EclipticaReplayGet Replay

AI Detection & Response

Watch your AI agents
like you'd watch a network.

Replay watches what your AI agents do: the commands, files, and URLs they touch. Detection rules run locally, sessions rebuild from saved history, and you can opt into blocking per rule.

Free and local-first. Nothing leaves your machine unless you say so.

live activity monitoring
agent ran a command
reached the cloud metadata endpoint
matched rule: cloud metadata probe · medium
checked against threat intel · no match
listening for activity…

How it works

Built for the way agents work.

Replay sits between the agent and the system: it watches and records, and only blocks when you opt in.

Local-first by design

Everything Replay records is stored on your machine in a single file. No accounts, no cloud, no telemetry you didn't ask for.

Always-on protection

Monitoring keeps running even when the app is closed, so nothing slips through while you're away.

Detection rules

A built-in rule catalog, plus your own policy, runs locally against every action. Opt into blocking per rule, or stay monitor-only.

Session replay

Alerts reconstruct into full session timelines: every tool call, command, and file touched, in order.

Threat-intel correlation

Observed domains, IPs, URLs, and hashes are matched against the Threat Landscape feed and surfaced as enriched alerts.

Verify your wiring

Wired doesn't mean working. A per-agent self-test confirms the connector really sends records, and a staleness flag catches silent failures.

Product

See it work.

One window for everything your agents did, and everything you should know about it.

Replay Overview screen
Overview — Status at a glance: protection per agent, alert triage, and the latest activity.
Replay Alerts screen
Alerts — Every detection with its rule, severity, evidence, and session drill-down.
Replay Observables screen
Observables — The domains, IPs, URLs, and hashes your agents touched.

Coverage

Works with the agents you already run.

On-demand rebuilds activity from an agent's saved history. Live captures as it acts. Enforcement can block an action when you deploy a rule in enforce mode.

AgentOn-demandLiveEnforcement
Claude Code
Claude Cowork
Codex
Gemini CLI
Cursor
Windsurf / Cascade
GitHub Copilot CLI
VS Code Copilot Chat
OpenCode
OpenClaw
Pi
Kimi Code
Antigravitysoon
Ampsoon
Auggiesoon
Cline CLIsoon
Crushsoon
Devin CLI
Factory Droidsoon
Goosesoon
Grok Buildsoon
Hermessoon
Junie CLIsoon
Kilo Codesoon
Kiro IDE / CLIsoon
OpenHandssoon
Qwen Codesoon

Download

Free and local.

Replay ships as one file that includes the interface and the detection engine. No accounts, no installers that phone home.

Linux quick start:tar -xzf replay-linux-amd64.tar.gz && ./replay

Replay checks for updates automatically and shows new versions in Settings.

Free for non-commercial individual use. For commercial use, contact [email protected]. License · Third-party notices

Enterprise

Central visibility, without surrendering the local engine.

The free app stays fully local. The enterprise tier adds managed services on top: same engine, central control.

Talk to uscoming soon

Managed analytics

Central visibility over agent activity across every installation: detections, observables, blocked actions, and raw events, with sensitive values redacted.

Orchestration

Distribute your rules centrally, assign per team or host, and audit which rule version was effective, and where and when.