Skip to content
CortexDocs
Defender · Endpoint application

Cortex Defender

Cortex Defender is the endpoint application that connects supported AI tools and syncs approved activity to your organization's Cortex workspace.

  • On your endpointDesktop app or headless service
  • Supported AI toolsApps, agents, providers, and cloud routes
  • Team activityAttribute activity to teams and workstreams
Set up your device
Your device, connected to Cortex
Supported sources
Browser
CLI
MCP
Cortex Defender Home and connected appsManage devices in Cortex
Workspace
Synced telemetryVerify capture.
Then verify sync.
Cortex Defender connects supported AI tools on your device. Verify local capture and workspace sync separately.

Cortex Defender captures activity from supported AI tools on a managed device and syncs it to Cortex Atlas. Use Home for Defender status, Connections to manage apps, and Settings for workspace and device preferences.

Set up your device

IT usually installs Cortex Defender. Once it appears on your device, set up Cortex Defender, then use AI tools supported by Defender when adding a source.

If your organization uses a shared gateway, connect an app or AI tool to Egress Gateway.

For the designated admin and IT

Chaos Labs creates the organization and designates an initial admin. Choose a deployment guide:

Capture controls and help

How capture works

  • Claude CodeCommand line
  • CodexCommand line
  • GeminiWeb and CLI
  • CursorCLI and IDE history

Cortex captures new activity from enabled sources or imports completed Cursor IDE conversations. Open an app in Connections to check Last activity seen. Enrolled devices upload captured activity to the organization workspace when sync is healthy. Review the synced activity in Atlas.

What Cortex Defender can capture

Fields vary by source and provider. A capture can include:

DataExamples
AI request and response contentPrompts, messages, and generated responses
Source and model contextCLI, browser, desktop, or MCP channel; application, provider, and model
Request metadataCapture time, duration, status, conversation, and exchange identifiers
Usage metadata, when availableInput, output, cache, and thinking-token counts
Tool activity, when supported by the pathTool definitions, calls, results, and captured local MCP activity
Capture qualityWhether the request and response are complete, partial, or contain errors

Cortex Defender does not capture every action on the device or all network traffic. It captures activity only from supported sources with capture enabled. Local capture and workspace sync are separate: if sync is temporarily unavailable, supported activity can still be captured locally but will not appear in Atlas until sync recovers.

Was this helpful?