- Turning Visibility Into Action: Introducing Aurora Exposure Management. LEARN MORE
- | | | | | |\
| --- | --- | --- | --- | --- |\
| | | | | | | |\
| --- | --- | --- | --- | --- |\
| Search | Experienced a Breach? | Contact Us | Blog | - EN - EN-GB(United Kingdom)
- FR(Français)
- DE(Deutsch)
- Dansk(Danish)
- Nederlands(Dutch)
- Suomi(Finnish)
- 日本語(Japanese)
- Norsk(Norwegian)
- Svenska(Swedish)
- EN-AU(Australia)
- Español(Spanish) | |
-
Platform
-
- Delivering security operations outcomes.
Aurora Superintelligence Platform
- Delivering AI outcomes you can trust.
-
- Leverage the power of scale and AI expertise.
-
- Ecosystem integrations and technology partnerships.
Agentic SOC
-
- Partner with the world’s largest commercial agentic SOC.
-
- Tailored security expertise and guided risk mitigation.
-
- Security experts proactively protecting you 24×7.
-
- Learn how our IR team stops attacks and swiftly restores your organization to pre-incident operations.
Journey
-
- Build a resilient business by embracing Security Operations.
-
- Map your security posture against industry standard frameworks.
- | |
| --- |
| - EN - EN-GB(United Kingdom)
- FR(Français)
- DE(Deutsch)
- Dansk(Danish)
- Nederlands(Dutch)
- Suomi(Finnish)
- 日本語(Japanese)
- Norsk(Norwegian)
- Svenska(Swedish)
- EN-AU(Australia)
- Español(Spanish) |
Ready to get started? Request a Demo
-
Reduce Attack Frequency
-
- Continuously discover, prioritize, and reduce exposure across your attack surface.
-
- Receive end-to-end IR coverage for one incident, no matter the incident type.
Security Awareness and Training
- Engage and prepare employees to recognize and neutralize social engineering attacks.
Reduce Attack Severity
-
- AI-driven prevention, detection, and response to stop endpoint threats before they disrupt your business.
Managed Detection and Response
- Quickly detect, respond, and recover from advanced threats.
-
- Recover quickly from cyber attacks and breaches, from threat containment to business restoration.
-
Transfer Risk
-
- Stay covered at no cost with up to $3M in financial assistance for cybersecurity incidents.
-
- Increase the likelihood of insurability, and potentially lower your rates.
-
- Access a complimentary suite of tools to reduce risk and improve insurability.
Get Started
- View All Arctic Wolf Solutions Explore Arctic Wolf Bundles Calculate Your Security ROI
- | |
| --- |
| - EN - EN-GB(United Kingdom)
- FR(Français)
- DE(Deutsch)
- Dansk(Danish)
- Nederlands(Dutch)
- Suomi(Finnish)
- 日本語(Japanese)
- Norsk(Norwegian)
- Svenska(Swedish)
- EN-AU(Australia)
- Español(Spanish) |
Ready to get started? Request a Demo
-
Why Arctic Wolf
-
- Awards & Recognition
- Customer Perspectives
- Security Operations Warranty
- Arctic Wolf Labs
Expertise by Topic
Incident Response Timelines
Ransomware Attack & Containment
- Business Email Compromise
Expertise by Industry
Ready to get started? Request a Demo
-
Resource Center
-
- Blog
- Case Studies
- Events
- Analyst Reports
- Webinars
- Podcasts
- Glossary
- Technical Videos
- View All
Trending Resources
2025 Arctic Wolf Threat Report
##### The Arctic Wolf Threat Report draws upon the first-hand experience of our security experts, augmented by research from our threat intelligence team.
The Arctic Wolf State of Cybersecurity: 2025 Trends Report
##### The Arctic Wolf State of Cybersecurity: 2025 Trends Report serves as an opportunity for decision makers to share their experiences over the past 12 months and their perspectives on some of the most important issues shaping the IT and security landscape.
Aurora: A New Dawn For Cybersecurity
##### Join Arctic Wolf on an interactive journey to discover a better path past the hazards of the modern threat landscape.-
Security Bulletins
May 7, 2026
CVE-2026-0300 — Critical Buffer Overflow in PAN-OS User-ID Authentication Portal
May 1, 2026
Beyond the Bug: Why Cybersecurity Still Matters Even If AI Improves Secure Development
April 14, 2026
Microsoft Patch Tuesday: April 2026
-
- | |
| --- |
| - EN - EN-GB(United Kingdom)
- FR(Français)
- DE(Deutsch)
- Dansk(Danish)
- Nederlands(Dutch)
- Suomi(Finnish)
- 日本語(Japanese)
- Norsk(Norwegian)
- Svenska(Swedish)
- EN-AU(Australia)
- Español(Spanish) |
- | |
| --- |
| - EN - EN-GB(United Kingdom)
Ready to get started? Request a Demo
-
Partners
- Solution Providers
- Helping Solution Providers scale their business with a comprehensive portfolio of products and services.
-
- Arctic Wolf provides the Insurance Partner Program for Brokers and Carriers to support them within the Cyber JumpStart portal.
-
- Ecosystem integrations and technology partnerships.
- Managed Service Providers
- Grow your business and solve your customers’ cybersecurity challenges with industry-leading turnkey security operations.
-
- Arctic Wolf OEM Solutions enable ISVs, MSSPs, U.S. Federal Agencies, and security companies.
- Become a Partner
- | |
| --- |
| - EN - EN-GB(United Kingdom)
- FR(Français)
- DE(Deutsch)
- Dansk(Danish)
- Nederlands(Dutch)
- Suomi(Finnish)
- 日本語(Japanese)
- Norsk(Norwegian)
- Svenska(Swedish)
- EN-AU(Australia)
- Español(Spanish) |
Ready to get started? Request a Demo
-
Company
-
- Contact Us
- Leadership
- Customers
- FAQ
Careers
-
- Open Jobs
- Our Values
- Pack Impact
Press
-
- Press Releases
Brand Partnerships
Ready to get started? Request a Demo
ARCTIC WOLF
Aurora® Endpoint Security
Battle-Proven, AI-Powered Endpoint Security
Stop ransomware and zero‑day threats with a 99% true‑positive rate, world class security ROI, and access to the Aurora® Agentic SOC.
Report Available
Aurora Endpoint Security Achieves 100% Threat Protection
In Independent Evaluation
Download independent testing from the Tolly Group to evaluate both the protection efficacy and system resource utilization of Arctic Wolf Endpoint Security.
Arctic Wolf
Aurora Endpoint Security
Endpoint Security
Managed Endpoint Security
Aurora Protect
Features
Endpoint Protection Platform
Next-Generation Antivirus
Aurora AI for Endpoint
Windows, macOS, Broad Linux support
Advanced Threat Protection (PE, Memory, Script Control)
Device Control
Application Control
Aurora Endpoint Defense
- Aurora Protect
Features
Endpoint Detection and Response
Behavioral Detection Engine
Threat Hunting Tooling
MITRE ATT&CK Mapping
30-Day Data Retention
Playbook Automation
Managed Endpoint Security
Aurora Managed Endpoint Defense
Aurora Protect
Aurora Endpoint Defense
Features
Managed Endpoint Security
24x7 Monitoring
Alert Triage by Aurora Agentic SOC
Endpoint Security Investigations
Response Actions
Guided Remediation
Tactical Threat Insights
Ongoing Configuration Assistance
Endpoint Security
Managed Endpoint Security
Aurora Protect (formerly CylanceProtect)
Features
Endpoint Protection Platform
Next-Generation Antivirus
Alpha AI (formerly Cylance AI) for Endpoint
Windows, macOS, Broad Linux Support
Advanced Threat Protection (PE, Memory, Script Control)
Device Control
Application Control
Aurora Endpoint Defense (formerly CylanceProtect + Optics)
- Aurora Protect
Features
Endpoint Detection and Response
Behavioral Detection Engine
Threat Hunting Tooling
MITRE ATT&CK Mapping
30-Day Data Retention
Playbook Automation
Managed Endpoint Security
Aurora Managed Endpoint Defense On-Demand (formerly CylanceMDR On Demand)
Aurora Protect
Aurora Endpoint Defense
Features
On-Demand Security Escalations
Security Investigation Requests
Guided Remediation
Tactical Threat Insights
Incident Analysis Report
Ongoing Configuration Assistance
Onboarding
Aurora Managed Endpoint Defense (formerly CylanceMDR Standard)
Aurora Protect
Aurora Endpoint Defense
Features
24x7 Monitoring
Alert Triage by Arctic Wolf SOC
Endpoint Security Investigations
Response Actions
Guided Remediation
Tactical Threat Insights
Incident Analyst Reports
Campaign-Focused Threat Hunting
Onboarding
Mobile‑First Security. Designed for Security and Privacy.
With Aurora Endpoint Security, organizations can secure smartphones and tablets alongside desktop PCs and laptops, across a wide range of chipsets and processors.
Aurora Mobile Threat Defense
Mobile Threat Defense
Rogue & Unsafe Network Defense
Identify Non-Compliant Apps
Prevent Mishing Attacks
Malware Detection & Classification
Privacy Friendly Forensic Analysis
Mobile Threat Defense
Rogue & Unsafe Network Defense
Identify Non-Compliant Apps
Prevent Mishing Attacks
Malware Detection & Classification
Privacy Friendly Forensic Analysis
Secure Your Endpoints Against Modern Threats
Battle-Proven Aurora AI
Zero-day threat prevention with a 99% true positive rate
On average, quarantined 250 malicious files pre-execution per customer last year
30% faster incident investigation and 90% reduction in alert fatigue
Maximum Security Value
Arctic Wolf customers, on average, see more than a 13x ROI on their security investment compared to a DIY approach.
Savings of over 8,000 hours from elimination of AV updates.1
Efficient, Effective Security
27% lower resource consumption than the industry composite.2
50% less labor burden from AI-driven efficacy and automation.3
Sources
Your Endpoints. Our Expertise.
Unlock Security Delivered by the Aurora Agentic SOC with ongoing tuning and configuration support.
“The onboarding for this product was one of the best I have experienced. We are confident our endpoints are protected.”
5.0★★★★★
Function
IT Security & Risk Management
Industry
Retail
Firm Size
<50M USD
Deployment Architecture
Cloud (SaaS or PaaS or IaaS)
See the Power of Battle Proven, AI-Powered Endpoint Security
Explore our hands-on experience that allows you to see our market-leading AI-driven endpoint solution in action.
Start Your Free Experience Today!
See how Aurora Endpoint Defense protects, detects, and responds to real malware as well as adversary tactics and techniques, through six documented use cases.
* Email Address
* First Name
* Last Name
* Job Title
* Phone Number
* Company Name
* Select Country
United StatesCanadaUnited KingdomAfghanistanAlandIslandsAlbaniaAlgeriaAmericanSamoaAndorraAngolaAnguillaAntarcticaAntiguaandBarbudaArmeniaArubaAustraliaAustriaAzerbaijanBahrainBangladeshBelarusBelgiumBeninBhutanBolivia,PlurinationalStateofBonaire,SintEustatiusandSabaBosniaandHerzegovinaBouvetIslandBritishIndianOceanTerritoryBruneiDarussalamBurkinaFasoBurundiCambodiaCameroonCapeVerdeChadChristmasIslandCocos(Keeling)IslandsComorosCongo,theDemocraticRepublicoftheCongoCookIslandsCoted'IvoireCubaCuraçaoCyprusDenmarkDjiboutiDominicaEquatorialGuineaEritreaEthiopiaFalklandIslands(Malvinas)FaroeIslandsFijiFinlandFranceFrenchGuianaFrenchPolynesiaFrenchSouthernTerritoriesGabonGambiaGermanyGhanaGreenlandGrenadaGuadeloupeGuernseyGuinea-BissauGuineaHaitiHeardIslandandMcDonaldIslandsHolySee(VaticanCityState)IcelandIndiaIndonesiaIran,IslamicRepublicofIraqIrelandIsleofManItalyIvoryCoastJapanJerseyJordanKazakhstanKenyaKiribatiKorea,DemocraticPeople'sRepublicofKosovoKyrgyzstanLaoPeople'sDemocraticRepublicLatviaLebanonLesothoLiberiaLibyaLiechtensteinLithuaniaLuxembourgMacaoMacedonia,theformerYugoslavRepublicofMadagascarMalawiMalaysiaMaldivesMaliMaltaMarshallIslandsMartiniqueMauritaniaMauritiusMicronesiaMoldova,RepublicofMontenegroMontserratMoroccoMozambiqueMyanmarNamibiaNauruNepalNetherlandsNewCaledoniaNewZealandNigerNiueNorfolkIslandNorthernMarianaIslandsNorwayPakistanPalauPalestinePapuaNewGuineaPhilippinesPitcairnQatarRussianFederationRwandaSaintBarthélemySaintHelena,AscensionandTristandaCunhaSaintKittsandNevisSaintLuciaSaintMartin(Frenchpart)SaintPierreandMiquelonSaintVincentandtheGrenadinesSamoaSanMarinoSaoTomeandPrincipeSenegalSerbiaSeychellesSierraLeoneSingaporeSintMaarten(Dutchpart)SloveniaSolomonIslandsSomaliaSouthAfricaSouthGeorgiaandtheSouthSandwichIslandsSouthSudanSudanSvalbardandJanMayenSwazilandSwedenSwitzerlandSyrianArabRepublicTajikistanTanzania,UnitedRepublicofThailandTimor-LesteTogoTokelauTongaTrinidadandTobagoTunisiaTurkeyTurkmenistanTurksandCaicosIslandsTuvaluUgandaUnitedArabEmiratesUSVirginIslandsUzbekistanVanuatuVietNamVirginIslands,BritishWallisandFutunaWesternSaharaYemenZambiaZimbabwe
*
By checking this box, you agree to the Aurora Endpoint Experience Agreement which governs your access.
*
Yes, I would like to receive marketing emails from Arctic Wolf about solutions that may be of interest to me.
By submitting this form, you agree to the Arctic Wolf Website Terms of Use and Arctic Wolf Privacy Policy.
Submit
Start Your Free Aurora Endpoint Experience
See an interactive demo of the Aurora Endpoint Defense Console
Step through this interactive demo to get a sneak preview of the user interface. Following the prompts will guide you through different aspects of the solution from alert management to policy configuration as well as automated response and Aurora AI capabilities.
An easy to navigate interface for all of your endpoint security needs:
Aurora AI powered endpoint security that delivers prevention and advanced threat protection
Online and offline protection delivered through the lightweight agent with support for all major operating systems
Behavioral Detection Engine that lowers operational overhead and enables the ability to implement automatic response actions
Detection and investigation capabilities including forensic data analysis, sandbox reports, and threat hunting
Interactive Demo:
Aurora Endpoint Defense Console
Dashboard | Aurora Endpoint Defense
Nested Runtime Canvas
Dashboard | Aurora Endpoint Defense
Dashboard
Running Threats \ \ 0\ \ Total
Running Threats \ \ 0\ \ Last 24 hours
Auto-Run Threats \ \ 1\ \ Total
Auto-Run Threats \ \ 0\ \ Last 24 hours
Quarantined Threats \ \ 867\ \ Total
Quarantined Threats \ \ 6\ \ Last 24 hours
Unique to Endpoint Defense \ \ 1\ \ Total
Unique to Endpoint Defense \ \ 0\ \ Last 24 hours
Total Files Analyzed
380,865
Threat Protection
92%
0100
Device Protection
99%
0100
Threat Events
7/157/167/177/187/197/207/217/227/237/247/257/267/277/287/297/307/318/18/28/38/48/58/68/78/88/98/108/118/128/138/148/150100200300400500600700800900UnsafeAbnormalQuarantinedWaivedCleared
Threats By Priority
68 Total
High
1.47% of total files | 1 affected devices
Medium
1.47% of total files | 1affected devices
Low
97.06% of total files | 1affected devices
Threat Classifications
Malware
Trojan
Ransom
Worm
Ransom
Infostealer
Virus
Worm
Backdoor
Backdoor
Trojan
Exploit
Infostealer
Infostealer
Virus
Trojan
Trojan
Backdoor
Backdoor
Trojan
Trojan
Trojan
Trojan
Backdoor
Backdoor
Backdoor
Infostealer
Trojan
Trojan
Trojan
Trojan
Trojan
Virus
Virus
Hacking Tool
Backdoor
Backdoor
Infostealer
Infostealer
Infostealer
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Trojan
Worm
Worm
Virus
Virus
Virus
Virus
Virus
Virus
Bot
Ransom
Generic
PUP
Generic
Hacking Tool
Top Ten Lists
Threats found on the most devices
- T1218-2.dll
- T1574.012x64.dll
- o.dll
- uacme.zip
- phant0m.exe
- uacme.zip
- EtwpCreateEtwThread.exe
- AllTheThingsx64.dll
- T1055.011_x86.exe
- uacme.zip
Devices with the most threats
Zones with the most threats
Welcome to Aurora Endpoint Defense
Our section-by-section tutorials will help you get started in securing your network!
Viewing Threats
Threats are viewable based on the Zones you're assigned to. An Admin can see threats across all Zones and Devices, including the "Unzoned" Zone. Users and Zone Managers are limited to the Zones they are assigned to.
Dashboard
The Dashboard provides a summary of the protection status of your organization.
Protection
The Protection page shows the number of threats found per day, for the last 30 days. The threats table lists all threats, plus file reputation, threat priority, signed status, and AV Industry status. By clicking on the down arrow, you are able to sort by ascending/descending, filter, and add/remove columns.
When selecting a row, you will see an overview of the threat you selected. To view the full threat details, click on the threat name.
The Threat Details page will help you decide what action to take on the threat. Stats will show how the threat has been marked within your own account, as well as across all Endpoint Defense users. The "Affected Devices and Zones" table shows the devices and Zones where the threat is Unsafe, Quarantined, Waived, or Abnormal. The "Detailed Threat Data" tab will show you more information on the threat.
Zones
The Zones page will show the at-risk Zones. Most at-risk is determined by the number of threats found in a Zone. The chart will show the number of unsafe and safe devices in each of the 5 most at-risk Zones. The "Zones List" is the list of all Zones that are accessible to you based on your User role.
The Zone Details page shows total threats and average threats per device in the Zone. You will also see a list of all Devices in that Zone.
Devices
The Devices page lists all of the devices starting with the device with the most threats. If you are both a User and Zone Manager for several different Zones, you will also see that role listed.
The Device Details page will show you the actual threats that are found on that particular device. The four different states a threat can be in are shown as well: Unsafe Threats, Abnormal, Quarantined, Waived.
Threat Actions
You can take actions against threats on the Device Details, Threats, and Threat Details pages. All three pages allow you to choose multiple threats or devices and take the same action.
The following states are available for threats:
- Unsafe Threats- Threats that have been found and are currently running (or) runnable on the device(s) listed.
- Abnormal- When the file reputation of an analyzed file is < 60, Endpoint Defense classifies the file as Abnormal. This indicates that the file may have abnormal features with a lower risk of threat.
- Quarantined- You can choose to quarantine an Unsafe or Abnormal file on the devices it was found. If you are an Admin, you can also choose to Global Quarantine the threat, in which case, the file will be quarantined on any device whenever it is found.
- Waived- You can provide a waiver to a file on the devices it is found. An Admin can also choose to add a file to the Safe List, which would allow it to run on any system in your network. Waivers/Safelisting is typically done for Abnormal files.
Global Quarantine List/Safe List (Admin only)
You can place any file into your Global Quarantine List or Safe List if you want to allow it to be quarantined or allowed on all systems. The global lists can be found in Settings > Global List.
Zones
What is a Zone?
A Zone is a way to organize and manage your devices. You can assign Users to Zones so they can view only what's been assigned to that Zone.
By default, there is an "Unzoned" Zone created. However, only an Admin is able to view devices in this default Zone. You will need to create at least one Zone to allow anyone with a "User" or "Zone Manager" role to view it.
Add a Zone(Admin only)
In the navigation bar, click on "Zones". Once you are on the Zones page, scroll down to the Zones List. Click on the "Add New Zone" button. This will trigger a popup that will allow you to name your new Zone.
Tips for Zones
You can create Zones based on region (West Coast, East Coast, North America, South America), department (Accounting, Engineering, Marketing), or any type of separation that works for you. This will help you decide who has permissions to see specific devices.
Remove a Zone(Admin only)
To remove a Zone, go to the main Zones page. Under the "Zones List", select the Zones you want to remove and click "Remove".
This action removes a Zone completely from your Endpoint Defense console.
Devices
Adding Devices
If you are an Admin, you can generate an installation token to add a device. Go to Settings > Application. There, you will see a link to generate a token. Once you've generated a token, you will need to copy and enter it during the installation of the Endpoint Defense app.
If you decide to delete or regenerate a token, the previous token will no longer be valid.
If you are a Zone Manager or User, you cannot generate an installation token. You will need to ask your Admin to generate one if one does not exist yet.
Adding Devices to a Zone(Admin and Zone Manager)
To add an existing device to a Zone, go to Zones and in the "Zones List", select the Zone you want to add the device to. In the Zone Details page, click on "Add Device to Zone" at the bottom of the "Zones Device List". In the popup, select all the devices you would like to add to the Zone.
Removing a Device (Admin only)
You can remove a device by going to the details page of the device. At the bottom of the "Device Info" box, you will see a "Remove this device" link.
This action will remove the device completely from your Endpoint Defense console.
Removing a Device from a Zone (Admin and Zone Manager)
To remove a device from a Zone, go to the Zone Details page and scroll to the "Zones Device List". Check the devices you would like remove and click "Remove".
If you want to remove a device from multiple Zones, you will need to go to each Zones details page and remove it from there.
Edit a Device Name and Changing Policy (Admin and Zone Manager)
You can do both actions by going to the Device Details page. In the "Device Info" box, you can see the current device name in an editable text field.
In the same section, there is a dropdown menu for Policy.
Once you've completed your changes, be sure to click "Save".
Users
The following four roles are available:
- Administrators have global permissions. Admins can add or remove users, assign users to Zones (either as a User or a Zone Manager), add or remove devices, create policies, and create zones. Admins can also delete users, devices, policies, and zones permanently from the site.
- Zone Managers have permissions within any Zone they manage. They can remove devices, edit policy, and edit device names. Zone Managers can also assign Users to view their zones as well as give other Zone Managers permission to access their zones.
- Users are assigned to Zones from an Admin or a Zone Manager. Within an assigned Zone, Users can quarantine or waive threats. If a User is not assigned to any Zone, then there will be no devices to view nor actions to take against threats.
- Read-only users have permissions to view the Endpoint Defense console but cannot take any actions nor change any settings.
Adding Users (Admin only)
As an Admin, you can add users by going to Settings > User Management. In the "Add Users" box, enter the email address of the user you'd like to add (at the moment, only one email can be entered at a time). You will be required to select a Role and a Zone for the Zone Manager and User roles. This requirement is put into place since any user with a Zone Manager or User role will need to be in a Zone in order to see any devices.
Adding Users to a Zone (Admin and Zone Manager)
To add users to specific Zones, go to Settings > User Management. Click on the user you'd like to add to a Zone. On the User Details page, you will see a list of Zones and the user's role in each Zone. Select the user's role for each Zone. Your changes will not go into effect until you click "Save."
Removing Users (Admin only) This action will completely remove users from your Endpoint Defense console. To remove users, go to Settings > User Management. Check the users you'd like to remove and click "Remove."
Removing Users from a Zone (Admin and Zone Manager)
You can remove a user from a Zone by going to Settings > User Management. Click on the user you'd like to remove from a zone. On the User Details page, change the user's role to "None" for each Zone you'd like the user removed from. Your changes will not go into effect until you click "Save."
User Permissions
Use this chart as a guideline to help you decide what Roles you assign to users.
| Admin | Zone Manager | User - Zone | Read-only |
|---|
| Agent Update | ||||
| View/Edit | X | X (View Only) | ||
| Audit Logging | ||||
| View | X | X | ||
| Devices | ||||
| Add Devices - Global | X | |||
| Add Devices to a Zone | X | |||
| Remove Devices - Global | X | |||
| Remove Devices from a Zone | X | X | ||
| Edit Device Name | X | X | ||
| Zones | ||||
| Create Zone | X | |||
| Delete Zone | X | |||
| Edit Zone Name - Any | X | |||
| Edit Assigned Zone Name | X | X | ||
| Policy | ||||
| Create Policy - Global | X | |||
| Create Policy for a Zone | X | |||
| Add Policy - Global | X | |||
| Add Policy to a Zone | X | X | ||
| Remove Policy - Global | X | |||
| Remove Policy from a Zone | X | X | ||
| Threats | ||||
| Quarantine Files - Global | X | |||
| Quarantine Files in a Zone | X | X | X | |
| Waive Files - Global | X | |||
| Waive Files in a Zone | X | X | X | |
| Global Quarantine/Safe | X | |||
| Settings | ||||
| Generate or delete install token | X | |||
| Generate or delete invite URL | X | |||
| Copy install token | X | X | X | |
| Copy invite URL | X | |||
| User Management | ||||
| Assign users to any Zone | X | |||
| Assign users to managed Zone | X | X | ||
| Assign Zone Managers - Global | X | |||
| Assign Zones Managers to managed Zones | X | X | ||
| Delete users from Aurora Endpoint Defense | X | |||
| Remove Users from Zone - Global | X | |||
| Remove Users from managed Zone | X | X |
Policies
Create Policy (Admin only)
Create a Policy by going to Settings > Device Policy. At the bottom of the "Active Policies" list, click on "Add New Policy". In the popup, enter the name of your Policy and choose the actions you want, and click "Save".
Edit Policy (Admin only)
In Settings > Device Policy, choose the Policy you'd like to edit in the "Active Policies" list. In the popup, check or uncheck the actions you'd like to edit and click "Save".
When editing a Policy, you will see a "Save As" option. This option helps speed up creating a Policy if you'd like to create a duplicate of another. If you choose "Save As", be sure to give this new Policy a different name.
Assign Policy (Admin and Zone Manager)
To assign a Policy to a Device, go to the Devices page. In the "Device List", select the Device(s) you'd like to edit, and choose "Assign Policy". You can also go to Device Details and assign Policy in the "Device Info" box.
You can also assign a Policy to a Zone. Go to the Zone Details page and in the "Zone Info" box, select the Policy you'd like. "Apply selected policy to all devices in zone" is checked by default. Your changes will not be saved until you click "Save".
Remove Policy (Admin only)
To remove a policy, go to Settings > Device Policy. In the "Active Policies" list, select the policy or policies you'd like to remove and click "Remove". Any Devices or Zones that were using a deleted policy will be assigned to the "default" policy.
This action removes the policy completely from your console.
Update
This feature is for Admins only
Aurora Endpoint Defense releases updates to the Protect Agent on a regular basis. By default, auto-updating is enabled. If you want to have a more controlled rollout of a new Agent release, you can do so with the Agent Update.
Test
To start testing the Agent release, you can select a Zone and start rolling out the latest Agent release to that Zone. Once you've verified that all devices in that Zone have updated successfully, you can test another Zone in "Pilot".
Pilot
After rolling out the Agent release to the Zone you selected in "Test", you can select another Zone in "Pilot" to further test the rollout.
Production
By default, only the Production tier is "active". Here is where auto-update is enabled. In order to rollout the Agent to selected Zones, you will need to change the default "Auto-Update" selection to a specific agent version in the dropdown. Once you've made the change, "Test" and "Pilot" are now enabled for you.
Notes
- When assigning a Zone in "Pilot", there is a possibility that a device will exist in that Zone, plus the Zone selected in "Test". In that case, the selection in "Test" takes precedence. This also applies when you make an Agent selection in "Production".
- An Agent can only be updated on devices that are not offline. You will see a running count of devices that have been successfully updated. If the specified Zone has offline devices, you will also see a count for those devices. Once a device comes back online, it will receive the update.
- Supported Agent Versions go back to one previous version, so you will be able to update to the latest release or the release prior.
- If you have Zones selected in either "Test" or "Pilot", but have yet to update all remaining Zones, all devices will be updated to the latest release after 30 days.
Audit Log
This feature is for Admins only
You can access the Audit Log in the top right dropdown in the navigation.
Audit Log captures all user interactions in the Endpoint Defense Console. You can see when a user has successfully or failed to login, when a user takes action on a threat, when new zones, or policies are added/created and when a device is removed or edited.
Do not show again. You can always return to this guide by going to your profile icon and selecting " How-to Guide".
Welcome to Aurora Endpoint Defense
This dashboard is designed to give you a summary view of endpoint security in your environment. From this page, you can investigate new alerts, research threats and review protection levels to guide policy or configuration changes.
Alert Triage
Reprise Plugin Starter
See Aurora Endpoint Security in Action Today
Take the next step to learn more about Aurora Endpoint Security.
Aurora Endpoint Interactive Demo
See an interactive demo of the Aurora Endpoint Defense Console
Aurora Endpoint Experience
Experience the power of outcome driven endpoint security
Aurora Endpoint Defense Capabilities
See Aurora Endpoint Defense's detection and response capabilities in action
Join Our Weekly Live Endpoint Demo
Discover Aurora’s AI-powered endpoint protection in a live weekly walkthrough.
Unify Cybersecurity to deliver outcomes
Technology
Platform
Operations
Accelerate with Aurora AI
Easily Scale your Cybersecurity with the Aurora® Superintelligence Platform
Aurora Endpoint Security is integrated with the Aurora Superintelligence Platform, enabling you to quickly and easily scale your cyber security program. At Arctic Wolf we partner with you to operationalize your security, from our world-class endpoint experience, to Managed Detection and Response, to attack surface and vulnerability management, shifting the approach from managing point tools to executing your security strategy.
Explore Aurora Endpoint Security in Action
Wednesdays at 12:00 PM CDT
Discover the power of Aurora Endpoint Security through an informative demo with one of our security experts. Register for one of our weekly demo sessions!