Endpoint

Configure detection options for endpoint monitoring in Arc. Features include node point extraction, asset validation using ARP, and malware detection with customizable actions.

Figure 1. Endpoint

Endpoint configuration page showing node point detection, Address Resolution Protocol-based asset validation, static entry options, and malware detection settings.

Node points

Enable this option to extract detailed asset information as node points. These can be plotted over time to visualize endpoint activity.

Valid assets (using ARP)

Enable this option to use the local ARP table to confirm media access control (MAC) addresses for connected assets.

Enable Use static entries to include user-defined static ARP table entries in the validation. Only enable this if the static entries are trusted.

Malware (Windows only)

The Malware checkbox lets you enable protection mode and select from the Action to perform on malware detection dropdown. This lets you set the action that Arc will take when it finds a malicious file.

You can choose from these options:

  • Only alert: Receive an alert with no further action
  • Quarantine: Move the malicious file to the quarantine folder, which is located in the Arc installation folder
  • Delete: Immediately delete the malicious file. Once deleted, the files cannot be recovered

You can also use the Directory exclusions feature to exclude specific directories from malware scanning. Select to open a file browser and select a directory. You can add as many directories as needed. Arc skips the selected directories when scanning for malware.