# AQUILA - All in One Endpoint Protection

### **Overview**

Install the AQUILA Endpoint Agent (AEA) to start monitoring your device and strengthen your security posture. The AQUILA Endpoint Agent (AEA) helps you scan and monitor your endpoints for Endpoint Protection, Data Loss Prevention, and Vulnerability Detection, giving you continuous visibility and control over your environment.

### **How To Install**

To install the AQUILA Endpoint Agent, access the AQUILA menu from the sidebar and select **AQUILA Store**. This action redirects you to the catalog listing for the AQUILA Endpoint Agent. Selecting **Learn More** opens the agent details page, which provides, system requirements, and publisher information.

[![HEHE.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/scaled-1680-/OXm3844AqJjlZBu6-hehe.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/OXm3844AqJjlZBu6-hehe.png)

In this interface you can download the AQUILA Endpoint Agent by pressing the get started but before we proceed on that we must need the credentials first. To get the credentials press the view credentials in order to generate token, please copy those credentials and keep it in a safe note in order to proceed in the next step.

[![HEHE (1).png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/scaled-1680-/3jscQ3nz1SvTGmwz-hehe-1.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/3jscQ3nz1SvTGmwz-hehe-1.png)

[![HEHE (5).png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/scaled-1680-/est8yzCawCynRXvX-hehe-5.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/est8yzCawCynRXvX-hehe-5.png)

After saving the credentials let's proceed to the installation of the AQUILA Endpoint Agent.

Press "**Get Started**" to download the AQUILA Endpoint Agent, please do not worry if AQUILA Endpoint Agent installer has that error saying **"AQUILA\_Endpoint\_Agent\_Installer.exe isn't commonly downloaded. Make sure you trust AQUILA\_Endpoint\_Agent\_Installer.exe before you open it."**

Security mechanisms such as **Windows SmartScreen** rely on reputation-based signals (download volume, age of the file, and digital signature prevalence). When a legitimate application is:

- Newly released or recently updated
- Downloaded by a limited number of users
- Distributed privately or outside common marketplaces
- Not yet widely recognized by SmartScreen

the system displays a cautionary message, even if the software is verified and secure.

This behavior is common for **enterprise agents, internal tools, and controlled-distribution software**. **Make sure to keep the file in order to proceed in the installation thank you.**

[![HEHE (2).png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/scaled-1680-/1YXDXzDlHHEv3uZu-hehe-2.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/1YXDXzDlHHEv3uZu-hehe-2.png)

### **Installation Process**

Allow this application to proceed in the installation

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/scaled-1680-/wiwApHUmbrWydM0C-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/wiwApHUmbrWydM0C-image.png)

Input the Client ID that was provided through the "view credentials":

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/scaled-1680-/zMmFBn8Qv3xGXryo-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/zMmFBn8Qv3xGXryo-image.png)

Input the Agent Alias that was provided through the "view credentials": :

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/scaled-1680-/UqI1trdNZspx5Zd0-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/UqI1trdNZspx5Zd0-image.png)

Input Enrollment Token that was provided through the "view credentials": :

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/scaled-1680-/ixKyaK4T9Zma7Mts-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/ixKyaK4T9Zma7Mts-image.png)

After inputting the Enrollment Token, press install to begin the installation of the AQUILA Endpoint Agent

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/scaled-1680-/QkmIipT6YtSfrC6V-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/QkmIipT6YtSfrC6V-image.png)

[![image.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/scaled-1680-/KbzFAaXSWD7FohqQ-image.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/KbzFAaXSWD7FohqQ-image.png)

And now the installation is complete.

[![hehehehe.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/scaled-1680-/kLuLcFoMvkV1Lzev-hehehehe.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/kLuLcFoMvkV1Lzev-hehehehe.png)

After the installation we can now proceed and see the scanned files through AQUILA website [usdc.cytechint.io](https://usdc-docs.cytechint.io/).

#### **Endpoint Detection and Response (EDR)**

By Navigating through **Cyber Monitoring Module**, the client can find the **Endpoint Detection and Response (EDR)** sub-module, this is where the client can locate the **Endpoint Detection and Response (EDR)** of **AQUILA Agent Endpoint.**

<p class="callout info">**Note: The name of your Endpoint is using the name of your Personal Computer (PC).**</p>

[![HEHE (4).png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/scaled-1680-/U5M1OurakBQg9l9M-hehe-4.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/U5M1OurakBQg9l9M-hehe-4.png)

Or the client can access the endpoint in the "**Control Panel**" as well to isolate it or uninstall the Endpoint Detection and Response (EDR) but be wary, **Endpoint Detection and Response (EDR)** is a separate application process of the AQUILA Agent Endpoint therefore do not uninstall the **Endpoint Detection and Response (EDR).** If the client decides to uninstall it, please contact ***<support@cytechint.com>*** to be assisted on the uninstallation for the **AQUILA Agent Endpoint. Thank you.**

[![HEHE (3).png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/scaled-1680-/6jRAOOHMORQaLzMB-hehe-3.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/6jRAOOHMORQaLzMB-hehe-3.png)

#### **Endpoint Detection and Response Capabilities**

Endpoint Detection and Response (EDR) have multiple features to offer, let's summarize each of those features that could be helpful for monitoring multiple devices.

1. Endpoint Security State - In this section, the client can identify which Endpoints are Secured, Infected, or Isolated. Which is helpful to identify which Endpoint needs remediation and needs to be isolated.
2. Endpoint Health - In this chart, it shows how many Endpoints does the client have and how many are online, unhealthy, or offline.
3. Endpoint OS Type - This section provides OS Types and how many Endpoints are installed in a specific Operating System.
4. Endpoint List - This list provides information on each Endpoints. The client can also see further information by pressing the eye icon.

[![HEHE.png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/scaled-1680-/BC26iNzNsMNkeh9P-hehe.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/BC26iNzNsMNkeh9P-hehe.png)

#### **Data Loss Prevention (DLP)**

Data Loss Prevention (DLP) is a section where the client can check if the endpoint can detect Private Data, Confidential Data, or Sensitive Data,

[![HEHE (1).png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/scaled-1680-/sgjc2lIY0zJci45h-hehe-1.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/sgjc2lIY0zJci45h-hehe-1.png)

#### **Data Loss Prevention (DLP) Capabilities**

Data Loss Prevention (DLP) has plenty of features to identify and classify files and alert which are helpful for proper monitoring on data.

1. Detection Resolution - Displays the current resolution rate of alerts generated by the DLP system. This includes how many alerts have been resolved versus those still open and require investigation.
2. Data Discover &amp; Classification - Summarizes the total number of files discovered, their combined size, and how they've been classified based on sensitivity levels.
3. Top Detection by Alert Rule - Lists the top alert rules triggered by user or system behavior, indicating which policies are being violated most frequently.
4. Current Files Being Exposed - Displays real-time visibility into sensitive or exposed files, including classification level, responsible user, and timestamp.
5. 24-Hour Alert Activity - This chart displays the number of detections categorized by the type of data involved.

[![HEHE (2).png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/scaled-1680-/G3Mds0kylkPhoc53-hehe-2.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/G3Mds0kylkPhoc53-hehe-2.png)

#### **Vulnerability Detection and Response (VDR)**

Vulnerability Detection and Response (VDR) is a section where clients can view detected vulnerabilities on their endpoints, including associated CVEs and the applications and endpoints affected by each vulnerability. Vulnerability Detection and Response (VDR) can be navigated on the sidebar inside Risk Management.

[![HEHE (3).png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/scaled-1680-/f2BsTIOv2DNCy5Cj-hehe-3.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/f2BsTIOv2DNCy5Cj-hehe-3.png)

#### **Vulnerability Detection and Response (VDR) Capabilities**

Vulnerability Detection and Response (VDR) provide multiple features to determine whether a vulnerability is currently in the process of mitigation or has already been mitigated. These vulnerabilities are based on a list of CVEs, which identify known security issues associated with vulnerable applications.

1. Total Vulnerabilities - Displays the total number of detected vulnerabilities across all endpoints and their current mitigation status.
2. Severity Breakdown - Shows the distribution of vulnerabilities based on their severity levels, helping prioritize remediation efforts.
3. Needs Attention Vulnerabilities - Lists critical or high-severity vulnerabilities that require immediate review or action.
4. Mitigated in Progress - List of the Vulnerabilities and Endpoints that are currently on process of mitigation.
5. Mitigated - List of the Vulnerabilities that are mitigated

[![HEHE (4).png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/scaled-1680-/dxxnijWWIfA0JskZ-hehe-4.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/dxxnijWWIfA0JskZ-hehe-4.png)

The client can also access the list of their endpoints and how many vulnerabilities are affected, this section can be found below the Detection.

[![HEHE (5).png](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/scaled-1680-/F9G13Z7rF9qpdvf3-hehe-5.png)](https://cytechint-docs-bookstack.s3.amazonaws.com/uploads/images/gallery/2026-01/F9G13Z7rF9qpdvf3-hehe-5.png)

1. Exposure Distribution -Shows the number of endpoints based on their current exposure level (Critical, High, Medium, Low).
2. Top 3 Vulnerable Endpoints by Exposure - Displays the three endpoints with the highest number of detected critical and high vulnerabilities, broken down by severity level.
3. Top 5 Vulnerabilities Needing Attention - Lists the vulnerabilities that impact the most endpoints and require immediate action. Prioritizes Critical and High severity.
4. Endpoint list - List of the Endpoints and # of vulnerabilities.

### **Core Capabilities**

What does it do? The AEA provides three main security functions:

#### **1. Endpoint Detection and Response (EDR)**

- Checks your device for threats such as malware, suspicious behavior, or unauthorized changes.
- Helps ensure your device is compliant with your company’s security rules.
- **<span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Prevent complex attacks</span></span>** <span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">- Prevent malware (Windows, macOS, Linux) and ransomware (Windows) from executing, and stop advanced threats with malicious behavior (Windows, macOS, Linux), memory threat (Windows, macOS, Linux), and credential hardening (Windows) protections.</span></span>
- <span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">**Alert in high fidelity** </span></span><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">- Bolster team efficacy by detecting threats centrally and minimizing false positives via extensive corroboration.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{}"> </span>
- <span class="EOP SCXW169441868 BCX0" data-ccp-props="{}">**Detect <span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">threats in high fidelity</span></span>** <span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">- </span><span class="NormalTextRun SCXW169441868 BCX0">facilitates</span><span class="NormalTextRun SCXW169441868 BCX0"> deep visibility by instrumenting the process, file, and network data in your </span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW169441868 BCX0">environments</span><span class="NormalTextRun SCXW169441868 BCX0"> with minimal data collection overhead.</span></span> </span>
- <span class="EOP SCXW169441868 BCX0" data-ccp-props="{}">**Triage <span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">and respond rapidly</span></span>**<span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> - Quickly analyze detailed data from across your hosts. Examine host-based </span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW169441868 BCX0">activity</span><span class="NormalTextRun SCXW169441868 BCX0"> with interactive visualizations. Invoke remote response actions across distributed endpoints. Extend investigation capabilities even further with the </span><span class="NormalTextRun SpellingErrorV2Themed SCXW169441868 BCX0">Osquery</span><span class="NormalTextRun SCXW169441868 BCX0"> integration, fully integrated into Security workflows.</span></span> </span>
- <span class="EOP SCXW169441868 BCX0" data-ccp-props="{}">**Secure <span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">your cloud workloads</span></span>** <span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">- Stop threats targeting cloud workloads and cloud-native applications. Gain real-time visibility and control with a lightweight user-space agent, powered by </span><span class="NormalTextRun SpellingErrorV2Themed SCXW169441868 BCX0">eBPF</span><span class="NormalTextRun SCXW169441868 BCX0">. Automate the identification of cloud threats with detection rules and machine learning (ML). Achieve rapid time-to-value with MITRE ATT&amp;CK-aligned detections.</span></span></span>
- <span class="EOP SCXW169441868 BCX0" data-ccp-props="{}"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">**View <span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US">terminal sessions</span>** - Give your security team a unique and powerful investigative tool for digital forensics and incident response (DFIR), reducing the mean time to respond (MTTR). Session view provides a time-ordered series of process executions in your Linux workloads in the form of a terminal shell, as well as the ability to replay the terminal session. </span></span></span>

##### **<span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0" data-ccp-parastyle="heading 2">🛡️</span></span>**<span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0" data-ccp-parastyle="heading 2">Protections Matrix</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335559738":299,"335559739":299}"> </span>**</span>

<div class="OutlineElement Ltr SCXW169441868 BCX0" id="bkmrk-protection-type%C2%A0-os-"><div class="TableContainer Ltr SCXW169441868 BCX0"><div aria-hidden="true" class="WACAltTextDescribedBy SCXW169441868 BCX0" id="bkmrk--19"></div><table aria-rowcount="6" border="1" class="Table Ltr TableWordWrap SCXW169441868 BCX0" data-tablelook="1696" data-tablestyle="MsoNormalTable" dir="ltr" style="width: 100%;"><tbody class="SCXW169441868 BCX0"><tr aria-rowindex="1" class="TableRow SCXW169441868 BCX0" role="row"><td class="FirstRow FirstCol SCXW169441868 BCX0" data-celllook="0" role="rowheader" style="width: 16.93%;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Protection Type</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335551550":2,"335551620":2,"335559738":0,"335559739":0}"> </span>**

</td><td class="FirstRow SCXW169441868 BCX0" data-celllook="0" role="columnheader" style="width: 17.5261%;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">OS Support</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335551550":2,"335551620":2,"335559738":0,"335559739":0}"> </span>**

</td><td class="FirstRow SCXW169441868 BCX0" data-celllook="0" role="columnheader" style="width: 7.6304%;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Detect</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335551550":2,"335551620":2,"335559738":0,"335559739":0}"> </span>**

</td><td class="FirstRow SCXW169441868 BCX0" data-celllook="0" role="columnheader" style="width: 8.46604%;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Prevent</span></span>**<span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335551550":2,"335551620":2,"335559738":0,"335559739":0}"> </span>

</td><td class="FirstRow LastCol SCXW169441868 BCX0" data-celllook="0" role="columnheader" style="width: 49.4773%;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Description</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335551550":2,"335551620":2,"335559738":0,"335559739":0}"> </span>**

</td></tr><tr aria-rowindex="2" class="TableRow SCXW169441868 BCX0" role="row"><td class="FirstCol SCXW169441868 BCX0" data-celllook="0" role="rowheader" style="width: 16.93%;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Malware</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>**

</td><td class="SCXW169441868 BCX0" data-celllook="0" style="width: 17.5261%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Windows, macOS, Linux</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="SCXW169441868 BCX0" data-celllook="0" style="width: 7.6304%;"><span class="EOP SCXW169441868 BCX0" data-ccp-props="{}"> </span>

</td><td class="SCXW169441868 BCX0 align-center" data-celllook="0" style="width: 8.46604%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0">✅</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="LastCol SCXW169441868 BCX0" data-celllook="0" style="width: 49.4773%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Blocks </span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW169441868 BCX0">known</span><span class="NormalTextRun SCXW169441868 BCX0"> malicious executables and scripts at runtime.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td></tr><tr aria-rowindex="3" class="TableRow SCXW169441868 BCX0" role="row"><td class="FirstCol SCXW169441868 BCX0" data-celllook="0" role="rowheader" style="width: 16.93%;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Ransomware</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>**

</td><td class="SCXW169441868 BCX0" data-celllook="0" style="width: 17.5261%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Windows</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="SCXW169441868 BCX0" data-celllook="0" style="width: 7.6304%;"><span class="EOP SCXW169441868 BCX0" data-ccp-props="{}"> </span>

</td><td class="SCXW169441868 BCX0 align-center" data-celllook="0" style="width: 8.46604%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0">✅</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="LastCol SCXW169441868 BCX0" data-celllook="0" style="width: 49.4773%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Detects rapid file changes and unauthorized encryption activity.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td></tr><tr aria-rowindex="4" class="TableRow SCXW169441868 BCX0" role="row"><td class="FirstCol SCXW169441868 BCX0" data-celllook="0" role="rowheader" style="width: 16.93%;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Memory Threats</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>**

</td><td class="SCXW169441868 BCX0" data-celllook="0" style="width: 17.5261%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Windows, macOS, Linux</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="SCXW169441868 BCX0" data-celllook="0" style="width: 7.6304%;"><span class="EOP SCXW169441868 BCX0" data-ccp-props="{}"> </span>

</td><td class="SCXW169441868 BCX0 align-center" data-celllook="0" style="width: 8.46604%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0">✅</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="LastCol SCXW169441868 BCX0" data-celllook="0" style="width: 49.4773%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Prevents memory-based attacks like process injection or ROP chains.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td></tr><tr aria-rowindex="5" class="TableRow SCXW169441868 BCX0" role="row"><td class="FirstCol SCXW169441868 BCX0" data-celllook="0" role="rowheader" style="width: 16.93%;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Malicious Behavior</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>**

</td><td class="SCXW169441868 BCX0" data-celllook="0" style="width: 17.5261%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Windows, macOS, Linux</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="SCXW169441868 BCX0" data-celllook="0" style="width: 7.6304%;"><span class="EOP SCXW169441868 BCX0" data-ccp-props="{}"> </span>

</td><td class="SCXW169441868 BCX0 align-center" data-celllook="0" style="width: 8.46604%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0">✅</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="LastCol SCXW169441868 BCX0" data-celllook="0" style="width: 49.4773%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Stops suspicious techniques such as abnormal child processes or </span><span class="NormalTextRun SpellingErrorV2Themed SCXW169441868 BCX0">LOLBins</span><span class="NormalTextRun SCXW169441868 BCX0">.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td></tr><tr aria-rowindex="6" class="TableRow SCXW169441868 BCX0" role="row"><td class="FirstCol LastRow SCXW169441868 BCX0" data-celllook="0" role="rowheader" style="width: 16.93%;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Credential Hardening</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>**

</td><td class="LastRow SCXW169441868 BCX0" data-celllook="0" style="width: 17.5261%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Windows</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="LastRow SCXW169441868 BCX0" data-celllook="0" style="width: 7.6304%;"><span class="EOP SCXW169441868 BCX0" data-ccp-props="{}"> </span>

</td><td class="LastRow SCXW169441868 BCX0" data-celllook="0" style="width: 8.46604%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Enabled</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="LastCol LastRow SCXW169441868 BCX0" data-celllook="0" style="width: 49.4773%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Protects credentials by preventing unauthorized LSASS access.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td></tr></tbody></table>

</div></div>##### **<span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0" data-ccp-parastyle="heading 2">📊</span></span>**<span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0" data-ccp-parastyle="heading 2">Event Collection</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335559738":299,"335559739":299}"> </span>**</span>

<div class="OutlineElement Ltr SCXW169441868 BCX0" id="bkmrk-event-type%C2%A0-windows%C2%A0"><div class="TableContainer Ltr SCXW169441868 BCX0"><div aria-hidden="true" class="WACAltTextDescribedBy SCXW169441868 BCX0" id="bkmrk--20"></div><table aria-rowcount="9" border="1" class="Table Ltr TableWordWrap SCXW169441868 BCX0" data-tablelook="1696" data-tablestyle="MsoNormalTable" dir="ltr" style="width: 100%;"><tbody class="SCXW169441868 BCX0"><tr aria-rowindex="1" class="TableRow SCXW169441868 BCX0" role="row"><td class="FirstRow FirstCol SCXW169441868 BCX0" data-celllook="0" role="rowheader" style="width: 15.8569%;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Event Type</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335551550":2,"335551620":2,"335559738":0,"335559739":0}"> </span>**

</td><td class="FirstRow SCXW169441868 BCX0 align-center" data-celllook="0" role="columnheader" style="width: 9.41878%;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Windows</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335551550":2,"335551620":2,"335559738":0,"335559739":0}"> </span>**

</td><td class="FirstRow SCXW169441868 BCX0 align-center" data-celllook="0" role="columnheader" style="width: 7.6304%;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">macOS</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335551550":2,"335551620":2,"335559738":0,"335559739":0}"> </span>**

</td><td class="FirstRow SCXW169441868 BCX0 align-center" data-celllook="0" role="columnheader" style="width: 6.43939%;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Linux</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335551550":2,"335551620":2,"335559738":0,"335559739":0}"> </span>**

</td><td class="FirstRow LastCol SCXW169441868 BCX0" data-celllook="0" role="columnheader" style="width: 60.5651%;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Description</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335551550":2,"335551620":2,"335559738":0,"335559739":0}"> </span>**

</td></tr><tr aria-rowindex="2" class="TableRow SCXW169441868 BCX0" role="row"><td class="FirstCol SCXW169441868 BCX0" data-celllook="0" role="rowheader" style="width: 15.8569%;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">API</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>**

</td><td class="SCXW169441868 BCX0 align-left" data-celllook="0" style="width: 9.41878%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0">✅</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="SCXW169441868 BCX0 align-left" data-celllook="0" style="width: 7.6304%;"> </td><td class="SCXW169441868 BCX0 align-left" data-celllook="0" style="width: 6.43939%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0">–</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="LastCol SCXW169441868 BCX0" data-celllook="0" style="width: 60.5651%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW169441868 BCX0">Logs</span><span class="NormalTextRun SCXW169441868 BCX0"> sensitive API calls that may </span><span class="NormalTextRun SCXW169441868 BCX0">indicate</span><span class="NormalTextRun SCXW169441868 BCX0"> injection or system tampering.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td></tr><tr aria-rowindex="3" class="TableRow SCXW169441868 BCX0" role="row"><td class="FirstCol SCXW169441868 BCX0" data-celllook="0" role="rowheader" style="width: 15.8569%;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">DLL &amp; Driver Load</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>**

</td><td class="SCXW169441868 BCX0 align-left" data-celllook="0" style="width: 9.41878%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> </span> <span class="NormalTextRun SCXW169441868 BCX0">✅</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="SCXW169441868 BCX0 align-left" data-celllook="0" style="width: 7.6304%;"> </td><td class="SCXW169441868 BCX0 align-left" data-celllook="0" style="width: 6.43939%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0">–</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="LastCol SCXW169441868 BCX0" data-celllook="0" style="width: 60.5651%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Captures DLL/driver loading to detect unsigned or malicious code injection.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td></tr><tr aria-rowindex="4" class="TableRow SCXW169441868 BCX0" role="row"><td class="FirstCol SCXW169441868 BCX0" data-celllook="0" role="rowheader" style="width: 15.8569%;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">DNS</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>**

</td><td class="SCXW169441868 BCX0 align-left" data-celllook="0" style="width: 9.41878%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0"> </span> <span class="NormalTextRun SCXW169441868 BCX0">✅</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="SCXW169441868 BCX0 align-left" data-celllook="0" style="width: 7.6304%;"> </td><td class="SCXW169441868 BCX0 align-left" data-celllook="0" style="width: 6.43939%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0">–</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="LastCol SCXW169441868 BCX0" data-celllook="0" style="width: 60.5651%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW169441868 BCX0">Records</span><span class="NormalTextRun SCXW169441868 BCX0"> DNS queries/responses to spot C2, tunneling, or data exfiltration.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td></tr><tr aria-rowindex="5" class="TableRow SCXW169441868 BCX0" role="row"><td class="FirstCol SCXW169441868 BCX0" data-celllook="0" role="rowheader" style="width: 15.8569%;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">File</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>**

</td><td class="SCXW169441868 BCX0 align-left" data-celllook="0" style="width: 9.41878%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0"> </span> <span class="NormalTextRun SCXW169441868 BCX0">✅</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="SCXW169441868 BCX0 align-left" data-celllook="0" style="width: 7.6304%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> </span> <span class="NormalTextRun SCXW169441868 BCX0">✅</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="SCXW169441868 BCX0 align-left" data-celllook="0" style="width: 6.43939%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0">✅</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="LastCol SCXW169441868 BCX0" data-celllook="0" style="width: 60.5651%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Monitors file creation, deletion, and modification to detect malware or ransomware.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td></tr><tr aria-rowindex="6" class="TableRow SCXW169441868 BCX0" role="row"><td class="FirstCol SCXW169441868 BCX0" data-celllook="0" role="rowheader" style="width: 15.8569%;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Network</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>**

</td><td class="SCXW169441868 BCX0 align-left" data-celllook="0" style="width: 9.41878%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0"> </span> <span class="NormalTextRun SCXW169441868 BCX0">✅</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="SCXW169441868 BCX0 align-left" data-celllook="0" style="width: 7.6304%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0"> </span> <span class="NormalTextRun SCXW169441868 BCX0">✅</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="SCXW169441868 BCX0 align-left" data-celllook="0" style="width: 6.43939%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0">✅</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="LastCol SCXW169441868 BCX0" data-celllook="0" style="width: 60.5651%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW169441868 BCX0">Logs</span><span class="NormalTextRun SCXW169441868 BCX0"> connections, ports, and protocols to uncover C2 traffic or lateral movement.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td></tr><tr aria-rowindex="7" class="TableRow SCXW169441868 BCX0" role="row"><td class="FirstCol SCXW169441868 BCX0" data-celllook="0" role="rowheader" style="width: 15.8569%;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Process</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>**

</td><td class="SCXW169441868 BCX0 align-left" data-celllook="0" style="width: 9.41878%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0"> </span> <span class="NormalTextRun SCXW169441868 BCX0">✅</span><span class="NormalTextRun SCXW169441868 BCX0"> </span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="SCXW169441868 BCX0 align-left" data-celllook="0" style="width: 7.6304%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0"> </span> <span class="NormalTextRun SCXW169441868 BCX0">✅</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="SCXW169441868 BCX0 align-left" data-celllook="0" style="width: 6.43939%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0">✅</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="LastCol SCXW169441868 BCX0" data-celllook="0" style="width: 60.5651%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Tracks process execution, parent/child relationships, and suspicious spawns.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td></tr><tr aria-rowindex="8" class="TableRow SCXW169441868 BCX0" role="row"><td class="FirstCol SCXW169441868 BCX0" data-celllook="0" role="rowheader" style="width: 15.8569%;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Registry</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>**

</td><td class="SCXW169441868 BCX0 align-left" data-celllook="0" style="width: 9.41878%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0"> </span> <span class="NormalTextRun SCXW169441868 BCX0">✅</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="SCXW169441868 BCX0 align-left" data-celllook="0" style="width: 7.6304%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0"> </span> <span class="NormalTextRun SCXW169441868 BCX0">–</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="SCXW169441868 BCX0 align-left" data-celllook="0" style="width: 6.43939%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0">–</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="LastCol SCXW169441868 BCX0" data-celllook="0" style="width: 60.5651%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW169441868 BCX0">Detects</span><span class="NormalTextRun SCXW169441868 BCX0"> persistence or tampering with critical Windows registry keys.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td></tr><tr aria-rowindex="9" class="TableRow SCXW169441868 BCX0" role="row"><td class="FirstCol LastRow SCXW169441868 BCX0" data-celllook="0" role="rowheader" style="width: 15.8569%;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Security</span><span class="NormalTextRun SCXW169441868 BCX0"> </span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>**

</td><td class="LastRow SCXW169441868 BCX0 align-left" data-celllook="0" style="width: 9.41878%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0"> </span> <span class="NormalTextRun SCXW169441868 BCX0">✅</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="LastRow SCXW169441868 BCX0 align-left" data-celllook="0" style="width: 7.6304%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0"> </span> <span class="NormalTextRun SCXW169441868 BCX0">–</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="LastRow SCXW169441868 BCX0 align-left" data-celllook="0" style="width: 6.43939%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> </span><span class="NormalTextRun SCXW169441868 BCX0">–</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="LastCol LastRow SCXW169441868 BCX0" data-celllook="0" style="width: 60.5651%;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Captures login attempts, privilege changes, and policy modifications.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td></tr></tbody></table>

</div></div>##### **<span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0" data-ccp-parastyle="heading 2">⚙️</span></span>**<span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0" data-ccp-parastyle="heading 2">Windows Antivirus Registration</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335559738":299,"335559739":299}"> </span>**</span>

<div class="SCXW169441868 BCX0" id="bkmrk-aquila-edr-can%C2%A0regis"><div class="ListContainerWrapper SCXW169441868 BCX0">- <span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">AQUILA EDR can </span></span><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">register as the primary antivirus</span></span><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> through Windows Security Center.</span></span>
- <span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Not supported on </span></span><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Windows Server</span></span><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> (no Security Center available).</span></span>
- <span class="NormalTextRun SCXW169441868 BCX0">Enable</span><span class="NormalTextRun SCXW169441868 BCX0">d</span><span class="NormalTextRun SCXW169441868 BCX0"> to register </span><span class="NormalTextRun SCXW169441868 BCX0">AQUILA EDR</span><span class="NormalTextRun SCXW169441868 BCX0"> as an official Antivirus solution for Windows OS. This will also disable Windows Defender.</span>
- <span class="NormalTextRun SCXW169441868 BCX0">Current configuration: </span><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">S</span><span class="NormalTextRun SCXW169441868 BCX0">ync with malware </span><span class="NormalTextRun SCXW169441868 BCX0">protectio</span><span class="NormalTextRun SCXW169441868 BCX0">n level</span><span class="NormalTextRun SCXW169441868 BCX0">.</span></span><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0"> ✅</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"> </span>

</div></div>##### <span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0" data-ccp-parastyle="heading 1">Event Categories – Detailed Reference</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335559738":322,"335559739":322}"> </span>**</span>

<table border="1" id="bkmrk-event-type%C2%A0-descript" style="border-collapse: collapse; width: 100%; height: 270.352px;"><colgroup><col style="width: 25.0373%;"></col><col style="width: 25.0373%;"></col><col style="width: 25.0373%;"></col><col style="width: 25.0373%;"></col></colgroup><thead><tr style="height: 30.0391px;"><td style="height: 30.0391px;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Event Type</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335551550":2,"335551620":2,"335559738":0,"335559739":0}"> </span>**</td><td style="height: 30.0391px;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Description</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335551550":2,"335551620":2,"335559738":0,"335559739":0}"> </span>**</td><td style="height: 30.0391px;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Use Case</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335551550":2,"335551620":2,"335559738":0,"335559739":0}"> </span>**</td><td style="height: 30.0391px;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Example</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335551550":2,"335551620":2,"335559738":0,"335559739":0}"> </span>**</td></tr></thead><tbody><tr style="height: 30.0391px;"><td class="FirstCol SCXW169441868 BCX0" data-celllook="0" role="rowheader">**<span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">API Events</span></span>**<span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>

</td><td class="SCXW169441868 BCX0" data-celllook="0"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Capture system-level API calls made by processes. These events show how applications interact with the OS, libraries, and security-sensitive functions.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td><td style="height: 30.0391px;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Detect process injection, privilege escalation, exploitation attempts, or use of unusual APIs by non-standard processes.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td><td style="height: 30.0391px;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">A Microsoft Office process (WINWORD.EXE) invokes </span><span class="NormalTextRun SpellingErrorV2Themed SCXW169441868 BCX0">VirtualAllocEx</span><span class="NormalTextRun SCXW169441868 BCX0"> and </span><span class="NormalTextRun SpellingErrorV2Themed SCXW169441868 BCX0">WriteProcessMemory</span><span class="NormalTextRun SCXW169441868 BCX0"> to inject code into another process.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td></tr><tr style="height: 30.0391px;"><td style="height: 30.0391px;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">DLL &amp; Driver Load Events</span></span>**<span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td><td style="height: 30.0391px;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Record the loading of DLLs into user processes and drivers into the OS kernel. Includes path, signature status, and process context.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td><td style="height: 30.0391px;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Detect unsigned or suspicious DLLs/drivers, DLL search order hijacking, and kernel-level rootkits.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td><td style="height: 30.0391px;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">An unsigned driver is loaded during system boot, or a legitimate app loads a DLL from a non-standard directory.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td></tr><tr style="height: 30.0391px;"><td style="height: 30.0391px;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">DNS Events</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>**</td><td style="height: 30.0391px;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Log all DNS lookups and responses, showing which domains are queried and by which process.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td><td style="height: 30.0391px;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Detect C2 callbacks, malware beaconing, DNS tunneling, and suspicious domain resolution.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td><td style="height: 30.0391px;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">A process repeatedly queries random subdomains of example\[.\]com, suggesting DGA (Domain Generation Algorithm) use.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td></tr><tr style="height: 30.0391px;"><td style="height: 30.0391px;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">File Events</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>**</td><td style="height: 30.0391px;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Monitor file activity: creation, modification, deletion, renaming, and read access. Includes metadata like file path, hash, and process context.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td><td style="height: 30.0391px;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Detect ransomware encryption, malware staging (dropping executables), </span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW169441868 BCX0">tampering with</span><span class="NormalTextRun SCXW169441868 BCX0"> sensitive files, or unauthorized access.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td><td style="height: 30.0391px;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">A process writes </span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW169441868 BCX0">multiple .encrypted</span><span class="NormalTextRun SCXW169441868 BCX0"> files in rapid succession in a user’s documents folder.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td></tr><tr style="height: 30.0391px;"><td style="height: 30.0391px;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Network Events</span></span>**<span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td><td style="height: 30.0391px;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Capture TCP/UDP connections, ports, IPs, protocols, and process </span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW169441868 BCX0">responsible</span><span class="NormalTextRun SCXW169441868 BCX0">.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td><td style="height: 30.0391px;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Detect outbound connections to malicious infrastructure, lateral movement inside a network, or data exfiltration attempts.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td><td style="height: 30.0391px;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">PowerShell </span><span class="NormalTextRun SCXW169441868 BCX0">initiates</span><span class="NormalTextRun SCXW169441868 BCX0"> a connection to a known malicious IP over port 443 with </span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW169441868 BCX0">unusual</span><span class="NormalTextRun SCXW169441868 BCX0"> payload size.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td></tr><tr style="height: 30.0391px;"><td style="height: 30.0391px;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Process Events</span></span>**</td><td style="height: 30.0391px;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Record process lifecycle: creation, termination, parent-child relationships, command-line arguments, and integrity info.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td><td style="height: 30.0391px;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Detect abnormal parent-child chains, privilege escalation, process hollowing/injection, and script-based attacks.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td><td style="height: 30.0391px;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">explorer.exe launches powershell.exe with a Base64-encoded command to download a payload.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td></tr><tr style="height: 30.0391px;"><td style="height: 30.0391px;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Registry Events</span></span>**<span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td><td style="height: 30.0391px;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Log modifications to Windows Registry, including key creation, deletion, and value changes.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td><td style="height: 30.0391px;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Detect persistence mechanisms, system tampering, and security feature bypasses.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td><td style="height: 30.0391px;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Malware creates HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\malware.exe for auto-start persistence.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td></tr><tr style="height: 30.0391px;"><td style="height: 30.0391px;">**<span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Security Events</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span>**</td><td style="height: 30.0391px;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Record security-related activity: authentication attempts, user/group changes, privilege assignments, and policy alterations.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td><td style="height: 30.0391px;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Detect brute force attacks, privilege abuse, unauthorized access, and security control disabling.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td><td style="height: 30.0391px;"><span class="TextRun SCXW169441868 BCX0" data-contrast="auto" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0">Multiple failed login attempts followed by a successful login with a privileged account.</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></td></tr></tbody></table>

<div class="OutlineElement Ltr SCXW169441868 BCX0" id="bkmrk-for-more-information">*For more information about EDR, please refer to this link: [AQUILA - Endpoint Dete... | AQUILA Documentations](https://usdc-docs.cytechint.io/books/aquila-edr-installation/page/aquila-endpoint-detection-and-response-edr-manual-installation)*</div><div class="OutlineElement Ltr SCXW169441868 BCX0" id="bkmrk-%C2%A0-%C2%A0-%C2%A0-%C2%A0-%C2%A0-%C2%A0-%C2%A0-%C2%A0-%C2%A0-%C2%A0-"> *[AQUILA - Endpoint Dete... | AQUILA Documentations](https://usdc-docs.cytechint.io/books/aquila-edr-installation/page/aquila-endpoint-detection-and-response-edr-automatic-installation)*</div><div class="OutlineElement Ltr SCXW169441868 BCX0" id="bkmrk--21"><div class="TableContainer Ltr SCXW169441868 BCX0"><div aria-hidden="true" class="WACAltTextDescribedBy SCXW169441868 BCX0" id="bkmrk--22"></div></div></div>---

#### **2. Data Loss Prevention (DLP)**

- Monitors how sensitive data is being used, shared, or transferred.
- Helps prevent accidental or intentional leaks of confidential information.
- Provide real-time visibility into data security by tracking potential risks and exposures.
- Monitor unresolved alerts to identify and address security issues promptly.
- Identify sensitive data that may be exposed and classify files accordingly (e.g., confidential, private, or public).
- Highlight trends in alert activity to spot and respond to critical incidents.
- Serve as a central tool for ensuring sensitive information remains secure and compliant with organizational policies.

##### **<span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0" data-ccp-parastyle="heading 2">🛡️</span></span>**<span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0" data-ccp-parastyle="heading 2">Protections Matrix</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335559738":299,"335559739":299}"> </span>**</span>

<table id="bkmrk-dlp-purpose-descript"><thead><tr><th>**DLP Purpose**</th><th>**Description**</th><th>**DLP Detect**</th></tr></thead><tbody><tr><td>**Identify Sensitive Data**</td><td>Finds confidential or regulated information (PII, PHI, PCI, IP).</td><td>Recognizes sensitive data using patterns, keywords, regex, file classification, or ML.</td></tr><tr><td>**Monitor Data Usage**</td><td>Observes how data is accessed, edited, or transferred.</td><td>Flags unusual or risky user activities (e.g., mass copying or emailing).</td></tr><tr><td>**Prevent Unauthorized Data Transfer**</td><td>Ensures data doesn’t leave the organization improperly.</td><td>Detects attempts to send data via email, USB, cloud apps, or printing.</td></tr><tr><td>**Protect Against Data Breaches**</td><td>Reduces risk from insiders, malware, or accidents.</td><td>Alerts on anomalous access or large data movement.</td></tr><tr><td>**Enforce Security Policies**</td><td>Ensures compliance with regulations (GDPR, HIPAA, PCI).</td><td>Detects policy violations automatically.</td></tr><tr><td>**Control Data Flow**</td><td>Manages how data moves inside/outside the network.</td><td>Detects data movement patterns and unauthorized destinations.</td></tr><tr><td>**Provide Visibility &amp; Reporting**</td><td>Offers logs and insights for audits/investigations.</td><td>Detects events and logs all data-related activities.</td></tr></tbody></table>

<div class="OutlineElement Ltr SCXW169441868 BCX0" id="bkmrk-for-more-information-1">*For more information about DLP, please refer to this link: [Data Loss Prevention (... | AQUILA Documentations](https://usdc-docs.cytechint.io/books/data-governance-privacy-Frn/page/cytech-aquila-data-security-posture-management)*</div><div class="OutlineElement Ltr SCXW169441868 BCX0" id="bkmrk-%C2%A0-%C2%A0-%C2%A0-%C2%A0-%C2%A0-%C2%A0-%C2%A0-%C2%A0-%C2%A0-%C2%A0--1"> </div>---

#### **3. Vulnerability Detection and Response (VDR)**

- Scans the device for weaknesses, outdated software, or security gaps that hackers could exploit.
- Alerts administrators so they can fix issues before they become serious threats.

##### **<span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0" data-ccp-parastyle="heading 2">🛡️</span></span>**<span style="color: rgb(53, 152, 219);">**<span class="TextRun SCXW169441868 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW169441868 BCX0" data-ccp-parastyle="heading 2">Protections Matrix</span></span><span class="EOP SCXW169441868 BCX0" data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335559738":299,"335559739":299}"> </span>**</span>

<table id="bkmrk-category-%2F-purpose-d" style="width: 100%;"><thead><tr><th style="width: 22.772%;">**Category / Purpose**</th><th style="width: 37.3174%;">**Description**</th><th style="width: 39.9404%;">**Detect**</th></tr></thead><tbody><tr><td style="width: 22.772%;">**Identify System Weaknesses**</td><td style="width: 37.3174%;">Finds flaws in software, hardware, or configurations that attackers could exploit.</td><td style="width: 39.9404%;">Scans for outdated software, missing patches, weak configurations, known CVEs.</td></tr><tr><td style="width: 22.772%;">**Assess Security Posture**</td><td style="width: 37.3174%;">Evaluates how secure an environment is against threats.</td><td style="width: 39.9404%;">Runs vulnerability assessments, baseline checks, and compliance scans.</td></tr><tr><td style="width: 22.772%;">**Detect Misconfigurations**</td><td style="width: 37.3174%;">Finds incorrect or insecure setup of systems or applications.</td><td style="width: 39.9404%;">Identifies open ports, weak permissions, default passwords, insecure protocols.</td></tr><tr><td style="width: 22.772%;">**Find Network Vulnerabilities**</td><td style="width: 37.3174%;">Looks for weaknesses within network infrastructure.</td><td style="width: 39.9404%;">Scans firewalls, routers, switches, exposed services, and network paths.</td></tr><tr><td style="width: 22.772%;">**Identify Application Vulnerabilities**</td><td style="width: 37.3174%;">Locates flaws in web and software applications.</td><td style="width: 39.9404%;">Detects OWASP Top 10 issues (XSS, SQL Injection, CSRF, etc.).</td></tr><tr><td style="width: 22.772%;">**Detect Unauthorized Access Paths**</td><td style="width: 37.3174%;">Finds hidden or unintended ways attackers could enter the system.</td><td style="width: 39.9404%;">Identifies backdoors, exposed APIs, weak authentication paths.</td></tr><tr><td style="width: 22.772%;">**Continuous Monitoring**</td><td style="width: 37.3174%;">Ongoing observation for new or emerging vulnerabilities.</td><td style="width: 39.9404%;">Uses automated scanning, SIEM alerts, threat intelligence feeds.</td></tr><tr><td style="width: 22.772%;">**Risk Prioritization**</td><td style="width: 37.3174%;">Determines which vulnerabilities are most dangerous.</td><td style="width: 39.9404%;">Rates vulnerabilities using CVSS scores and exploit likelihood.</td></tr></tbody></table>

### **Why is it important?**

- It gives your IT or security team **continuous visibility** into the health and security status of all devices.
- It allows them to **control risks proactively**, rather than waiting for something bad to happen.
- Overall, it strengthens the **security posture** of your organization by ensuring every device is properly monitored and protected.

### **Requirements**

- Your device must have at least 1 CPU core running at 2 GHz or higher (2 cores recommended).
- Requires a minimum of 2 GB DDR4 RAM (3 GB recommended).
- Needs at least of 1.5 GB of available SSD storage space (2 GB recommended for optimal performance).
- Compatible with Windows OS.
- Requires a stable internet connection (minimum 5 Mbps) to connect with AQUILA services.