Settings
Account & Instance
Organization and console configuration
Organization Name
Instance ID
Region
Console Language
Timezone
Agent Configuration
Behavior and update settings applied to all agents
Auto-Update Agents
Automatically push new agent versions when available
Require Agent Tamper Protection
Prevent users from stopping or removing the agent without authorization
Full Disk Scan on Agent Install
Run a full scan immediately after agent deployment
Scheduled Scan
Weekly full disk scan every Sunday at 02:00 UTC
Cloud Intelligence (Reputation API)
Enhance local AI decisions with real-time cloud threat intelligence
Offline Protection Mode
Agents continue protecting in Detect mode when network is unavailable
SIEM Integration
Stream events and alerts to your SIEM
Enable SIEM Forwarding
Stream all detection events to the configured endpoint
SIEM Endpoint URL
Protocol
Include Raw Event Data
Send full telemetry payload alongside detection metadata
Forward Informational Events
Send process, file, and network events in addition to threats
Connected
Last event: 00:03:14 ago
API Access
API token for programmatic access and integrations
API Token
Created May 01, 2024 · Last used 2 hours ago
API Base URL
Enable API Access
Allow programmatic access to this console via the REST API
Notifications
Alert channels and delivery rules
Email: Critical Threats
Send email on all Critical severity detections
Email: High Threats
Send email on all High severity detections
Email: Medium & Low
Send email on Medium and Low severity detections
Weekly Summary Digest
Send a summary email every Monday at 08:00 UTC
Notification Email
Users & Roles
Console access and role assignments
P
Security Analyst
S
Admin
D
Viewer