# Endpoint Agent

## What is the function of the endpoint agent?

The agent collects advanced telemetry from your endpoints to enable cyber threat detection and facilitate incident response. It provides complete visibility into endpoints, recording forensic-like evidence such as network connections, logins, processes, user actions, downloaded files, and much more. The agent can also be used to execute interactive threat-hunting queries and perform various incident response actions.

## What Operating Systems are Supported?

Check Agent Deployment Prerequisites /endpoint-agent/prerequisites.md

## How can we verify if an agent is online and reporting?

In the Analyst Console, under the endpoint menu, two dashboards are available:

* **Inventory of Agents**: conducts regular checks to confirm if agents are live and reporting.

## How do you remove an agent from the Console?

You must uninstall the agent directly from the endpoint.

## Can I run EDR and the visibility agent at the same time?

Yes, they can co-exist on the same endpoint. Just ensure that your EDR is not blocking the installation of the agent.


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://docs.threatdefence.com/getting-started/frequently-asked-questions/endpoint-agent.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
