Skip to main content

Welcome

EDR Agent Monitor ties together a Windows agent, an AWS serverless API, and a React SOC console so teams can detect risky activity, review evidence, and use AI + optional VirusTotal enrichment.

Where things live
WhatWhere
This documentationdocument.ravisarode.com
Operator consoleconsole.ravisarode.com

Read this first

Start like a commercial EDR administration guide (e.g. FortiEDR — Introducing):

  1. Introducing EDR Agent Monitor — components, how it works, doc map.
  2. Using the workflow — analyst steps from login to investigation.

Then:

Installation and hosting are under Architecture & concepts and Deploy & host.

Audience

RoleSuggested path
Analyst / SOCConsole features, AI & enrichment
Endpoint adminDetection pipeline, Agent desktop
EngineerFrom agent to console, Backend overview

Technical truth is always the source code in the GitHub repo; this site explains behavior and operator experience.

Academic background

This system was developed as part of an M.Tech (Cyber Security) project at IIIT Kottayam (AI-Driven EDR with RAG-Powered Automation, Nov 2025). A short alignment of the thesis with this documentation—problem statement, objectives, Sysmon scope, agent layers, and future work—is on Thesis context.