Dependencies
To enable all the functions of Arc, you need to have certain items installed on the host machine.
Sigma rules | Sysmon |
PowerShell-script block-logging | |
PowerShell Core-script block-logging | |
USB detections | USBPcap |
Traffic monitoring | WinPcap or Npcap |
Asset details | Not needed |
Sigma rules | Not supported |
USB detections | Not supported |
Traffic monitoring | Not needed |
Asset details | dmidecode |
Sigma rules | Not supported |
USB detections | Not supported |
Traffic monitoring | libpcap |
Asset details | Not needed |
During Automatic deployment, dependencies are also installed. To install the dependencies manually, download them and install them individually. Alternatively, you can use a mobile device management (MDM) tool to install them across the managed network.
Windows
install_dependencies
to
automatically install these dependencies on the target machine:For Sysmon, the installation is semi-automatic. First, you must upload the latest Sysmon bundle to the applicable Guardian page. The bundle is then used for automatic installation during subsequent deployments.
If Arc is connected to Vantage, Sysmon is automatically fetched from the original website, and no other actions are required.