Runtime Explorer
Runtime Explorer combines recent event history with the latest host reports for selected sensors. Check which tab you are using: an execution or connection event is not proof that the process or socket is still running.
Use Monitor > Investigate for a different time range or more detailed historical conditions.
Sensor selection
Open Monitor > Runtime Explorer and select one or more Sensors. Large fleets require an explicit selection before data loads, preventing an accidental fleet-wide query.
The Runtime Explorer displays up to five Sensors at a time. Narrow the selection when you need to compare another set of nodes.
Tabs
The Runtime Explorer has seven tabs:
| Tab | What it shows |
|---|---|
| Process | Recorded process activity and execution context |
| Top | Processes ranked by CPU, memory, PID, or name |
| System | Recent system-level runtime evidence |
| Connection | Recorded connection activity attributed to processes |
| Red Flags | High-priority runtime evidence that requires review |
| Listening | Listening services, addresses, ports, and owning processes |
| Container | Processes grouped by container or Kubernetes workload |




History and current reports
Process, System, Connection, and Red Flags browse recorded activity from the recent seven-day window. Search and move through pages with Previous and Next. Browsing an older page keeps its position instead of replacing it with the latest events.
Top, Listening, and Container use the latest available sensor reports. Check the observation time before treating those reports as current.
Select a row for process identity, executable path, command, user, parent relationship, and workload context when available. Use Retry after a failed request; a load error does not mean the sensor reported no activity.
Network connections and listening services
Select Connection to review recorded process-attributed connection activity. Select Listening to identify exposed services and their owning executables. Use Network View for fleet-wide DNS and connection investigation.
Related live and capture views
- Use Monitor > Live Feed to follow new events as they arrive.
- Use Telco > Assurance > Packet Capture to start a bounded telecom packet capture and download PCAPNG evidence.
- Use Monitor > Investigate to query historical runtime evidence.
Limitations
- Current-state process data reflects the latest Sensor report. A short-lived process may appear only in Monitor > Investigate or Process Tree historical evidence.
- Kernel threads may appear alongside user-space processes.
- Multi-Sensor comparison is limited to five selected Sensors at a time.