their remotes, so AI activity can be attributed to a repository and AI Profiles can be assigned per-repo - letting a payments repository carry stricter guardrails than a marketing site.
What the Agent Installed
- Dependency monitoring across 9 package formats
- Automatic checks for known vulnerabilities in discovered packages
- Detection of packages introduced by AI agents specifically
- Policy can block installs of packages with known CVEs outright


Controls This Pillar Satisfies
- ISO A.5.9
- Inventory of information and other associated assets
- NIST CM-8
- System component inventory - hardware, software, extensions, AI tools
- NIST CM-11
- User-installed software - extension and package controls
- SOC 2 CC6.8
- Unauthorized software controls via extension risk classification
See Kraitos AIDR in Action
Deploy in 60 seconds. Get answers in 24 hours. Stop guessing what your AI-augmented organization is doing.
[email protected]kraitos.io