Cortex Defender
Cortex Defender is the endpoint application that connects supported AI tools and syncs approved activity to your organization's Cortex workspace.
- On your endpointDesktop app or headless service
- Supported AI toolsApps, agents, providers, and cloud routes
- Team activityAttribute activity to teams and workstreams
Then verify sync.
Cortex Defender captures activity from supported AI tools on a managed device and syncs it to Cortex Atlas. Use Home for Defender status, Connections to manage apps, and Settings for workspace and device preferences.
Set up your device
IT usually installs Cortex Defender. Once it appears on your device, set up Cortex Defender, then use AI tools supported by Defender when adding a source.
If your organization uses a shared gateway, connect an app or AI tool to Egress Gateway.
For the designated admin and IT
Chaos Labs creates the organization and designates an initial admin. Choose a deployment guide:
Capture controls and help
How capture works
Claude CodeCommand line
CodexCommand line
GeminiWeb and CLI
CursorCLI and IDE history
Cortex captures new activity from enabled sources or imports completed Cursor IDE conversations. Open an app in Connections to check Last activity seen. Enrolled devices upload captured activity to the organization workspace when sync is healthy. Review the synced activity in Atlas.
What Cortex Defender can capture
Fields vary by source and provider. A capture can include:
| Data | Examples |
|---|---|
| AI request and response content | Prompts, messages, and generated responses |
| Source and model context | CLI, browser, desktop, or MCP channel; application, provider, and model |
| Request metadata | Capture time, duration, status, conversation, and exchange identifiers |
| Usage metadata, when available | Input, output, cache, and thinking-token counts |
| Tool activity, when supported by the path | Tool definitions, calls, results, and captured local MCP activity |
| Capture quality | Whether the request and response are complete, partial, or contain errors |
Cortex Defender does not capture every action on the device or all network traffic. It captures activity only from supported sources with capture enabled. Local capture and workspace sync are separate: if sync is temporarily unavailable, supported activity can still be captured locally but will not appear in Atlas until sync recovers.