Skip to main content
Panguard Guard is the core runtime protection engine. It monitors your system 24/7 using 10 monitor types, processes every security event through a 4-agent DARE pipeline (Detect, Analyze, Respond, Report), and takes automated action against threats based on confidence scoring.

Quick Start

Operating Modes

Guard operates in two modes and transitions automatically:

Learning Mode (Day 1—7)

During the first 7 days, Guard observes your system to build a behavioral baseline:
  • No alerts are generated (prevents false positives)
  • Records normal process patterns, network connections, file activity
  • Sends daily learning progress summaries via Chat

Protection Mode (Day 8+)

After the baseline is established, Guard switches to active protection:
  • Deviations from baseline trigger alerts
  • Automated response based on confidence thresholds
  • Real-time notifications via Chat

The DARE Pipeline

Every security event flows through 4 agents in sequence:

Agent Pipeline Deep Dive

Detailed breakdown of each agent’s inputs, outputs, and decision logic.

Detection Layers

Guard uses a 3-layer AI detection funnel to minimize latency and cost: Only events that cannot be resolved at a lower layer are escalated to the next.

Key Capabilities

Status Dashboard

CLI Options

Monitors

All 10 monitor types: built-in and advanced.

Event Correlation

7 correlation patterns for multi-step attack detection.

Auto-Response

Response actions, safety rules, and escalation ladder.

Agent Pipeline

Deep dive into the 4-agent DARE pipeline.