Here's How the Sekoia Endpoint Agent Works
ID: fb4134cf-4545-55e2-8832-756691f21338
STIX ID: report--fb4134cf-4545-55e2-8832-756691f21338
Feed Name: Sekoia.com
This blog post presents Sekoia's Endpoint Agent, detailing how it collects and normalizes host event logs (in Elastic Common Schema), forwards them to the Sekoia SOC platform over HTTPS, and supports Windows and Linux environments. It covers installation steps (including optional Sysmon), configuration (YAML for app logs, region selection, proxies, and automatic updates), features like offline buffering, low resource usage, log integrity preservation, and ongoing enhancements driven by the Threat Detection & Research team.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
