Kernel-level EDR for your Linux fleet, as a service
eBPF telemetry, MITRE ATT&CK-mapped detection, automated response and host isolation. Local-first by design โ your endpoints keep protecting themselves even when the internet is gone.
See everything
eBPF exec / file / network / ptrace telemetry with container & Kubernetes lineage โ plus fanotify, netlink and proc fallbacks for any kernel.
Detect what matters
Path, chain, anomaly and sequence rules, Sigma import, YARA, and five threat-intel feeds. Fully offline-capable detection engine.
Respond automatically
Kill, quarantine, and nftables-isolate at policy severity โ with a pre-execution gate that blocks known-malicious binaries before they run.
Enroll in one command
sudo sahmedr login, approve the code in this portal, done.
No config files to hand-edit, no shared secrets in the fleet.
AI triage, metered
Optional LLM enrichment through our gateway โ server-side keys, atomic quotas, and per-request usage you can see. Core detection never depends on it.
Fail safe, never destructive
Expired payment never deletes anything: agents drop to a documented restricted mode and recover automatically the moment billing is fixed.
Protect a host in three steps
Grab the signed .deb from
downloads: sudo apt install ./sahmedr_*.deb
sudo sahmedr login โ approve the device code
here in your browser. Credentials are per-agent and revocable.
sudo systemctl start sahmedr โ the agent
reports to your fleet, refreshes its authorization lease, and stands guard.