General
Is the SamurAI Endpoint Agent available to all clients?
Yes, the SamurAI Endpoint Agent is available to all SamurAI Managed Detection & Response (MDR) clients.
Is the SamurAI Endpoint Agent an Endpoint Detection & Response (EDR) product?
No, despite having similar capabilities to commercial EDR solutions it is not intended as a replacement. The intent is for a SamurAI platform native agent, allowing full customization, built and configured in support of SamurAI Managed Detection & Response (MDR) and Incident Response engagements.
I already have an EDR (e.g Crowdstrike, Microsoft Defender), do I need the SamurAI Endpoint Agent?
The SamurAI Endpoint Agent is optional, however there are advantages to its use such as the ability to gather advanced data and metrics optimized specifically for the SamurAI platform and detection engines in addition to aiding our SOC analysts to investigate and validate threats.
Can I use the SamurAI Endpoint Agent in conjunction with my current EDR?
Yes, the SamurAI Endpoint Agent can run in conjunction with your existing EDR solution for maximum visibility and response.
Are there any known limitations or problems with running the SamurAI Endpoint Agent in addition to my deployed agents?
The SamurAI Endpoint Agent has been tested alongside other agents e.g EDR solutions, and no limitations or problems were identified. In some cases you may need to 'whitelist' the SamurAI Endpoint Agent on your existing EDR deployments to ensure no issues. As the SamurAI Endpoint Agent is lightweight with a low footprint, resource contention is unlikely but is highly dependant on the underlying endpoint and network connectivity.
There is a potential for duplicate security alerts, however the SamurAI platform handles this.
What type of data does the SamurAI Endpoint Agent collect from the host?
This is dependant on the underlying operating system, however for Microsoft Windows we gather event data using System Monitor (Sysmon) which is part of the Sysinternals Suite developed by Microsoft (if you have accepted the Microsoft UELA see SamurAI Endpoint Agent for Windows for additional information).
We leverage a custom Sysmon configuration (which we maintain) that collects detailed information about system activity (logged to the Windows Event Log) to help with security monitoring and investigations.
The SamurAI Endpoint Agent also leverages osquery which allows the SamurAI platform / SOC to query the endpoint operating system as if it were a relational database, for example gather system information (hostname,OS version, uptime), user and login activity, processes and services, networking (active network connections, listening ports).
What is the average log data volume per day for the SamurAI Endpoint Agent?
This can vary depending on the type of endpoint and activity however typically 30MB per day but can go up to approximately 200MB per day.
Support
What Operating Systems are supported?
Please review Support and Pre-requisites for a current list of supported operating systems.
Can the agent also be used and installed on server systems (e.g Windows Server 202x)
Yes, Please review Support and Pre-requisites for a current list of supported operating systems.
Can the SamurAI Endpoint Agent be installed on virtual systems? e.g within a virtualization platform where multiple virtual machines (VMs) share the same underlying hardware?)
Yes, however please adhere to supported operating systems. Please review Support and Pre-requisites for a current list of supported operating systems
Installation and Setup
What network connectivity is required?
Please review Communication Pre-Requisites for network connectivity requirements.
What endpoints should I install the SamurAI Endpoint Agent on?
Ideally all endpoints – laptops, servers. Alternatively you can install the SamurAI Endpoint Agent on specific endpoints where you have limited or no EDR coverage.
Are there any restrictions on installing on a user’s PC/endpoint?
There are no restrictions on installation other than supported OS and connectivity requirements.
Is it possible to install the SamurAI Endpoint Agent remotely?
It is your responsibility to deploy the SamurAI Endpoint Agent after download from the SamurAI portal. We recommend deploying the SamurAI Endpoint Agent using your organization's preferred software distribution tools.
For Windows environments, this may include Group Policy Objects (GPO) in an Active Directory domain or Microsoft Intune for cloud-based management.
Management
How often are SamurAI Endpoint Agents updates available?
We periodically make SamurAI Endpoint Agent software updates as needed to ensure the latest enhancements are available. We keep you updated via announcements in the SamurAI Portal and the latest Release Notes.
How do I update deployed SamurAI Endpoint Agents?
You can update automatically or choose how and when to update deployed SamurAI Endpoint Agents. Please review Agent Updates.
Why is the term Node(s) used in the SamurAI Portal?
A Node is a registered instance of an Endpoint with the SamurAI Endpoint Agent installed. Please review the SamurAI Glossary of Terms.
Why is the name Spiral used in folder paths and services names?
The SamurAI Endpoint Agent operates under the name Spiral, which are expected internal identifiers by the SamurAI platform.