What changed
Aegis has been released as an open-source Endpoint Detection and Response (EDR) tool specifically designed to monitor the local activities of autonomous AI agents. The tool focuses on providing visibility into agent processes, file system interactions, and network connections without the need for agents to integrate specific plugins. Its core functionality includes monitoring these aspects and offering an optional feature for policy-controlled execution of selected agent actions. This means Aegis can observe what agents are doing, allow for review of files before they are used by an agent, and check policies against chosen actions. The monitoring data is stored locally, emphasizing privacy with no usage telemetry or cloud synchronization. Endpoint naming within Aegis utilizes DNS queries. Optional AI analysis capabilities can send activity metadata to Anthropic upon request, and update checks contact GitHub. The project is available under the MIT license.
Key Monitoring Capabilities:
- Processes: Monitors 112 agents with 265 process-name signatures, including parent-chain and IDE-host detection, with experimental support for WSL and IDE extensions.
- Files: Tracks changes in configured sensitive directories and agent configuration paths, with Windows open-handle and Restart Manager observations.
- Network: Records TCP endpoints for detected agent PIDs, performs forward-confirmed reverse DNS lookups, and provides verdicts for allowlisted, unknown, or flagged network connections.
- Behavior: Employs 73 sensitive-path detection rules across 8 categories, maintains rolling 10-session baselines, and performs anomaly scoring and sequence correlations.
- Local LLMs: Includes runtime probes for Ollama and LM Studio, with detection for other runtimes via process signatures.
The Observatory workspace within Aegis provides a live instance radar, separate agent instance views, file and network inspection tools, rule management, a custom agent catalog, AI analysis features, reporting, auditing, statistics, and settings. Activity data can be filtered, grouped, inspected by stamped instance identity, and exported in various formats like JSON, CSV, HTML, or ZIP. The agent database and contributor guide are available to assist in extending detection capabilities.
Opt-in Action Control:
Aegis's default mode is monitor-first, meaning it logs activity but does not automatically block or contain agents. Manual actions like killing, suspending, or resuming agents are available. The tool also offers opt-in routes for controlling selected agent launches. These include:
- Exact Execution Policy: Allows explicit CLI launches based on an 'allow' policy; 'ask', 'deny', and preparation failures will not initiate execution.
- Windows AppContainer Launch: Provides explicit terminal approval for a single bounded offline action within a new, retained workspace, including private-file access checks and Job cleanup.
- Windows Job Lifetime Route: Starts approved selected Windows actions within a private Job, with confirmed cleanup ending descendant processes. Actions outside this route are not controlled.
- Terminal Confirmation: Enables review of the complete effective action before confirming a launch attempt, with policy denials being non-overrideable.
- Selected-Action MCP Catalog: Supports up to eight operator-selected actions with empty tool arguments, optionally requiring terminal review and confirmation per eligible call.
To generate a client configuration for selected actions, a PowerShell 7 example is provided: node src/main/main.js --action-mcp-config-json catalog "X:/private/actions/catalog.json" > aegis-mcp.json. This command prints an mcpServers.aegis entry using the current Node executable and the absolute source entry path. The output is intended to be kept private due to local path inclusion. Generation does not validate the catalog or start a server; separate checks are required.
Download and Installation:
A Windows installer is available via GitHub Releases, requiring the .exe, manifest.json, and manifest.json.sig files. For installation from source, Node.js 24.x is required, with Windows 10/11 as the primary platform and experimental support for macOS/Linux. The installation process involves cloning the repository, navigating into the directory, running npm ci, and then npm start.
Why it matters for builders
For AI builders, Aegis provides a crucial tool for understanding and managing the behavior of AI agents operating on local systems. The ability to monitor processes, file access, and network traffic in real-time offers deep insights into agent operations, which is invaluable for debugging complex AI systems. Furthermore, the opt-in action control features allow developers to enforce security policies and ensure that agents execute actions only as intended, mitigating potential risks associated with autonomous behavior.
Practical impact
AI developers can leverage Aegis to gain unprecedented visibility into their agents' local activities. This can be used to identify unexpected behavior, diagnose performance issues, and verify that agents are adhering to security protocols. The tool's monitor-first approach ensures that debugging and analysis can be performed without immediately impacting agent functionality. Builders can explore the Observatory workspace to visualize agent activity, review sensitive file alerts, and perform static analysis of agent profiles before deployment. For those implementing agent control, the opt-in action control features offer a pathway to integrate policy enforcement directly into agent workflows, starting with reviewing and confirming selected actions.
Caveats and source limits
Aegis is currently in alpha software status, with the latest release being v0.17.0-alpha as of September 27, 2026. The README describes the current source code, which may be more advanced than the features included in the latest installed build. While Windows is the primary supported platform, macOS and Linux support are experimental. The tool's advanced features, such as policy-controlled execution and MCP tools, require explicit setup and configuration by the operator. The source does not provide details on independent benchmarks or performance metrics for the monitoring capabilities. The privacy policy mentions optional AI analysis sending metadata to Anthropic on request, but specifics on data handling and encryption for this feature are not detailed in the provided excerpts.
Sources
Claim check: 12/12 supported claims - 12 evidence links - 100% avg confidence
- Aegis is an open-source Endpoint Detection and Response (EDR) tool for monitoring AI agents.supported - github.com
- Aegis monitors processes, file activity, network connections, and agent behavior locally without requiring agent plugins.supported - github.com
- Aegis offers optional policy-controlled execution for selected agent actions.supported - github.com
- Monitoring data is stored locally with no usage telemetry or cloud sync.supported - github.com
- Aegis monitors 112 agents with 265 process-name signatures, including parent-chain and IDE-host detection.supported - github.com
- Aegis tracks file changes in configured sensitive directories and agent config paths.supported - github.com
- Aegis records TCP endpoints for detected agent PIDs and provides network connection verdicts.supported - github.com
- Aegis uses 73 sensitive-path detection rules across 8 categories and performs anomaly scoring.supported - github.com
- Aegis includes runtime probes for Ollama and LM Studio.supported - github.com
- Aegis offers opt-in action control features including exact execution policy, Windows AppContainer launch, and Windows Job lifetime route.supported - github.com
- Aegis is available under the MIT license.supported - github.com
- The latest release version is v0.17.0-alpha, dated September 27, 2026.supported - github.com
Caveats
- Single-source caution: verify critical details at the linked source.
Radar score 76/100 - how it was calculated
- Reliability 82: GitHub metadata supports source trust
- Freshness 8: Fresh GitHub release date
- Novelty 62: Novelty blends source metadata and enrichment
- Technical 85: Repository technical metadata
- Developer 96: Developer tooling signals
- Ecosystem 66: Developer-oriented GitHub signal
- Confidence 100: Claims have reliable evidence