Endpoint
The Endpoint page lets you configure the settings for your Arc deployment.

Node points
Enable this option to extract detailed asset information as node points. These can be plotted over time to visualize endpoint activity.
Unusual behaviors (Windows only)
This lets you enable/disable Sigma rules for local behavior analysis.
Valid assets (using ARP)
Enable this option to use the local address resolution protocol (ARP) table to confirm media access control (MAC) addresses for connected assets.
Enable Use static entries to include user-defined static ARP table entries in the validation. Only enable this if the static entries are trusted.
USB devices (Windows only)
This lets you enable/disable universal serial bus (USB) detections.
Malware
The Malware checkbox lets you enable protection mode and select from the Action to perform on malware detection dropdown. This lets you set the action that Arc will take when it finds a malicious file.
You can choose from these options:
- Only alert: Receive an alert with no further action
- Quarantine: Move the malicious file to the quarantine folder, which is located in the Arc installation folder
- Delete: Immediately delete the malicious file. Once deleted, the files cannot be recovered
Restore default
Once the settings have been saved, you can use this button to restore the default configuration.