Benefits
Benefits
Benefits
Benefits
Benefits
Benefits
Benefits
Benefits
Benefits
The Network Agent keeps connectivity reliable; the Security Agent keeps you from being compromised.
They’re complementary, and both live in CERNE.
| Network Agent | Security Agent | |
|---|---|---|
| Primary purpose | Network performance, availability, traffic, paths, and configuration | Endpoint protection, detection, investigation, and response |
| Primary telemetry | Latency, packet loss, bandwidth, flows, interfaces, routes | Processes, files, scripts, memory, registry, identity, connections, vulnerabilities |
| Typical action | Alert on link degradation, map a path, adjust network configuration | Block malware, isolate a host, quarantine a file, stop a process |
| Main users | NetOps, ITOps, cloud operations, NOC | SOC, security engineering, incident response |
| Typical deployment | Probe, collector, router/switch integration, VM, branch appliance | Laptop, server, VM, cloud workload, container host |
| Core outcome | Reliable, optimized connectivity and service delivery | Lower probability and impact of compromise |
FAQ
It’s a lightweight endpoint software component that continuously monitors device, process, identity, file, memory, and network behavior; prevents known and unknown threats; enforces security policy; and enables centralized detection, investigation, containment, and automated remediation across enterprise and cloud environments.
A network agent watches network availability, traffic, paths, and configuration — its job is reliable connectivity, for NetOps and the NOC. A security agent focuses on the endpoint, user, processes, identity, data, and threat behavior — its job is lowering the probability and impact of compromise, for the SOC. They’re complementary, and both live in the CERNE control plane.
NGAV prevents — it blocks known-bad files by signature, reputation, and heuristics before they run. EDR detects and responds — it continuously records endpoint activity and surfaces behavioral threats that have no signature, then enables investigation and containment. You need both, because most modern attacks are malware-free.
Instead of asking ‘is this file known-bad?’, behavioral detection asks ‘is this behavior malicious?’ — watching for credential dumping, process injection, living-off-the-land abuse of tools like PowerShell, ransomware-style encryption, and unusual script activity. That’s essential when 82% of detections involve no malware file at all.
Yes. The same agent extends endpoint-grade protection to cloud VMs, containers, Kubernetes nodes, GPU training nodes, and management-plane hosts — detecting container runtime abuse, cryptomining, privilege escalation, and credential theft, and applying data controls to model weights, embeddings, and datasets.
It can act automatically under your policy: isolate the host from the network while preserving a management path, kill the malicious process, quarantine the file, remove persistence, and roll back changes — then gather evidence and hand off to your SIEM, SOAR, and ticketing workflows. Tamper protection keeps the agent running even on a compromised system.
Copyright © 2026 • All Rights Reserved