Endpoint Agent
Inventories your devices, deploys their patches and provides remote management.
- 3
- core functions — inventory, patch, RMM
- 500+
- maximum patches in bulk deployment
- Ring-based
- phased rollout strategy
- Zero dependencies
- static Go binary, system calls
When endpoints are unmanaged, the network is unguarded.
Hundreds of computers run open; nobody knows what software is installed where or which patches are missing. Attackers slip through these unguarded doors: outdated software versions, missing security updates, configuration errors. The problem is not the lack of remedies but the lack of visibility and control.
- How many computers do you have and which ones run licensed software you need to track?
- When a critical security patch comes out, how many machines can you patch immediately?
- What versions are your business applications running, and who decides which patches to skip?
What it does.
Complete inventory scan
Software, version, install date, license status, open ports and network data are automatically collected from every device and sent to the cloud.
Missing patch discovery
Windows Update, Microsoft Update, third-party patches — the system lists all applicable updates for each machine with severity levels shown.
Ring-based patch deployment
Roll out patches in pilot, test and production phases — you can set pause points at each stage and roll back if errors occur.
Bulk installation
Deploy patches and software to up to 500 machines at once — progress is tracked until completion.
Software exclusion
Exclude known incompatible software from patching — the list is company-specific, no global exceptions.
Device health summary
Clean, at risk, unknown, unlicensed — each device status at a glance, with counts of critical missing patches and silent machines.
Task scheduling
Schedule patches for early morning, weekends or a specific day window — run updates during off-peak hours.
Installation history and report
Every deployment job is logged with outcome, error or reboot status — audit and compliance reports come from this record.
From setup to report.
- 01
Agent deployment
A static Go binary is installed on each machine along with an enrollment key. The agent automatically communicates with the panel and registers itself.
- 02
Inventory collection
The agent reads software, versions, ports and Windows Update status and sends the data to the cloud. The machine appears in the panel.
- 03
Select patches
The panel lists missing patches filtered by critical, important, moderate and low. You remove any that should be excluded.
- 04
Plan the rollout
Divide patches into rings (phases) — test machines first, then general machines. You can pause at the start, middle or end.
- 05
Monitor and verify
Installation progress is tracked in real-time and both success and errors are logged. The next scan verifies the patch was applied.
The specifics.
- Supported operating systems
- Windows 10, Windows 11, Windows Server 2019+, Windows Server 2022
- Patch sources
- Windows Update, Microsoft Update, software vendor updates
- Ring phases
- 3-5 stages in production setup (pilot, test, production etc.)
- Bulk deployment
- Up to 500 machines per job
- Status tracking
- Real-time progress, success/error logs, reboot status
- License management
- Seat-based licensing, enrollment key, persistent per-device key
- Reporting
- Timestamped update history, device health summary, compliance audit trail
Frequently asked questions.
Can unlicensed computers be scanned?
Yes, the agent runs on every machine as a scanner. Licensing only determines whether patches can be installed on the device. Deploying patches to an unlicensed machine does not block the operation but consumes licenses.
Can I pause a patch deployment?
Yes. When deployment is divided into rings, you can pause after each ring — wait for test results and cancel if incompatible. There is no rollback; the next scan only verifies if the patch applied.
What happens if a device is offline?
If the agent is offline, the job queues and resumes when the device comes online. Queue size is limited and very old jobs are automatically purged. Success is recorded once applied.
Other CyCastle services.
Endpoint Agent starts today.
Create a free account and run your first scan within minutes.