Endpoint

The Endpoint page lets you configure the settings for your Arc deployment.

Figure 1. Endpoint page

Endpoint page in Guardian deployment settings, showing options for Asset information, Valid assets using ARP, USB devices, Unusual behaviors, and Malware (Windows only).

Asset information

Enable Asset information to collect detailed information about the endpoint. Arc collects the following data:

  • CPU usage: The current processor load of the endpoint.
  • RAM usage: The amount of memory currently in use on the endpoint.
  • Disk usage: The current disk space usage on the endpoint.
  • Logged-in users: The users currently logged in to the endpoint.
  • Processes with network activity: The running processes that have active network connections, including the local and remote addresses and ports.
  • Hotfixes: The security patches and updates installed on the endpoint (Windows only).
  • User accounts: The local user accounts configured on the endpoint.
  • DNS: The domain name server (DNS) servers and configuration of the endpoint.
  • Installed software: The software packages installed on the endpoint.

Unusual behaviors (Windows only)

This lets you enable/disable Sigma rules for local behavior analysis.

Valid assets (using ARP)

Enable this option to use the local address resolution protocol (ARP) table to confirm media access control (MAC) addresses for connected assets.

Enable Use static entries to include user-defined static ARP table entries in the validation. Only enable this if the static entries are trusted.

USB devices (Windows only)

This lets you enable/disable universal serial bus (USB) detections.

Malware (Windows only)

The Malware checkbox lets you enable protection mode and select from the Action to perform on malware detection dropdown. This lets you set the action that Arc will take when it finds a malicious file.

You can choose from these options:

  • Only alert: Receive an alert with no further action
  • Quarantine: Move the malicious file to the quarantine folder, which is located in the Arc installation folder
  • Delete: Immediately delete the malicious file. Once deleted, the files cannot be recovered

You can also use the Directory exclusions feature to exclude specific directories from malware scanning. Select to open a file browser and select a directory. You can add as many directories as needed. Arc skips the selected directories when scanning for malware.

Restore default

Once the settings have been saved, you can use this button to restore the default configuration.