[{"data":1,"prerenderedAt":744},["ShallowReactive",2],{"docs-nav-docs_en":3,"i-lucide:menu":451,"i-lucide:search":455,"i-lucide:chevron-down":457,"docs-\u002Fdocs\u002Fagent\u002Foverview":459,"docs-surround-\u002Fdocs\u002Fagent\u002Foverview":734,"docs-section-\u002Fdocs\u002Fagent":737,"i-lucide:chevron-right":738,"i-lucide:arrow-left":740,"i-lucide:arrow-right":742},[4],{"title":5,"path":6,"stem":7,"children":8},"Docs","\u002Fdocs","docs",[9,15,51,111,168,199,233,275,305,339,357,399,421],{"title":10,"path":6,"stem":11,"order":12,"badge":13,"navTitle":14},"XenXDR documentation","docs\u002Findex",0,null,"Overview",{"title":16,"path":17,"stem":18,"children":19,"order":12,"badge":13,"navTitle":16},"Getting started","\u002Fdocs\u002Fgetting-started","docs\u002F01.getting-started\u002Findex",[20,21,26,31,36,41,46],{"title":16,"path":17,"stem":18,"order":12,"badge":13,"navTitle":16},{"title":22,"path":23,"stem":24,"order":25,"badge":13,"navTitle":14},"Platform overview","\u002Fdocs\u002Fgetting-started\u002Foverview","docs\u002F01.getting-started\u002F01.overview",1,{"title":27,"path":28,"stem":29,"order":30,"badge":13,"navTitle":13},"Requirements and sizing","\u002Fdocs\u002Fgetting-started\u002Frequirements","docs\u002F01.getting-started\u002F02.requirements",2,{"title":32,"path":33,"stem":34,"order":35,"badge":13,"navTitle":13},"Install with Docker Compose","\u002Fdocs\u002Fgetting-started\u002Finstall","docs\u002F01.getting-started\u002F03.install",3,{"title":37,"path":38,"stem":39,"order":40,"badge":13,"navTitle":13},"Single sign-on","\u002Fdocs\u002Fgetting-started\u002Fsingle-sign-on","docs\u002F01.getting-started\u002F04.single-sign-on",4,{"title":42,"path":43,"stem":44,"order":45,"badge":13,"navTitle":13},"First hour checklist","\u002Fdocs\u002Fgetting-started\u002Ffirst-hour","docs\u002F01.getting-started\u002F05.first-hour",5,{"title":47,"path":48,"stem":49,"order":50,"badge":13,"navTitle":13},"Production hardening checklist","\u002Fdocs\u002Fgetting-started\u002Fhardening","docs\u002F01.getting-started\u002F06.hardening",6,{"title":52,"path":53,"stem":54,"children":55,"order":12,"badge":13,"navTitle":52},"Endpoint agent","\u002Fdocs\u002Fagent","docs\u002F02.agent\u002Findex",[56,57,61,65,69,73,77,81,86,91,96,101,106],{"title":52,"path":53,"stem":54,"order":12,"badge":13,"navTitle":52},{"title":58,"path":59,"stem":60,"order":25,"badge":13,"navTitle":14},"Agent overview","\u002Fdocs\u002Fagent\u002Foverview","docs\u002F02.agent\u002F01.overview",{"title":62,"path":63,"stem":64,"order":30,"badge":13,"navTitle":13},"Supported platforms","\u002Fdocs\u002Fagent\u002Fsupported-platforms","docs\u002F02.agent\u002F02.supported-platforms",{"title":66,"path":67,"stem":68,"order":35,"badge":13,"navTitle":13},"Install on Windows","\u002Fdocs\u002Fagent\u002Finstall-windows","docs\u002F02.agent\u002F03.install-windows",{"title":70,"path":71,"stem":72,"order":40,"badge":13,"navTitle":13},"Install on Linux","\u002Fdocs\u002Fagent\u002Finstall-linux","docs\u002F02.agent\u002F04.install-linux",{"title":74,"path":75,"stem":76,"order":45,"badge":13,"navTitle":13},"Installer bundles and enrolment","\u002Fdocs\u002Fagent\u002Finstaller-bundles","docs\u002F02.agent\u002F05.installer-bundles",{"title":78,"path":79,"stem":80,"order":50,"badge":13,"navTitle":13},"Telemetry","\u002Fdocs\u002Fagent\u002Ftelemetry","docs\u002F02.agent\u002F06.telemetry",{"title":82,"path":83,"stem":84,"order":85,"badge":13,"navTitle":13},"Live response","\u002Fdocs\u002Fagent\u002Flive-response","docs\u002F02.agent\u002F07.live-response",7,{"title":87,"path":88,"stem":89,"order":90,"badge":13,"navTitle":13},"Network isolation","\u002Fdocs\u002Fagent\u002Fnetwork-isolation","docs\u002F02.agent\u002F08.network-isolation",8,{"title":92,"path":93,"stem":94,"order":95,"badge":13,"navTitle":13},"Application control","\u002Fdocs\u002Fagent\u002Fapplication-control","docs\u002F02.agent\u002F09.application-control",9,{"title":97,"path":98,"stem":99,"order":100,"badge":13,"navTitle":13},"Quick triage","\u002Fdocs\u002Fagent\u002Fquick-triage","docs\u002F02.agent\u002F10.quick-triage",10,{"title":102,"path":103,"stem":104,"order":105,"badge":13,"navTitle":13},"Updates","\u002Fdocs\u002Fagent\u002Fupdates","docs\u002F02.agent\u002F11.updates",11,{"title":107,"path":108,"stem":109,"order":110,"badge":13,"navTitle":13},"Troubleshooting the agent","\u002Fdocs\u002Fagent\u002Ftroubleshooting","docs\u002F02.agent\u002F12.troubleshooting",12,{"title":112,"path":113,"stem":114,"children":115,"order":12,"badge":13,"navTitle":112},"Data sources","\u002Fdocs\u002Fdata-sources","docs\u002F03.data-sources\u002Findex",[116,117,121,125,129,133,137,141,145,164],{"title":112,"path":113,"stem":114,"order":12,"badge":13,"navTitle":112},{"title":118,"path":119,"stem":120,"order":25,"badge":13,"navTitle":14},"Data sources overview","\u002Fdocs\u002Fdata-sources\u002Foverview","docs\u002F03.data-sources\u002F01.overview",{"title":122,"path":123,"stem":124,"order":30,"badge":13,"navTitle":13},"Ingest keys","\u002Fdocs\u002Fdata-sources\u002Fingest-keys","docs\u002F03.data-sources\u002F02.ingest-keys",{"title":126,"path":127,"stem":128,"order":35,"badge":13,"navTitle":13},"Beats","\u002Fdocs\u002Fdata-sources\u002Fbeats","docs\u002F03.data-sources\u002F03.beats",{"title":130,"path":131,"stem":132,"order":40,"badge":13,"navTitle":13},"Syslog, CEF and LEEF","\u002Fdocs\u002Fdata-sources\u002Fsyslog","docs\u002F03.data-sources\u002F04.syslog",{"title":134,"path":135,"stem":136,"order":45,"badge":13,"navTitle":13},"HTTP JSON","\u002Fdocs\u002Fdata-sources\u002Fhttp-json","docs\u002F03.data-sources\u002F05.http-json",{"title":138,"path":139,"stem":140,"order":50,"badge":13,"navTitle":13},"Splunk HEC","\u002Fdocs\u002Fdata-sources\u002Fsplunk-hec","docs\u002F03.data-sources\u002F06.splunk-hec",{"title":142,"path":143,"stem":144,"order":85,"badge":13,"navTitle":13},"Data source catalog","\u002Fdocs\u002Fdata-sources\u002Fcatalog","docs\u002F03.data-sources\u002F07.catalog",{"title":146,"path":147,"stem":148,"children":149,"order":12,"badge":13,"navTitle":146},"Connectors","\u002Fdocs\u002Fdata-sources\u002Fconnectors","docs\u002F03.data-sources\u002F08.connectors\u002Findex",[150,151,155,159],{"title":146,"path":147,"stem":148,"order":12,"badge":13,"navTitle":146},{"title":152,"path":153,"stem":154,"order":25,"badge":13,"navTitle":13},"Okta System Log","\u002Fdocs\u002Fdata-sources\u002Fconnectors\u002Fokta","docs\u002F03.data-sources\u002F08.connectors\u002F01.okta",{"title":156,"path":157,"stem":158,"order":30,"badge":13,"navTitle":13},"Microsoft Entra ID and Microsoft 365","\u002Fdocs\u002Fdata-sources\u002Fconnectors\u002Fmicrosoft-entra","docs\u002F03.data-sources\u002F08.connectors\u002F02.microsoft-entra",{"title":160,"path":161,"stem":162,"order":35,"badge":163,"navTitle":13},"Connectors coming soon","\u002Fdocs\u002Fdata-sources\u002Fconnectors\u002Fcoming-soon","docs\u002F03.data-sources\u002F08.connectors\u002F03.coming-soon","coming-soon",{"title":165,"path":166,"stem":167,"order":95,"badge":13,"navTitle":13},"Threat intelligence","\u002Fdocs\u002Fdata-sources\u002Fthreat-intel","docs\u002F03.data-sources\u002F09.threat-intel",{"title":169,"path":170,"stem":171,"children":172,"order":12,"badge":13,"navTitle":169},"Search","\u002Fdocs\u002Fsearch","docs\u002F04.search\u002Findex",[173,174,179,183,187,191,195],{"title":169,"path":170,"stem":171,"order":12,"badge":13,"navTitle":169},{"title":175,"path":176,"stem":177,"order":25,"badge":13,"navTitle":178},"The Logs page","\u002Fdocs\u002Fsearch\u002Fdiscover","docs\u002F04.search\u002F01.discover","Logs page tour",{"title":180,"path":181,"stem":182,"order":30,"badge":13,"navTitle":13},"Query syntax","\u002Fdocs\u002Fsearch\u002Fquery-syntax","docs\u002F04.search\u002F02.query-syntax",{"title":184,"path":185,"stem":186,"order":35,"badge":13,"navTitle":13},"Keyboard shortcuts","\u002Fdocs\u002Fsearch\u002Fkeyboard","docs\u002F04.search\u002F03.keyboard",{"title":188,"path":189,"stem":190,"order":40,"badge":13,"navTitle":13},"Saved views and search tabs","\u002Fdocs\u002Fsearch\u002Fsaved-views","docs\u002F04.search\u002F04.saved-views",{"title":192,"path":193,"stem":194,"order":45,"badge":13,"navTitle":13},"AI Hunt","\u002Fdocs\u002Fsearch\u002Fai-hunt","docs\u002F04.search\u002F05.ai-hunt",{"title":196,"path":197,"stem":198,"order":50,"badge":13,"navTitle":13},"Field dictionary","\u002Fdocs\u002Fsearch\u002Ffield-dictionary","docs\u002F04.search\u002F06.field-dictionary",{"title":200,"path":201,"stem":202,"children":203,"order":12,"badge":13,"navTitle":200},"Detections","\u002Fdocs\u002Fdetections","docs\u002F05.detections\u002Findex",[204,205,209,213,217,221,225,229],{"title":200,"path":201,"stem":202,"order":12,"badge":13,"navTitle":200},{"title":206,"path":207,"stem":208,"order":25,"badge":13,"navTitle":14},"Detections overview","\u002Fdocs\u002Fdetections\u002Foverview","docs\u002F05.detections\u002F01.overview",{"title":210,"path":211,"stem":212,"order":30,"badge":13,"navTitle":13},"Writing rules","\u002Fdocs\u002Fdetections\u002Fwriting-rules","docs\u002F05.detections\u002F02.writing-rules",{"title":214,"path":215,"stem":216,"order":35,"badge":13,"navTitle":13},"Importing rules","\u002Fdocs\u002Fdetections\u002Fimporting","docs\u002F05.detections\u002F03.importing",{"title":218,"path":219,"stem":220,"order":40,"badge":13,"navTitle":13},"Content pack","\u002Fdocs\u002Fdetections\u002Fcontent-pack","docs\u002F05.detections\u002F04.content-pack",{"title":222,"path":223,"stem":224,"order":45,"badge":13,"navTitle":13},"Exceptions and suppressions","\u002Fdocs\u002Fdetections\u002Fexceptions-suppressions","docs\u002F05.detections\u002F05.exceptions-suppressions",{"title":226,"path":227,"stem":228,"order":50,"badge":13,"navTitle":13},"ATT&CK coverage","\u002Fdocs\u002Fdetections\u002Fattack-coverage","docs\u002F05.detections\u002F06.attack-coverage",{"title":230,"path":231,"stem":232,"order":85,"badge":13,"navTitle":13},"Baseline signals","\u002Fdocs\u002Fdetections\u002Fbaseline-signals","docs\u002F05.detections\u002F07.baseline-signals",{"title":234,"path":235,"stem":236,"children":237,"order":12,"badge":13,"navTitle":234},"Operations","\u002Fdocs\u002Foperations","docs\u002F06.operations\u002Findex",[238,239,243,247,251,255,259,263,267,271],{"title":234,"path":235,"stem":236,"order":12,"badge":13,"navTitle":234},{"title":240,"path":241,"stem":242,"order":25,"badge":13,"navTitle":13},"Alerts","\u002Fdocs\u002Foperations\u002Falerts","docs\u002F06.operations\u002F01.alerts",{"title":244,"path":245,"stem":246,"order":30,"badge":13,"navTitle":13},"Correlations","\u002Fdocs\u002Foperations\u002Fcorrelations","docs\u002F06.operations\u002F02.correlations",{"title":248,"path":249,"stem":250,"order":35,"badge":13,"navTitle":13},"Cases","\u002Fdocs\u002Foperations\u002Fcases","docs\u002F06.operations\u002F03.cases",{"title":252,"path":253,"stem":254,"order":40,"badge":13,"navTitle":13},"Case categories","\u002Fdocs\u002Foperations\u002Fcase-categories","docs\u002F06.operations\u002F04.case-categories",{"title":256,"path":257,"stem":258,"order":45,"badge":13,"navTitle":13},"SLA","\u002Fdocs\u002Foperations\u002Fsla","docs\u002F06.operations\u002F05.sla",{"title":260,"path":261,"stem":262,"order":50,"badge":13,"navTitle":13},"Reports","\u002Fdocs\u002Foperations\u002Freports","docs\u002F06.operations\u002F06.reports",{"title":264,"path":265,"stem":266,"order":85,"badge":13,"navTitle":13},"Tickets","\u002Fdocs\u002Foperations\u002Ftickets","docs\u002F06.operations\u002F07.tickets",{"title":268,"path":269,"stem":270,"order":90,"badge":13,"navTitle":13},"Notifications","\u002Fdocs\u002Foperations\u002Fnotifications","docs\u002F06.operations\u002F08.notifications",{"title":272,"path":273,"stem":274,"order":95,"badge":13,"navTitle":13},"Dashboards","\u002Fdocs\u002Foperations\u002Fdashboards","docs\u002F06.operations\u002F09.dashboards",{"title":276,"path":277,"stem":278,"children":279,"order":12,"badge":13,"navTitle":276},"AI","\u002Fdocs\u002Fai","docs\u002F07.ai\u002Findex",[280,281,285,289,293,297,301],{"title":276,"path":277,"stem":278,"order":12,"badge":13,"navTitle":276},{"title":282,"path":283,"stem":284,"order":25,"badge":13,"navTitle":14},"AI overview","\u002Fdocs\u002Fai\u002Foverview","docs\u002F07.ai\u002F01.overview",{"title":286,"path":287,"stem":288,"order":30,"badge":13,"navTitle":13},"Triage verdicts","\u002Fdocs\u002Fai\u002Ftriage-verdicts","docs\u002F07.ai\u002F02.triage-verdicts",{"title":290,"path":291,"stem":292,"order":35,"badge":13,"navTitle":13},"Investigation agent","\u002Fdocs\u002Fai\u002Finvestigation-agent","docs\u002F07.ai\u002F03.investigation-agent",{"title":294,"path":295,"stem":296,"order":40,"badge":13,"navTitle":13},"Notes, handovers and report drafts","\u002Fdocs\u002Fai\u002Fnotes-and-reports","docs\u002F07.ai\u002F04.notes-and-reports",{"title":298,"path":299,"stem":300,"order":45,"badge":13,"navTitle":13},"Model setup","\u002Fdocs\u002Fai\u002Fmodel-setup","docs\u002F07.ai\u002F05.model-setup",{"title":302,"path":303,"stem":304,"order":50,"badge":13,"navTitle":13},"Feedback","\u002Fdocs\u002Fai\u002Ffeedback","docs\u002F07.ai\u002F06.feedback",{"title":306,"path":307,"stem":308,"children":309,"order":12,"badge":13,"navTitle":306},"Automation","\u002Fdocs\u002Fautomation","docs\u002F08.automation\u002Findex",[310,311,315,319,323,327,331,335],{"title":306,"path":307,"stem":308,"order":12,"badge":13,"navTitle":306},{"title":312,"path":313,"stem":314,"order":25,"badge":13,"navTitle":13},"Playbooks","\u002Fdocs\u002Fautomation\u002Fplaybooks","docs\u002F08.automation\u002F01.playbooks",{"title":316,"path":317,"stem":318,"order":30,"badge":13,"navTitle":13},"The workflow builder","\u002Fdocs\u002Fautomation\u002Fbuilder","docs\u002F08.automation\u002F02.builder",{"title":320,"path":321,"stem":322,"order":35,"badge":13,"navTitle":13},"Block reference","\u002Fdocs\u002Fautomation\u002Fblocks","docs\u002F08.automation\u002F03.blocks",{"title":324,"path":325,"stem":326,"order":40,"badge":13,"navTitle":13},"Modes and ceilings","\u002Fdocs\u002Fautomation\u002Fmodes-and-ceilings","docs\u002F08.automation\u002F04.modes-and-ceilings",{"title":328,"path":329,"stem":330,"order":45,"badge":13,"navTitle":13},"Response actions","\u002Fdocs\u002Fautomation\u002Fresponse-actions","docs\u002F08.automation\u002F05.response-actions",{"title":332,"path":333,"stem":334,"order":50,"badge":13,"navTitle":13},"Egress and notifications","\u002Fdocs\u002Fautomation\u002Fegress","docs\u002F08.automation\u002F06.egress",{"title":336,"path":337,"stem":338,"order":85,"badge":13,"navTitle":13},"Playbook runs","\u002Fdocs\u002Fautomation\u002Fruns","docs\u002F08.automation\u002F07.runs",{"title":340,"path":341,"stem":342,"children":343,"order":12,"badge":13,"navTitle":340},"Fleet","\u002Fdocs\u002Ffleet","docs\u002F09.fleet\u002Findex",[344,345,349,353],{"title":340,"path":341,"stem":342,"order":12,"badge":13,"navTitle":340},{"title":346,"path":347,"stem":348,"order":25,"badge":13,"navTitle":13},"Hosts","\u002Fdocs\u002Ffleet\u002Fhosts","docs\u002F09.fleet\u002F01.hosts",{"title":350,"path":351,"stem":352,"order":30,"badge":13,"navTitle":13},"Risk score","\u002Fdocs\u002Ffleet\u002Frisk-score","docs\u002F09.fleet\u002F02.risk-score",{"title":354,"path":355,"stem":356,"order":35,"badge":13,"navTitle":13},"Response console","\u002Fdocs\u002Ffleet\u002Fresponse-console","docs\u002F09.fleet\u002F03.response-console",{"title":358,"path":359,"stem":360,"children":361,"order":12,"badge":13,"navTitle":358},"Administration","\u002Fdocs\u002Fadministration","docs\u002F10.administration\u002Findex",[362,363,367,371,375,379,383,387,391,395],{"title":358,"path":359,"stem":360,"order":12,"badge":13,"navTitle":358},{"title":364,"path":365,"stem":366,"order":25,"badge":13,"navTitle":13},"Organizations","\u002Fdocs\u002Fadministration\u002Forganizations","docs\u002F10.administration\u002F01.organizations",{"title":368,"path":369,"stem":370,"order":30,"badge":13,"navTitle":13},"Users and roles","\u002Fdocs\u002Fadministration\u002Fusers-and-roles","docs\u002F10.administration\u002F02.users-and-roles",{"title":372,"path":373,"stem":374,"order":35,"badge":13,"navTitle":13},"Audit log","\u002Fdocs\u002Fadministration\u002Faudit-log","docs\u002F10.administration\u002F03.audit-log",{"title":376,"path":377,"stem":378,"order":40,"badge":13,"navTitle":13},"Retention","\u002Fdocs\u002Fadministration\u002Fretention","docs\u002F10.administration\u002F04.retention",{"title":380,"path":381,"stem":382,"order":45,"badge":13,"navTitle":13},"Backups and restore","\u002Fdocs\u002Fadministration\u002Fbackups","docs\u002F10.administration\u002F05.backups",{"title":384,"path":385,"stem":386,"order":50,"badge":13,"navTitle":13},"Upgrades","\u002Fdocs\u002Fadministration\u002Fupgrades","docs\u002F10.administration\u002F06.upgrades",{"title":388,"path":389,"stem":390,"order":85,"badge":13,"navTitle":13},"Monitoring the deployment","\u002Fdocs\u002Fadministration\u002Fmonitoring","docs\u002F10.administration\u002F07.monitoring",{"title":392,"path":393,"stem":394,"order":90,"badge":13,"navTitle":13},"Scaling","\u002Fdocs\u002Fadministration\u002Fscaling","docs\u002F10.administration\u002F08.scaling",{"title":396,"path":397,"stem":398,"order":95,"badge":13,"navTitle":13},"Settings reference","\u002Fdocs\u002Fadministration\u002Fsettings-reference","docs\u002F10.administration\u002F09.settings-reference",{"title":400,"path":401,"stem":402,"children":403,"order":12,"badge":13,"navTitle":400},"Customer portal","\u002Fdocs\u002Fcustomer-portal","docs\u002F11.customer-portal\u002Findex",[404,405,409,413,417],{"title":400,"path":401,"stem":402,"order":12,"badge":13,"navTitle":400},{"title":406,"path":407,"stem":408,"order":25,"badge":13,"navTitle":14},"Customer portal overview","\u002Fdocs\u002Fcustomer-portal\u002Foverview","docs\u002F11.customer-portal\u002F01.overview",{"title":410,"path":411,"stem":412,"order":30,"badge":13,"navTitle":13},"Inviting customers","\u002Fdocs\u002Fcustomer-portal\u002Finviting-customers","docs\u002F11.customer-portal\u002F02.inviting-customers",{"title":414,"path":415,"stem":416,"order":35,"badge":13,"navTitle":13},"What customers see","\u002Fdocs\u002Fcustomer-portal\u002Fwhat-customers-see","docs\u002F11.customer-portal\u002F03.what-customers-see",{"title":418,"path":419,"stem":420,"order":40,"badge":13,"navTitle":13},"Portal security","\u002Fdocs\u002Fcustomer-portal\u002Fsecurity","docs\u002F11.customer-portal\u002F04.security",{"title":422,"path":423,"stem":424,"children":425,"order":12,"badge":13,"navTitle":422},"Reference","\u002Fdocs\u002Freference","docs\u002F12.reference\u002Findex",[426,427,431,435,439,443,447],{"title":422,"path":423,"stem":424,"order":12,"badge":13,"navTitle":422},{"title":428,"path":429,"stem":430,"order":25,"badge":13,"navTitle":13},"Glossary","\u002Fdocs\u002Freference\u002Fglossary","docs\u002F12.reference\u002F01.glossary",{"title":432,"path":433,"stem":434,"order":30,"badge":13,"navTitle":13},"Support tiers","\u002Fdocs\u002Freference\u002Fsupport-tiers","docs\u002F12.reference\u002F02.support-tiers",{"title":436,"path":437,"stem":438,"order":35,"badge":13,"navTitle":13},"Compatibility","\u002Fdocs\u002Freference\u002Fcompatibility","docs\u002F12.reference\u002F03.compatibility",{"title":440,"path":441,"stem":442,"order":40,"badge":13,"navTitle":13},"Notification kinds","\u002Fdocs\u002Freference\u002Fnotification-kinds","docs\u002F12.reference\u002F04.notification-kinds",{"title":444,"path":445,"stem":446,"order":45,"badge":13,"navTitle":13},"Data source catalog (reference)","\u002Fdocs\u002Freference\u002Fdata-source-catalog","docs\u002F12.reference\u002F05.data-source-catalog",{"title":448,"path":449,"stem":450,"order":50,"badge":13,"navTitle":13},"Release notes","\u002Fdocs\u002Freference\u002Frelease-notes","docs\u002F12.reference\u002F06.release-notes",{"left":12,"top":12,"width":452,"height":452,"rotate":12,"vFlip":453,"hFlip":453,"body":454},24,false,"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M4 5h16M4 12h16M4 19h16\"\u002F>",{"left":12,"top":12,"width":452,"height":452,"rotate":12,"vFlip":453,"hFlip":453,"body":456},"\u003Cg fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\">\u003Cpath d=\"m21 21l-4.34-4.34\"\u002F>\u003Ccircle cx=\"11\" cy=\"11\" r=\"8\"\u002F>\u003C\u002Fg>",{"left":12,"top":12,"width":452,"height":452,"rotate":12,"vFlip":453,"hFlip":453,"body":458},"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"m6 9l6 6l6-6\"\u002F>",{"id":460,"title":58,"audience":13,"badge":13,"body":461,"description":728,"extension":729,"meta":730,"navTitle":14,"navigation":731,"order":25,"path":59,"seo":732,"stem":60,"updated":13,"__hash__":733},"docs_en\u002Fdocs\u002F02.agent\u002F01.overview.md",{"type":462,"value":463,"toc":719},"minimark",[464,469,473,490,501,505,541,548,552,619,622,626,629,633,707,711,714],[465,466,468],"h2",{"id":467},"one-agent-one-service","One agent, one service",[470,471,472],"p",{},"The XenXDR agent runs as a Windows service or a Linux systemd unit. It does two jobs:",[474,475,476,484],"ul",{},[477,478,479,483],"li",{},[480,481,482],"strong",{},"collect",": send the host's security telemetry to the deployment over TLS;",[477,485,486,489],{},[480,487,488],{},"respond",": give an analyst a live console on the host: processes, files, a shell, network isolation, application control, a triage snapshot.",[470,491,492,493,496,497,500],{},"It installs and updates ",[480,494,495],{},"without a reboot"," and connects ",[480,498,499],{},"outbound only",". Every command an analyst runs reaches the host over the agent's authenticated, encrypted connection with the analyst's identity attached.",[465,502,504],{"id":503},"what-it-collects","What it collects",[506,507,508,521],"table",{},[509,510,511],"thead",{},[512,513,514,518],"tr",{},[515,516,517],"th",{},"Platform",[515,519,520],{},"Sources",[522,523,524,533],"tbody",{},[512,525,526,530],{},[527,528,529],"td",{},"Windows",[527,531,532],{},"Windows Event Log channels including Security, System and PowerShell; Sysmon; Microsoft Defender Antivirus detections.",[512,534,535,538],{},[527,536,537],{},"Linux",[527,539,540],{},"journald, SSH and sudo authentication, auditd.",[470,542,543,544,547],{},"The fleet policy for the organization decides what each host collects. See ",[545,546,78],"a",{"href":79},".",[465,549,551],{"id":550},"what-it-can-do","What it can do",[506,553,554,564],{},[509,555,556],{},[512,557,558,561],{},[515,559,560],{},"Capability",[515,562,563],{},"Summary",[522,565,566,574,582,590,597,604,611],{},[512,567,568,571],{},[527,569,570],{},"Processes",[527,572,573],{},"List, kill, suspend, resume.",[512,575,576,579],{},[527,577,578],{},"Files",[527,580,581],{},"Browse, stat, preview, hash, collect.",[512,583,584,587],{},[527,585,586],{},"Live shell",[527,588,589],{},"Interactive terminal on the host.",[512,591,592,594],{},[527,593,87],{},[527,595,596],{},"Five containment modes, lease-based, reboot-safe.",[512,598,599,601],{},[527,600,92],{},[527,602,603],{},"Block and unblock by image or hash.",[512,605,606,608],{},[527,607,97],{},[527,609,610],{},"One-shot snapshot of the places that matter.",[512,612,613,616],{},[527,614,615],{},"Security tool availability",[527,617,618],{},"Reports when a required tool goes down.",[470,620,621],{},"Each capability has its own page in this section.",[465,623,625],{"id":624},"size-and-footprint","Size and footprint",[470,627,628],{},"The Windows agent is about 12 MB and the Linux agent about 13 MB on disk, with a light memory footprint. The Windows tray helper, if deployed, is a separate 4 MB executable with read-only access to agent status.",[465,630,632],{"id":631},"where-it-lives","Where it lives",[506,634,635,645],{},[509,636,637],{},[512,638,639,641,643],{},[515,640],{},[515,642,529],{},[515,644,537],{},[522,646,647,663,678,692],{},[512,648,649,652,658],{},[527,650,651],{},"Program",[527,653,654],{},[655,656,657],"code",{},"C:\\Program Files\\XenXDR",[527,659,660],{},[655,661,662],{},"\u002Fopt\u002Fxenxdr",[512,664,665,668,673],{},[527,666,667],{},"Configuration",[527,669,670],{},[655,671,672],{},"C:\\ProgramData\\XenXDR",[527,674,675],{},[655,676,677],{},"\u002Fetc\u002Fxenxdr",[512,679,680,683,687],{},[527,681,682],{},"State and spool",[527,684,685],{},[655,686,672],{},[527,688,689],{},[655,690,691],{},"\u002Fvar\u002Flib\u002Fxenxdr",[512,693,694,697,702],{},[527,695,696],{},"Service name",[527,698,699],{},[655,700,701],{},"XenXDRAgent",[527,703,704],{},[655,705,706],{},"xenxdr-agent.service",[465,708,710],{"id":709},"identity-and-trust","Identity and trust",[470,712,713],{},"At first connect the agent presents the organization's bootstrap enrolment token once and receives its own credential. From then on it authenticates with that credential, so every agent in the fleet has a credential of its own. The agent's fleet identifier is issued by XenXDR at enrolment, so a renamed or cloned machine keeps a distinct identity.",[470,715,716,717,547],{},"Updates are signed by FluenceSecurity and verified on the host against a key pinned at install time before they are applied. See ",[545,718,102],{"href":103},{"title":720,"searchDepth":35,"depth":35,"links":721},"",[722,723,724,725,726,727],{"id":467,"depth":30,"text":468},{"id":503,"depth":30,"text":504},{"id":550,"depth":30,"text":551},{"id":624,"depth":30,"text":625},{"id":631,"depth":30,"text":632},{"id":709,"depth":30,"text":710},"What the XenXDR endpoint agent is and what it does on the host.","md",{},true,{"title":58,"description":728},"0Qv7ts-PGY_Whd-oX2k7f0YrqI3Hv0IfSy7_Ve6mFCk",[735,736],{"title":52,"path":53,"stem":54,"children":-1},{"title":62,"path":63,"stem":64,"children":-1},{"title":52,"navTitle":52},{"left":12,"top":12,"width":452,"height":452,"rotate":12,"vFlip":453,"hFlip":453,"body":739},"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"m9 18l6-6l-6-6\"\u002F>",{"left":12,"top":12,"width":452,"height":452,"rotate":12,"vFlip":453,"hFlip":453,"body":741},"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"m12 19l-7-7l7-7m7 7H5\"\u002F>",{"left":12,"top":12,"width":452,"height":452,"rotate":12,"vFlip":453,"hFlip":453,"body":743},"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M5 12h14m-7-7l7 7l-7 7\"\u002F>",1789936658640]