Command Overview
Runbeacon scan after endpoint telemetry is flowing to evaluate the runtime log with active threat-detection rules.
Run a local scan
Rule selection
Beacon chooses rules in this order:- Rules in the local rule store.
- The built-in baseline rules when no store is installed.
- The directory passed with
--rules, when you want an explicit rule pack for one scan.
Scan with an explicit rule directory
Runtime log selection
Use per-user endpoint paths by default:Scan user-mode telemetry
Scan system-mode telemetry
Scan a specific runtime log
Session filtering
Filter to one session id substring when you are investigating a known agent run:Scan one session
Output
Human-readable output summarizes each finding, its severity, rule id, reason, session, and matched events. For JSON output, use:Print JSON findings
Related
Use scan gates
Filter findings and fail automation on severity thresholds.
beacon rules
Manage the rules used by local scans.

