Locally running AI agents and MCP servers

ISPM discovers endpoint AI agents and the MCP servers that they use through the CrowdStrike Falcon connector, links them together, and keeps a continuous inventory across your managed endpoints.

Early Access release

Why this matters

Endpoint AI agents run on employee devices with direct access to local files, shell commands, and system resources. They often connect to MCP servers, which give agents access to external tools, data, and APIs, and which often hold embedded credentials for the systems they expose. These agents and servers fall outside your other detection paths. A user can run a tool such as Cursor or Claude Code with no SSO event, no OAuth grant, and no browser request. Discovering them shows you what is running and what it can reach.

What ISPM discovers

The CrowdStrike Falcon connector reports both the endpoint agents and the MCP servers running across your managed endpoints, and links the two together. ISPM surfaces them on two pages.

Endpoint agents
AI agents that run on endpoints, with the AI model itself running locally or in the cloud. These agents have direct access to local files, shell commands, and system resources. The Endpoint agents page lists each agent with its platform, its endpoint, and the MCP servers it connects to. Open an agent to see its details and the MCP servers it uses.
MCP servers
MCP servers give AI agents access to external tools, data, and APIs. They run locally on endpoints or as remote services, and often hold embedded credentials for the systems they expose. The MCP Servers page lists each server with its linked agents and endpoint users. Open a server to see the agents connected to it. This gives you the other perspective: from an MCP server, see which agents use it.
Endpoint user
For each agent, ISPM shows the endpoint user. When ISPM can match the agent to an Okta account, it shows that Okta account. When no Okta account is found, ISPM shows the user on the endpoint instead, so you may see local users such as root or administrator. On some operating systems, the endpoint user isn't available.

Use cases

  • Investigate endpoint AI agent activity. Find which endpoints are running a given AI agent, and see the MCP servers it connects to.
  • Audit your endpoint AI footprint. Track the AI agents running across your endpoints over time.
  • Review your MCP servers from the other direction. See which MCP servers are running and which agents connect to each one, along with the endpoint users, so you understand the access surface.