Collect
eBPF, fanotify, netlink, and /proc observe execution, files, network, ptrace, modules, fork, and exit.
Linux security · SaaS platform · v2.3.1
Offline-first Linux Endpoint Detection and Response for teams that need visibility, evidence, and response — even when the network is unavailable.
Detect suspicious behavior locally, investigate process and file activity, and respond with policy-driven controls from a centralized security console.
console.sahmedr / overview● Protected●telemetrynetlink-proc
●eventexec /tmp/unknown
●scanhash + YARA + rules
●actionalert
suspicious_execution/tmp/unknown · execInvestigatefile_write_burstcontainer/web · anomalyReview01 · Live protection loop
The agent observes activity, adds Linux context, evaluates locally, and reports the result. Every stage is visible to the operator.
● telemetry: netlink-proc● event: exec /tmp/unknown● scan: hash + YARA + rules● action: alert● report: queued02 · Offline-first
The most important detection path is local. Detection, local storage, and configured response continue without cloud access. Events are retained locally and shipped later through a bounded retry spool.
Cloud coordination improves visibility without being required for the endpoint to protect itself.
03 · Architecture
Choose a layer to see how the endpoint plane, control plane, and human plane work together.
04 · Endpoint agent
It uses the best available Linux telemetry backend, falls back when necessary, and keeps the critical detection path local.
eBPF, fanotify, netlink, and /proc observe execution, files, network, ptrace, modules, fork, and exit.
Process trees, namespaces, cgroups, containers, pods, parents, and command context explain what happened.
Rules, anomaly windows, sequences, YARA, hashes, CVE data, threat intelligence, and optional AI.
Policy decides whether to log, alert, kill, quarantine, or isolate the host.
Evidence persists locally, then ships as bounded NDJSON to the central control plane.
05 · Deep Linux visibility
Generic alerts say what happened. Process lineage and Linux context help explain why it happened.
systemdPID 1 · rootnginxPID 712 · www-dataphp-fpmPID 924 · container:websuspicious.shPID 1402 · network connection06 · Detection engine
Local detection combines multiple signals. AI can add context, but it is never the foundation of protection.
VirusTotalMalwareBazaarOTXOSV.devNVD07 · Response
Start with observation, validate policy, and enforce only when your team understands the result.
/tmp/unknownnginx08 · Multi-tenant SaaS
Organizations, agents, credentials, entitlements, commands, and audit history stay separated in the control plane.
linux-prod-01onlinelease validlinux-prod-02onlinelease validlinux-stage-01offlinelocal modeedge-node-01onlinelease validedge-node-02restrictedlocal mode09 · Client journey
A client can begin with one Linux machine and expand into a managed fleet.
$ sudo sahmedr login Device code: XXXX-XXXX Waiting for approval... ✓ Device approved ✓ Identity created ✓ Agent enrolled $ sudo systemctl enable --now sahmedr ✓ SahmEDR running · protection active
10 · AI enrichment
AI helps analysts summarize evidence, analyze files, pentest results, and posture reports. Core detection and response remain independent of the provider.
11 · Daily operations
The console turns raw endpoint activity into a repeatable security workflow.
12 · Security architecture
Local controls and cloud controls work together so a lost connection or compromised credential does not automatically become total compromise.
13 · Threat coverage
Use EDR as a strong layer in a broader security program.
14 · Quick start
Install the current signed release, enroll the host, then manage it from the portal.
# Enroll $ sudo sahmedr login # Start at boot $ sudo systemctl enable --now sahmedr # Verify $ sahmedr status ✓ Enrolled ✓ Service running ✓ Protection active
15 · Pricing
Every plan begins with a 14-day trial. Actual plan limits and entitlements are loaded from the control plane.
16 · FAQ
No. Core telemetry, local detection, SQLite evidence, and configured response continue. Events wait in the bounded spool and retry when connectivity returns.
Only SahmEDR project management configures the UnoRouter provider on the SaaS control server. Customers and enrolled agents never receive provider keys.
No. SahmEDR uses its managed UnoRouter partnership/provider configuration so analysis quality, cost controls, and credential security stay centrally governed.
Begin with dry-run mode, review detections and reports, tune policy, then enable enforcement when the behavior is understood.
An organization is the tenant. An agent is one enrolled Linux host inside that tenant, with its own identity, authorization lease, events, and revocation state.
SahmEDR · Linux security, understood
Enroll one Linux host, start in dry-run, and expand when your security policy is trusted.