Linux security · SaaS platform · v2.3.1

See the threat.
Stop the damage.

Offline-first Linux Endpoint Detection and Response for teams that need visibility, evidence, and response — even when the network is unavailable.

Detect suspicious behavior locally, investigate process and file activity, and respond with policy-driven controls from a centralized security console.

Local detection Signed leases Managed UnoRouter AI
console.sahmedr / overview● Protected
SECURITY CONSOLE / SYSTEM OVERVIEW

Good morning, security team

LIVE
AGENT STATUSProtected● online
CONTROL PLANEConnected● HTTPS
RESPONSE MODEDry-runobserve only
AI PROVIDERUnoRouter● managed
Event activitylast 30 min · local stream
−30m−15mnow
Live event stream receiving

telemetrynetlink-proc

eventexec /tmp/unknown

scanhash + YARA + rules

actionalert

Recent detectionsview all →
HIGHsuspicious_execution/tmp/unknown · execInvestigate
MEDfile_write_burstcontainer/web · anomalyReview
Host statusdetails →
linux-prod-01onlinelease valid
linux-prod-02onlinelease valid
Local firstCore protection survives offline periods.
Evidence firstEvents, lineage, rules, and actions stay auditable.
Policy controlledObserve safely, then enforce with confidence.

01 · Live protection loop

From telemetry to evidence.

The agent observes activity, adds Linux context, evaluates locally, and reports the result. Every stage is visible to the operator.

01TelemetryeBPF · fanotify
netlink · /proc
02Local eventprocess · file
network · container
03Detectionrules · YARA
anomaly · sequence
04Responselog · alert
kill · isolate
05EvidenceSQLite · NDJSON
central console
LIVE PROTECTION LOOP
● telemetry: netlink-proc● event: exec /tmp/unknown● scan: hash + YARA + rules● action: alert● report: queued

02 · Offline-first

Security that stays useful when the network does not.

The most important detection path is local. Detection, local storage, and configured response continue without cloud access. Events are retained locally and shipped later through a bounded retry spool.

INTERNET ×
S
SAHMEDR AGENTlocal protection active
✓ Detection✓ Storage✓ Response
connection restored
Buffered
events
HTTPS
ingestion
Central
console

Cloud coordination improves visibility without being required for the endpoint to protect itself.

03 · Architecture

Three layers. Clear ownership.

Choose a layer to see how the endpoint plane, control plane, and human plane work together.

Human planeAccount sessions, organization management, device approval, settings, reports, downloads, and subscription workflows.

04 · Endpoint agent

The agent is the protective core.

It uses the best available Linux telemetry backend, falls back when necessary, and keeps the critical detection path local.

01

Collect

eBPF, fanotify, netlink, and /proc observe execution, files, network, ptrace, modules, fork, and exit.

event.source = netlink-proc
02

Context

Process trees, namespaces, cgroups, containers, pods, parents, and command context explain what happened.

lineage = nginx › php-fpm › shell
03

Detect

Rules, anomaly windows, sequences, YARA, hashes, CVE data, threat intelligence, and optional AI.

verdict = SUSPICIOUS
04

Respond

Policy decides whether to log, alert, kill, quarantine, or isolate the host.

policy = dry_run
05

Report

Evidence persists locally, then ships as bounded NDJSON to the central control plane.

ship = queued → HTTPS

05 · Deep Linux visibility

Understand what led to the event.

Generic alerts say what happened. Process lineage and Linux context help explain why it happened.

PIDPPIDUIDCONTAINERNAMESPACECGROUPNETWORK
PROCESS LINEAGE● captured
SsystemdPID 1 · root
NnginxPID 712 · www-data
Pphp-fpmPID 924 · container:web
!suspicious.shPID 1402 · network connection

06 · Detection engine

Detect behavior, not just files.

Local detection combines multiple signals. AI can add context, but it is never the foundation of protection.

LOCAL RULESpath · chain · expression
+
ANOMALIESbursts · fan-out · storms
+
SEQUENCESmulti-event behavior
+
YARAcontent scanning
+
HASH + CVEreputation · packages
+
OPTIONAL AItriage enrichment
THREAT INTELLIGENCEVirusTotalMalwareBazaarOTXOSV.devNVD

07 · Response

From detection to response.

Start with observation, validate policy, and enforce only when your team understands the result.

DETECTIONSuspicious process
POLICYHigh severity
DECISIONWould quarantine
QUARANTINE
HIGH SEVERITYINCIDENT / 0042

Suspicious process detected

Process
/tmp/unknown
Parent
nginx
Action
Quarantine
Status
Would execute in enforcement
RESPONSE MODE

08 · Multi-tenant SaaS

One console. Isolated organizations.

Organizations, agents, credentials, entitlements, commands, and audit history stay separated in the control plane.

AOrganization A3 enrolled agents● active
linux-prod-01onlinelease valid
linux-prod-02onlinelease valid
linux-stage-01offlinelocal mode
per-agentidentitysigned leasesaudit
BOrganization B2 enrolled agents● active
edge-node-01onlinelease valid
edge-node-02restrictedlocal mode

09 · Client journey

From signup to protected host.

A client can begin with one Linux machine and expand into a managed fleet.

01Create accountChoose an organization and plan.
02Install agentDownload the signed package.
03Enroll hostApprove the device code.
04OperateInvestigate and respond.
$ sudo sahmedr login
Device code: XXXX-XXXX
Waiting for approval...
✓ Device approved
✓ Identity created
✓ Agent enrolled
$ sudo systemctl enable --now sahmedr
✓ SahmEDR running · protection active

10 · AI enrichment

AI enrichment without AI dependency.

AI helps analysts summarize evidence, analyze files, pentest results, and posture reports. Core detection and response remain independent of the provider.

EVIDENCEevents · hashes · lineage
Core detectionrules · response
AI enrichmentexplanation · context · summary
ANALYST VIEWauditable report
CONSISTENT ANALYSIS · OPENAIgpt-5.6-lunafixed model

11 · Daily operations

Investigate. Decide. Respond. Learn.

The console turns raw endpoint activity into a repeatable security workflow.

01Check agent healthonline · offline · restricted
02Filter detectionsseverity · host · time
03Inspect lineageprocess · file · network
04Review evidencehash · rule · events
05Choose responsepolicy · action · audit

12 · Security architecture

Reduce blast radius by design.

Local controls and cloud controls work together so a lost connection or compromised credential does not automatically become total compromise.

01

On the host

  • Root-only identity
  • Local SQLite evidence
  • Binary and rule integrity checks
  • Watchdog and telemetry fallbacks
02

In transit

  • HTTPS transport
  • Per-agent authentication
  • Bounded ingestion
  • Command expiry and HMAC verification
03

Control plane

  • Tenant separation
  • Signed authorization leases
  • Audit logging
  • Server-held provider keys
Security is a system, not a single product.SahmEDR complements patching, backups, identity controls, network segmentation, and human incident response.

13 · Threat coverage

Signals worth investigating.

Use EDR as a strong layer in a broader security program.

✓ Malicious execution✓ Suspicious process chains✓ Reverse shells✓ Mass file-write bursts✓ Credential access patterns✓ Known malware hashes✓ Vulnerable packages✓ EDR tampering

14 · Quick start

A Linux host can be operational in minutes.

Install the current signed release, enroll the host, then manage it from the portal.

# Enroll
$ sudo sahmedr login

# Start at boot
$ sudo systemctl enable --now sahmedr

# Verify
$ sahmedr status
✓ Enrolled  ✓ Service running  ✓ Protection active

15 · Pricing

Start with one host. Grow with your fleet.

Every plan begins with a 14-day trial. Actual plan limits and entitlements are loaded from the control plane.

Advanced

$24.99/month
  • 100 protected agents
  • 365-day detection retention
  • AI investigation quota
  • Remote response and reports
Start free trial →

16 · FAQ

Built for practical security teams.

Does the agent stop working when the internet is down?

No. Core telemetry, local detection, SQLite evidence, and configured response continue. Events wait in the bounded spool and retry when connectivity returns.

Where is the AI provider key configured?

Only SahmEDR project management configures the UnoRouter provider on the SaaS control server. Customers and enrolled agents never receive provider keys.

Can clients change the AI provider?

No. SahmEDR uses its managed UnoRouter partnership/provider configuration so analysis quality, cost controls, and credential security stay centrally governed.

How should response be deployed safely?

Begin with dry-run mode, review detections and reports, tune policy, then enable enforcement when the behavior is understood.

What is the difference between an agent and an organization?

An organization is the tenant. An agent is one enrolled Linux host inside that tenant, with its own identity, authorization lease, events, and revocation state.

SahmEDR · Linux security, understood

Protect the host.
Understand the evidence.

Enroll one Linux host, start in dry-run, and expand when your security policy is trusted.