Home › Blog

# Your EDR Agents Are Lonely. Mine Hunt in Packs

Scott Gardner — March 2026

There's a fundamental problem with how every EDR product on the market works, and nobody wants to talk about it because the fix sounds insane.

Here's the problem: your endpoint agents are solitary hunters. Every single one of them — CrowdStrike, SentinelOne, Defender, Carbon Black, whatever your CISO bought after that one conference — they all work the same way. The agent sees something on the endpoint. It phones home. The server thinks about it. Maybe it correlates with what another agent saw. Maybe.

The "maybe" is the problem. Because that correlation happens on the server's schedule. Every 30 seconds. Every 60 seconds. However often your agents are configured to heartbeat. And if you're dealing with modern ransomware that can encrypt a network in 45 seconds flat? You're done before the server even knows there was a fight.

Your agents are fighting one-on-one against an attacker who's hitting your entire network simultaneously. That's not a fair fight. That's not even a fight. That's a lunch buffet.

## The Observation Nobody Made

I spent six months building a hardened EDR agent — cryptographic identity, anti-tamper monitoring, behavioral heuristics, the whole nine yards. Good agent. Does its job. But every time I watched a simulated multi-host ransomware scenario play out, the same thing happened: Agent A detected something. Agent B detected something. Agent C detected something. And then they all individually phoned home like teenagers reporting to different parents, and nobody connected the dots until it was too late.

The insight was embarrassingly obvious once I had it: why are they reporting to a server when they could just tell each other?

Not as a replacement for centralized correlation. As an additional layer. A mesh. A swarm.

## What "Swarm Intelligence" Actually Means (Not the Buzzword)

Let me be clear about what this isn't: this isn't "AI" in the marketing sense. There's no large language model involved. There's no cloud service analyzing telemetry with someone else's GPU farm. This is combinatorial mathematics and distributed systems theory applied to endpoint detection.

Think about how ant colonies work. No individual ant is smart. No individual ant has a map of the territory. But collectively, they solve optimization problems that would take a supercomputer significant resources to brute-force. They do this through local communication — each ant communicates with nearby ants using pheromone signals, and global behavior emerges from local interactions.

That's the principle. Except my ants have ED25519 keypairs and they communicate threats, not food sources.

## Five Things a Pack Can See That a Lone Wolf Can't

I identified five detection patterns that are literally impossible for a single agent to detect, but trivially obvious to a mesh of agents sharing observations in real time:

1. Coordinated Phase Alignment

Modern ransomware follows a kill chain: reconnaissance, staging, preparation, pre-encryption, encryption. An individual agent seeing "preparation" on one host? Concerning, but could be a false positive. Three hosts simultaneously entering "preparation"? That's not a false positive. That's an attacker pressing the go button.

2. Entropy Waves

When files get encrypted, their Shannon entropy approaches the theoretical maximum. One host with rising file entropy? Could be a ZIP operation. Could be a backup. Five hosts with simultaneously rising entropy? That's a coordinated encryption wave, and you've got about 60 seconds to pull the network cable.

3. Lateral Movement Confirmation

This one is elegant in its simplicity. Agent A sees an outbound connection to Agent B's subnet. Agent B sees an inbound connection from Agent A's subnet. Neither agent alone knows this is lateral movement — Agent A just sees "outbound connection" and Agent B just sees "inbound connection." But the swarm knows instantly: someone is moving laterally from A to B. Sub-second detection. No server required.

4. Collective Anomaly Detection

This is my favourite because it captures something genuinely novel. Imagine five agents each reporting a low-confidence anomaly — individually, these wouldn't trigger any alert. They're below threshold. Noise. But five independent sensors reporting the same type of noise simultaneously? That's signal hiding in the noise, and the swarm is the only architecture that can detect it.

5. Canary Mesh

Each agent watches a lightweight honeypot resource. Any access to any canary anywhere in the network is instantly broadcast to every peer. One trip wire, network-wide alert, sub-second. If an attacker is probing your network, the swarm knows before they've finished their port scan.

## Why This Is Hard (And Why Nobody's Done It)

Three reasons:

Trust. In a peer-to-peer system, how do you know the peer you're talking to is actually a legitimate agent and not an attacker who's injected a fake one? I use a three-tier trust model: untrusted (just discovered), verified (passed mutual cryptographic challenge-response), and trusted (explicitly vouched for by the central server). Only verified and trusted peers participate in consensus. An attacker would need to compromise the server's signing key to inject a trusted peer.

Byzantine Tolerance. What if an attacker compromises one of your actual agents? In a voting-based consensus system, a compromised agent could flood the swarm with false votes. The solution is trust-weighted consensus: votes from low-trust agents are rejected outright, and the system requires a quorum of independent agreeing agents before any swarm alert fires. A single compromised agent can't achieve quorum alone.

Degradation. The system must work in three states: full connectivity (server + peers), partial connectivity (peers only, server down), and partitioned (isolated subgroups). This is the hardest engineering problem of the three, and it's the one that separates a research paper from a production system.

## The Math of Collective Detection

For the technically curious: the confidence of a swarm detection is computed as a trust-weighted proportion of affirmative votes. If three agents with trust scores of 0.7, 0.9, and 1.0 all agree on a detection, the consensus confidence is:

```

(0.7 + 0.9 + 1.0) / (0.7 + 0.9 + 1.0) = 1.0 (all agree)

```

If only two agree and one dissents:

```

(0.7 + 0.9) / (0.7 + 0.9 + 1.0) = 0.615

```

The server's correlation engine then applies a multiplier to swarm-validated detections (they've already been peer-reviewed) and reduces the cooldown period. A swarm consensus alert combined with server-side correlation achieves the highest possible confidence classification in the system.

In practice: individual agent detection gives you a signal. Server correlation gives you context. Swarm consensus gives you certainty.

## What This Means for Defenders

If you're running a SOC, here's what changes:

- Your mean time to detect coordinated attacks drops from minutes (heartbeat latency) to seconds (gossip propagation)

- Your false positive rate for multi-host detections drops dramatically (consensus filtering)

- Your system continues detecting threats even during a network partition or server outage

- Attacks that produce weak individual signals but strong collective signals become detectable

The last point is the one that keeps me up at night. There is an entire class of attacks designed to fly under individual detection thresholds. The adversary knows your threshold. They craft their activity to stay below it. The swarm changes the math: five sub-threshold signals from five independent sensors is a signal that no amount of threshold tuning can hide from.

## The Patent

I've filed a patent application: "Distributed Endpoint Detection and Response Swarm: Cryptographically Authenticated Peer-to-Peer Collective Threat Detection Using Gossip-Based Consensus."

Fourteen claims covering the peer discovery mechanism, gossip protocol, consensus voting, five collective detection patterns, trust hierarchy, Byzantine tolerance, and graceful degradation. If the concept of endpoint agents talking directly to each other for collective threat detection sounds obvious in hindsight — good. The best ideas usually do.

## What I Didn't Tell You

I deliberately left out the protocol details, the message format, the crypto implementation, and the gossip propagation strategy. That's the sauce, and it stays in the kitchen.

What I will tell you: the entire swarm module compiles into the same binary as the base agent. Zero external dependencies beyond what was already there. Feature-gated behind an environment variable. Off by default. When it's off, the agent behaves identically to a standard hub-and-spoke endpoint sensor. When it's on, the endpoints start hunting in packs.

I built this because I got tired of watching ransomware operators take down networks while individual endpoint agents filed their reports one at a time like polite bureaucrats. The agents are supposed to be defending the network. It's about time they started acting like it.

Scott Gardner builds security tools at ninja.ing. He is the sole author and inventor of the Raz0r EDR agent and the distributed detection swarm architecture described above.

The author's opinions on enterprise EDR products are his own and do not constitute an endorsement or criticism of any specific vendor's technology. They're just wrong about the architecture.

The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

Originally published on LinkedIn ↗

← All writing