Detection information
The information that Arc detects. The table shows two types of Category: network and asset. When the Category is listed as network, it means that the detection is based on information that has been extracted from the network. When the Category is listed as asset, it means that the detection is based on information that has been extracted from the asset.
Category | Information | Windows |
macOS |
Linux |
Configuration option |
---|---|---|---|---|---|
network | Traffic monitoring | Traffic monitoring | |||
network | Smart Polling | Smart Polling | |||
asset | media access control (MAC) addresses | always on | |||
asset | internet protocol (IP) addresses | always on | |||
asset | Product name | always on | |||
asset | Vendor | always on | |||
asset | Label/host name | always on | |||
asset | operating system (OS) | always on | |||
asset | Serial number | always on | |||
asset | Local address resolution protocol (ARP) table | Local ARP table | |||
asset | Sigma rules | Sigma rules | |||
asset | universal serial bus (USB) detections | USB detections | |||
asset | central processing unit (CPU) usage | node points | |||
asset | Memory usage | node points | |||
asset | Disk usage | node points | |||
asset | Installed software | node points | |||
asset | Hotfixes | node points | |||
asset | Antivirus | node points | |||
asset | Log4j detection | node points | |||
asset | User accounts | node points | |||
asset | Logged in users | node points | |||
asset | USB interfaces | node points | |||
asset | Network interfaces | node points | |||
asset | Processes and ports | node points | |||
asset | Disk partitions | node points | |||
asset | domain name server (DNS) | node points | |||
asset | CPU | node points |