Dependencies
To enable all the functions of Arc, you need to have certain items installed on the host machine.
| Sigma rules | Sysmon |
| PowerShell-script block-logging | |
| PowerShell Core-script block-logging | |
| USB detections | USBPcap |
| Traffic monitoring | Npcap |
| Asset details | Not needed |
| Threat Prevention | EaseFilter (optional, for enhanced real-time performance) |
| Compliance scanning | SCAP Compliance Checker (SCC) |
| Sigma rules | Not supported |
| USB detections | Not supported |
| Traffic monitoring | Not needed |
| Asset details | dmidecode |
| Compliance scanning | SCC |
| Sigma rules | Not supported |
| USB detections | Not supported |
| Traffic monitoring | libpcap |
| Asset details | Not needed |
| Compliance scanning | SCC |
During Automatic deployment, dependencies are also installed. To install the dependencies manually, download them and install them individually. Alternatively, you can use a mobile device management (MDM) tool to install them across the managed network.
SCC is never installed by default on any platform. On Windows it can be installed through the Arc setup when connected to Vantage. On Linux and macOS, SCC needs to be downloaded from the Arc dependencies page on Vantage and installed manually. Arc detects an existing installation automatically on any platform. For more information about Compliance scanning on Arc, see Compliance scanning.
Windows
install_dependencies to
automatically install these dependencies on the target machine:- PowerShell-script block-logging
- PowerShell Core-script block-logging
- USBPcap
- Npcap
- SCC
- EaseFilter
Since Windows 11 24H2 (build 26100.8037) or Windows Server 2025 (build 26100), Windows includes Sysmon as a native component. Neither Arc nor Guardian can install it, and you cannot install it manually either.
Windows 7, 8, 10, and Windows 11 builds earlier than 26100.8037 do not include Sysmon, so you must install it. For Sysmon, the installation is semi-automatic. First, you must upload the latest Sysmon bundle to the applicable Guardian page. Guardian then uses the bundle for automatic installation during subsequent deployments.
If you are connected to Vantage, or to a Guardian with Vantage as upstream, Vantage automatically fetches Sysmon from the Microsoft website. You do not need to take any further action.