Endpoint security · Add-on

The host you already watch can also watch for threats.

Monitoring tells you a server is up. It doesn't tell you someone is hammering its SSH login, that a system file changed overnight, or that a policy drifted out of compliance. Bayqus' security sensor adds that layer to the machines you already run the agent on — one click enrolls threat detection on the host, and what it finds is scored by severity and routed straight into the alerting you already use. It comes with the Secure plan ($29/mo — everything in Pro plus this and RMM/Patch), with per-endpoint pricing ($6/endpoint) available at scale.

One-click enroll · Linux & Windows Severity-scored detections Same agent · zero open ports
01 — Where the sensor fits

It rides the agent you already installed.

The security sensor is not a second product to roll out. It installs onto hosts that already run the Bayqus agent, using the same outbound-only connection your monitoring uses. Enabling it doesn't open a port, doesn't need an inbound rule, and doesn't touch machines you didn't choose — you enroll the specific hosts that matter, and everything the sensor sees comes back out the same trusted channel. Monitoring answers "is it healthy?"; the sensor adds "is it under attack, or has it been tampered with?" on the same screen.

STATE A

Agent present

The host already reports health to Bayqus. No security sensor yet.

STATE B

Enroll

Owner clicks Enroll on the Security page — or "Enroll all eligible" for the whole fleet.

STATE C

Installing

The agent installs and connects the sensor on the host; the page polls until it's live.

STATE D

Connected

Detections stream into the security console and into your alert channels.

02 — What the sensor watches

Security-relevant events, scored so you can triage them.

Every detection carries a severity level, and Bayqus groups those levels into plain-language bands so an on-call engineer doesn't need to memorise a numeric scale. The console shows the real events from the host; the bands decide what's worth waking someone for.

BandMeansTypical events
CriticalWake someone upSuccessful intrusion indicators, high-confidence attack signatures, sensitive system tampering.
HighLook todayRepeated failed logins and brute-force patterns, privilege changes, suspicious process or file activity.
NoticeGood to knowRoutine policy and integrity events — a watched file changed, a config drifted, an audit rule fired.
InfoContextLow-level log activity kept for correlation and history in the console.
Detection categories the sensor produces include authentication & brute-force, file-integrity monitoring, and security-policy / audit events — each mapped to a severity level and shown with its rule level, host, and time in the console.
03 — Turning it on, and being told

One click to enroll. Critical-only by default, so it doesn't flood.

Enrolling a host
On the Security page, the account owner clicks Enroll on a host that already runs the agent — no separate ticket, no second approval hop. The agent installs and connects the sensor; the page polls until it reports connected. Use Enroll all eligible to do the whole fleet at once.
Linux & Windows
The sensor enrolls on both Linux and Windows hosts. A machine on an OS or agent version that can't run it is told to update rather than shown a dead button.
Alerting & noise control
Detections route through the same channels, policies and silences as your monitoring alerts — Telegram, email, webhook, Slack. The security notifier defaults to critical-only, so switching it on doesn't bury anyone; lower the threshold when you want more.
Console & history
A live security console shows the real detections per host, grouped by severity band, with the coverage summary telling you which hosts are enrolled and connected.
04 — Questions

The things people ask first.

Q. Is this a separate product to deploy?

No. The security sensor installs onto hosts that already run the Bayqus agent. There's no new collector, no inbound port, and no separate rollout — you enroll the hosts you care about from the Security page and the existing agent does the install.

Q. What does it actually detect?

Security-relevant host events — authentication and brute-force attempts, file-integrity changes, and security-policy or audit violations — each scored by severity. Bayqus groups those scores into plain-language bands (Critical / High / Notice / Info) so triage doesn't depend on memorising a numeric scale.

Q. Will it flood my team with alerts?

Not by default. The security notifier ships critical-only, so enabling it doesn't page anyone for routine events. Detections still all land in the console; only the severity you choose is delivered to your channels, and existing policies and silences apply.

Q. Does it open any ports or change my firewall?

No. It uses the same agent-push, outbound-only model as the rest of Bayqus. The host initiates the connection; nothing inbound is opened, so it works behind NAT exactly like your monitoring.

Q. How is it priced?

The simplest way to get it is the Secure plan — $29/month for everything in Pro plus the security sensor and RMM/Patch across your fleet. At larger scale it can be billed per endpoint ($6/endpoint per month). Your base Pro plan (a flat monitoring price for up to 100 devices) is unchanged.

Related reading

More on how it fits together

Add threat detection to the hosts you already trust to Bayqus.

Run the agent, click Enroll, and let the security sensor watch for what monitoring can't see.

Start free Talk to us

Verified against the security sensor surface (backend/src/routes/siem.js · siem-poller.js · agent/siem.go) — 2026-08-01