numbat is an open-source endpoint security tool for monitoring AI-agent activity across supported desktop, CLI, IDE, and gateway agents. It combines local hooks and plugins, OTLP/HTTP logs, and on-disk session artifacts, normalizes live and stored activity into a common event model, and evaluates it locally with built-in, sequence-based, or custom YAML CEL rules. The tool can produce NDJSON events, findings, enforcement decisions, indicators, and scan summaries for alerting and forensic reconstruction, including read-only artifact scans, per-session timelines, and portable case bundles with SHA-256 manifests. Optional pre-action blocking is disabled by default and is limited to supported synchronous hooks and explicitly enforced rules. It is distributed as a single cgo-free binary for macOS, Linux, and Windows, with read-only inventory and scanning commands.