Securing the agentic endpoint

Every AI agent, MCP server, Skill and plug-in running across enterprise endpoints - seen, governed, and protected in real time.

1Endpoints
0AI agents
0MCP servers
0Skills
0Attack pathsFirst attack path detected
One endpoint
Enterprise view

Opening Up Attack Paths Across The Agentic AI Fabric

Keep scrolling

AI moved security to the endpoint

AI usage control is about understanding and protecting the interconnected fabric of agentic AI components - that your pre-AI endpoint protection tools can't see.

What's running

An AI agent is never one thing - models, MCP servers, MCP tools, Skills, hooks, rules, plugins, context

What it can do

Read credentials, move data, execute code, delete files and reach outside your network

Where it runs

On employee and developer endpoints, initiated by users and autonomously expanded by agents

What Backslash does

Backslash covers the full agentic AI fabric on the endpoint -
from inventory to per-tool policy to inline enforcement.

Continuous Discovery and Visibility

  • Every endpoint, agent, model, MCP, hook, plug-in, and skill
  • User identities and credentials used
  • Permissions, data paths and network connections
DiscoverContinuously scanning · 412 endpoints
412Endpoints
1,284Components
37Critical
AgentIdentityOSRiskAction
Claude CodeDave Cohen · personal
personal
macOS
Critical
Review
CursorAaron Allen · personal
personal
Win 11
High
Review
CodexAbigail Hayes · SSO
SSO
macOS
Medium
Monitor
DevinAdam Smith · SSO
SSO
Win 11
Medium
Monitor
AntigravityAlex Butler · SSO
SSO
macOS
No Risk
None
Claude Code — Dave CohenAG-1042 · seen 12s agoCritical
macOS 25.3v2.1.43 MCP · 1 skill
Attached components
claude-code · v2.1.4agent · dave-mbp
[email protected]MCP · network + execCritical
ops-mcp · shellMCP · executeHigh
deploy-helperskill · write scopeHigh
dave.cohen@gmailidentity · personal credsNot SSO
dave-mbp · personal credsOpen asset
DiscoverContinuously scanning · 412 endpoints
412Endpoints
1,284Components
37Critical
AgentIdentityOSRiskAction
Claude CodeDave Cohen · personal
personal
macOS
Critical
Review
CursorAaron Allen · personal
personal
Win 11
High
Review
CodexAbigail Hayes · SSO
SSO
macOS
Medium
Monitor
DevinAdam Smith · SSO
SSO
Win 11
Medium
Monitor
AntigravityAlex Butler · SSO
SSO
macOS
No Risk
None
Claude Code — Dave CohenAG-1042 · seen 12s agoCritical
macOS 25.3v2.1.43 MCP · 1 skill
Attached components
claude-code · v2.1.4agent · dave-mbp
[email protected]MCP · network + execCritical
ops-mcp · shellMCP · executeHigh
deploy-helperskill · write scopeHigh
dave.cohen@gmailidentity · personal credsNot SSO
dave-mbp · personal credsOpen asset

Ongoing Vetting and Risk Assessment

  • Prioritized risks including vulnerable components, excessive permissions, local network access
  • Detection of shadow IT, unapproved tools, use of private accounts
VettingPrioritized risks · 128 open
14Critical
63High
51Medium
FindingComponentEvidenceRiskAction
Vulnerable component[email protected]
mcp-fetch
CVE-1183
Critical
Review
Private account in usecursor · aaron.allen
cursor
personal
High
Review
Excessive permissionssupport-agent-v2
support-v2
write
High
Open
Local network accessops-mcp · 10.0.4.0/24
ops-mcp
10.0.4.0
High
Open
Unapproved toolnotion-bridge-mcp
notion-mcp
shadow
Medium
Triage
Vulnerable component[email protected] · CVE-2026-11839.1
npmReachableFix in 0.3.0
Exposure
claude-code · dave-mbpdirect dependencyIn use
codex · abigail.hayesdirect dependencyIn use
ops-mcp buildpinned 0.2.1Indirect
fetch() → exec()path reaches sinkConfirmed
Upgrade to 0.3.0fix availablePR #482
detected 2h agoFull evidence
VettingPrioritized risks · 128 open
14Critical
63High
51Medium
FindingComponentEvidenceRiskAction
Vulnerable component[email protected]
mcp-fetch
CVE-1183
Critical
Review
Private account in usecursor · aaron.allen
cursor
personal
High
Review
Excessive permissionssupport-agent-v2
support-v2
write
High
Open
Local network accessops-mcp · 10.0.4.0/24
ops-mcp
10.0.4.0
High
Open
Unapproved toolnotion-bridge-mcp
notion-mcp
shadow
Medium
Triage
Vulnerable component[email protected] · CVE-2026-11839.1
npmReachableFix in 0.3.0
Exposure
claude-code · dave-mbpdirect dependencyIn use
codex · abigail.hayesdirect dependencyIn use
ops-mcp buildpinned 0.2.1Indirect
fetch() → exec()path reaches sinkConfirmed
Upgrade to 0.3.0fix availablePR #482
detected 2h agoFull evidence

Granular Policies and Guardrails

  • Hundreds of out-of-the box rules for immediate risk reduction
  • Custom, AI-assisted and context-driven adaptive policies
  • Scoped by user, team, endpoint, component and requested action
GovernPolicies and guardrails · 312 rules
312Rules
28AI-drafted
3Drafts
PolicySourceScopeRiskAction
Skills attempting escalationAI-drafted · all endpoints
AI-drafted
All
High
Block
Block unofficial MCPsOut-of-box · all endpoints
Out-of-box
All
High
Block
Block shadow agent deployTemplate · all endpoints
Template
All
High
Block
Deny local networkOut-of-box · 10.0.0.0/8
Out-of-box
10.0.0.0
High
Block
Agents on personal credsAI-drafted · 312 endpoints
AI-drafted
312 ep
Medium
Warn
Skills attempting escalationP-118 · v4 · AI-draftedActive
All endpointsEU AI ActNIS2
Rule logic
Skill requests sudomatch · any endpoint
Tool call writes /etcmatch · ops-mcp shell
Block call, hold sessionaction · enforced inline
Slack #sec-agentsnotify · owner platform
chmod 777 /etc blockedlast event10:09
last change 4m agoEdit policy
GovernPolicies and guardrails · 312 rules
312Rules
28AI-drafted
3Drafts
PolicySourceScopeRiskAction
Skills attempting escalationAI-drafted · all endpoints
AI-drafted
All
High
Block
Block unofficial MCPsOut-of-box · all endpoints
Out-of-box
All
High
Block
Block shadow agent deployTemplate · all endpoints
Template
All
High
Block
Deny local networkOut-of-box · 10.0.0.0/8
Out-of-box
10.0.0.0
High
Block
Agents on personal credsAI-drafted · 312 endpoints
AI-drafted
312 ep
Medium
Warn
Skills attempting escalationP-118 · v4 · AI-draftedActive
All endpointsEU AI ActNIS2
Rule logic
Skill requests sudomatch · any endpoint
Tool call writes /etcmatch · ops-mcp shell
Block call, hold sessionaction · enforced inline
Slack #sec-agentsnotify · owner platform
chmod 777 /etc blockedlast event10:09
last change 4m agoEdit policy

Real-Time Protection at Execution

  • Risky agent actions blocked inline, before execution
  • Agent intent analysis and drift detection and response
  • Covers unauthorized code execution, credential access, privilege escalation, data sent to unapproved destinations
ProtectBlocked inline · last 24h
41Blocked
12Warned
0Allowed
EventTargetTimeRiskAction
Injection-triggered pushPR ← env variables
github.pr
13:22
Critical
Blocked
Credential access~/.aws/credentials
aws creds
10:14
Critical
Blocked
Privilege escalationsudo chmod 777 /etc
/etc
10:09
High
Blocked
Data to unapproved dest.POST cdn-stats.click
cdn-stats
09:58
High
Blocked
New tool registeredmcp/drive-bridge
drive-bridge
09:41
Medium
Warned
Agent went off-scriptAG-1042 · claude-code · 13:22Blocked
claude-codedave-mbp3 blocks
What happened
Opened the GitHub issuebecause you asked
Read a hidden instructioninstructed by content
Reached for AWS credsnot requestedBlocked
Tried to grant itself sudonot requestedBlocked
Push to cdn-stats.clickinstructed by contentBlocked
5 steps · 41sSee session
ProtectBlocked inline · last 24h
41Blocked
12Warned
0Allowed
EventTargetTimeRiskAction
Injection-triggered pushPR ← env variables
github.pr
13:22
Critical
Blocked
Credential access~/.aws/credentials
aws creds
10:14
Critical
Blocked
Privilege escalationsudo chmod 777 /etc
/etc
10:09
High
Blocked
Data to unapproved dest.POST cdn-stats.click
cdn-stats
09:58
High
Blocked
New tool registeredmcp/drive-bridge
drive-bridge
09:41
Medium
Warned
Agent went off-scriptAG-1042 · claude-code · 13:22Blocked
claude-codedave-mbp3 blocks
What happened
Opened the GitHub issuebecause you asked
Read a hidden instructioninstructed by content
Reached for AWS credsnot requestedBlocked
Tried to grant itself sudonot requestedBlocked
Push to cdn-stats.clickinstructed by contentBlocked
5 steps · 41sSee session

Forensics and Audit Readiness

  • Full path traced from prompt to agent to tool call to outcome
  • Activity trail for individual components, workflows and users
  • Evidence generated automatically for EU AI Act, NIS2, DORA and SOC 2
InvestigateFull path traced · audit ready
2,904Runs
4Frameworks
9Blocked
ActivityFrameworkTimeRiskAction
Infra permissionsprompt → devin → sudo
DORA
10:09
High
Blocked
Summarize issue #311prompt → claude → github.pr
EU AI Act
13:22
Critical
Blocked
Refactor paymentsprompt → cursor → repo.write
SOC 2
12:04
Medium
Completed
Customer data exportprompt → codex → crm.read
NIS2
11:36
Medium
Approved
Nightly data syncschedule → ops-mcp → s3.put
DORA
02:00
No Risk
Completed
Blocked privilege escalationrun-914 · adam.smith · 10:09Blocked
devinops-mcpEU AI ActSOC 2
Full path
Fix the deploy failureprompt · adam.smith
Planned 3 shell stepsagent plan
Read /etc/sudoersops-mcp · read
chmod 777 /etcops-mcp · executeBlocked
Denied, session heldevidence exportedP-118
5 steps · 23sOpen raw log
InvestigateFull path traced · audit ready
2,904Runs
4Frameworks
9Blocked
ActivityFrameworkTimeRiskAction
Infra permissionsprompt → devin → sudo
DORA
10:09
High
Blocked
Summarize issue #311prompt → claude → github.pr
EU AI Act
13:22
Critical
Blocked
Refactor paymentsprompt → cursor → repo.write
SOC 2
12:04
Medium
Completed
Customer data exportprompt → codex → crm.read
NIS2
11:36
Medium
Approved
Nightly data syncschedule → ops-mcp → s3.put
DORA
02:00
No Risk
Completed
Blocked privilege escalationrun-914 · adam.smith · 10:09Blocked
devinops-mcpEU AI ActSOC 2
Full path
Fix the deploy failureprompt · adam.smith
Planned 3 shell stepsagent plan
Read /etc/sudoersops-mcp · read
chmod 777 /etcops-mcp · executeBlocked
Denied, session heldevidence exportedP-118
5 steps · 23sOpen raw log

Security Leaders Trust Backslash
to Enable Their AI Journey

Backslash gave us a live picture of the AI our engineers were already running, and a way to govern it without slowing anyone down
Philip Walsh
Head of Security Engineering

Backslash
Customer Outcomes

Turn the lights on

From "we think our developers are using DeepSeek" to a live map of every AI tool, model, MCP, and integration in use.

Eliminate shadow AI

Enforcement moves from a policy document the employees ignore to a continuously governed and controlled.

Be AI audit ready

Evidence generated automatically for EU AI Act, NIS2, DORA, and SOC 2.

Become the department of YES

Teams adopt AI freely, with guardrails that never become the bottleneck.

Awards & Recognitions

Know what's running on your endpoints.

Free AI Endpoint Exposure Assessment - inventory, posture score, prioritised findings, and a remediation plan.

\ No data retention \ 30 seconds to request \ Read-only \ Agentless

‍

Get your free AI Endpoint Exposure Assessment
Book a Demo ›