Skip to main content

Commands

Use this reference to browse Beacon commands by hierarchy. Each command links to the consolidated guide section with examples, flags, and operational notes.

Install and Upgrade

Install the Beacon CLI, check for released updates, and repair endpoint configuration after upgrades:

Install Beacon

Install Beacon with Homebrew or platform archives.

Upgrade Beacon

Check for updates and upgrade the Beacon CLI.

Manual CLI Installation

Install from platform archives or build Beacon from source.

beacon

Command syntax
Top-level Agent Beacon CLI commands.

beacon version

Command syntax
Display the installed Beacon version or check for released updates.

beacon scan

Command syntax
Run threat-detection rules over local endpoint telemetry without network access.

beacon rules

Command syntax
Manage local threat-detection rules and author rule packs.

beacon ci

Command syntax
Run ephemeral Beacon telemetry collection for CI jobs without installing a persistent endpoint service.

beacon cloud

Command syntax
Configure provider-managed cloud agent telemetry setup helpers.

beacon mcp

Command syntax
Expose local Beacon runtime activity through MCP.

beacon ingest

Command syntax
Upload Beacon telemetry to configured ingest destinations.

beacon endpoint

Command syntax
Manage the local endpoint agent and inspect supported agent harness telemetry.

beacon endpoint config

Command syntax
Inspect, validate, and update endpoint configuration.

beacon endpoint wazuh

Command syntax
Generate Wazuh configuration, content packs, and validation events for Beacon endpoint logs.

beacon endpoint elastic

Command syntax
Generate Elastic configuration, content packs, and local validation stacks for Beacon endpoint logs.

beacon endpoint datadog

Command syntax
Generate Datadog Agent custom log collection content and validation events for Beacon endpoint logs.

beacon endpoint sumo

Command syntax
Generate Sumo Logic HTTP Source forwarding content and validation events for Beacon endpoint logs.

beacon endpoint rapid7

Command syntax
Generate Rapid7 InsightIDR Custom Logs forwarding content and validation events for Beacon endpoint logs.

beacon endpoint sentinel

Command syntax
Generate Microsoft Sentinel Azure Monitor Agent forwarding content and validation events for Beacon endpoint logs.

beacon endpoint cloudwatch

Command syntax
Generate AWS CloudWatch Logs forwarding content and validation events for Beacon endpoint events.

beacon endpoint s3

Command syntax
Generate AWS S3 forwarding content and validation events for Beacon endpoint logs.

beacon endpoint gcs

Command syntax
Generate Google Cloud Storage forwarding content and validation events for Beacon endpoint logs.

beacon endpoint hooks

Command syntax
Install, inspect, and remove hook-based telemetry for supported local runtimes.

beacon endpoint integrations claude-cowork

Command syntax
Configure and validate Claude Cowork OpenTelemetry export.

beacon endpoint integrations openclaw

Command syntax
Configure and validate OpenClaw Gateway OpenTelemetry export.