Dependencies
To enable all the functions of Arc, you need to have certain items installed on the host machine.
Feature | Windows | Linux | macOS |
---|---|---|---|
Sigma rules | Sysmon | Not supported | Not supported |
PowerShell-script block-logging | |||
PowerShell Core-script block-logging | |||
USB detections | USBPcap | Not supported | Not supported |
Traffic monitoring | WinPcap or Npcap | Not needed | libpcap |
Asset details | Not needed | dmidecode | Not needed |
Users have to install dependencies. To install the dependencies manually, download them and install them individually. Alternatively, you can use a mobile device management (MDM) tool to install them across the managed network.
Windows
On Windows, you can use the command
install_dependencies
to
automatically install these dependencies on the target machine:For Sysmon, the installation is semi-automatic. First, you must upload the latest Sysmon bundle to the applicable Guardian page. The bundle is then used for automatic installation during subsequent deployments.
If Arc is connected to Vantage, Sysmon is automatically fetched from the original website, and no other actions are required.
Note: After you have installed USBPcap,
you must reboot the host machine to make the dependency active.
Note: After a dependency is installed, you must restart Arc to make it
active. When Guardian automatically installs dependencies during deployment, no user
actions are necessary.