- [Turning Visibility Into Action: Introducing Aurora Exposure Management.   LEARN MORE](https://arcticwolf.com/resources/press-releases/arctic-wolf-introduces-the-next-era-of-exposure-management-to-help-organizations-outpace-ai-accelerated-vulnerability-discovery/)
- [|     |     |     |     |     |\\
| --- | --- | --- | --- | --- |\\
|  | |     |     |     |     |     |\\
| --- | --- | --- | --- | --- |\\
| Search | [Experienced a Breach?](https://arcticwolf.com/emergency-incident-response/) | [Contact Us](https://arcticwolf.com/company/contact-us/) | [Blog](https://arcticwolf.com/resources/blog/) | - [EN](https://arcticwolf.com/solutions/endpoint-security/# "Switch to EN (EN)")    - [EN-GB(United Kingdom)](https://arcticwolf.com/uk/solutions/endpoint-security/ "Switch to United Kingdom (EN-GB)")<br>    - [FR(Français)](https://arcticwolf.com/fr/ "Switch to Français (FR)")<br>    - [DE(Deutsch)](https://arcticwolf.com/de/ "Switch to Deutsch (DE)")<br>    - [Dansk(Danish)](https://arcticwolf.com/da/ "Switch to Danish (Dansk)")<br>    - [Nederlands(Dutch)](https://arcticwolf.com/nl/ "Switch to Dutch (Nederlands)")<br>    - [Suomi(Finnish)](https://arcticwolf.com/fi/ "Switch to Finnish (Suomi)")<br>    - [日本語(Japanese)](https://arcticwolf.com/ja/ "Switch to Japanese (日本語)")<br>    - [Norsk(Norwegian)](https://arcticwolf.com/no/ "Switch to Norwegian (Norsk)")<br>    - [Svenska(Swedish)](https://arcticwolf.com/sv/ "Switch to Swedish (Svenska)")<br>    - [EN-AU(Australia)](https://arcticwolf.com/au/ "Switch to Australia (EN-AU)")<br>    - [Español(Spanish)](https://arcticwolf.com/es/ "Switch to Spanish (Español)") | |](https://arcticwolf.com/solutions/endpoint-security/#)

|     |
| --- |
| - [EN](https://arcticwolf.com/solutions/endpoint-security/# "Switch to EN (EN)")  - [EN-GB(United Kingdom)](https://arcticwolf.com/uk/solutions/endpoint-security/ "Switch to United Kingdom (EN-GB)")<br>  - [FR(Français)](https://arcticwolf.com/fr/ "Switch to Français (FR)")<br>  - [DE(Deutsch)](https://arcticwolf.com/de/ "Switch to Deutsch (DE)")<br>  - [Dansk(Danish)](https://arcticwolf.com/da/ "Switch to Danish (Dansk)")<br>  - [Nederlands(Dutch)](https://arcticwolf.com/nl/ "Switch to Dutch (Nederlands)")<br>  - [Suomi(Finnish)](https://arcticwolf.com/fi/ "Switch to Finnish (Suomi)")<br>  - [日本語(Japanese)](https://arcticwolf.com/ja/ "Switch to Japanese (日本語)")<br>  - [Norsk(Norwegian)](https://arcticwolf.com/no/ "Switch to Norwegian (Norsk)")<br>  - [Svenska(Swedish)](https://arcticwolf.com/sv/ "Switch to Swedish (Svenska)")<br>  - [EN-AU(Australia)](https://arcticwolf.com/au/ "Switch to Australia (EN-AU)")<br>  - [Español(Spanish)](https://arcticwolf.com/es/ "Switch to Spanish (Español)") |

- [Platform](https://arcticwolf.com/aurora-platform/)
  - #### Platform

- [How It Works](https://arcticwolf.com/how-it-works/)
  - Delivering security operations outcomes.

- [Aurora Superintelligence Platform](https://arcticwolf.com/aurora-platform/)
  - Delivering AI outcomes you can trust.

- [Aurora AI](https://arcticwolf.com/aurora-platform/aurora-ai/)
  - Leverage the power of scale and AI expertise.

- [Platform Integrations](https://arcticwolf.com/ecosystem-integrations/)
  - Ecosystem integrations and technology partnerships.
  - #### Agentic SOC

- [Aurora Agentic SOC](https://arcticwolf.com/aurora-soc/)
  - Partner with the world’s largest commercial agentic SOC.

- [Concierge Delivery Model](https://arcticwolf.com/how-it-works/concierge-delivery-model/)
  - Tailored security expertise and guided risk mitigation.

- [Arctic Wolf Security Teams](https://arcticwolf.com/how-it-works/security-teams/)
  - Security experts proactively protecting you 24×7.

- [Incident Response In Action](https://arcticwolf.com/ir-in-action/)
  - Learn how our IR team stops attacks and swiftly restores your organization to pre-incident operations.
  - #### Journey

- [Security Journey](https://arcticwolf.com/how-it-works/security-journey/)
  - Build a resilient business by embracing Security Operations.

- [Cyber Resilience Assessment](https://arcticwolf.com/solutions/cyber-jumpstart/)
  - Map your security posture against industry standard frameworks.
  - |     |
        | --- |
        | - [EN](https://arcticwolf.com/solutions/endpoint-security/# "Switch to EN (EN)")      - [EN-GB(United Kingdom)](https://arcticwolf.com/uk/solutions/endpoint-security/ "Switch to United Kingdom (EN-GB)")<br>      - [FR(Français)](https://arcticwolf.com/fr/ "Switch to Français (FR)")<br>      - [DE(Deutsch)](https://arcticwolf.com/de/ "Switch to Deutsch (DE)")<br>      - [Dansk(Danish)](https://arcticwolf.com/da/ "Switch to Danish (Dansk)")<br>      - [Nederlands(Dutch)](https://arcticwolf.com/nl/ "Switch to Dutch (Nederlands)")<br>      - [Suomi(Finnish)](https://arcticwolf.com/fi/ "Switch to Finnish (Suomi)")<br>      - [日本語(Japanese)](https://arcticwolf.com/ja/ "Switch to Japanese (日本語)")<br>      - [Norsk(Norwegian)](https://arcticwolf.com/no/ "Switch to Norwegian (Norsk)")<br>      - [Svenska(Swedish)](https://arcticwolf.com/sv/ "Switch to Swedish (Svenska)")<br>      - [EN-AU(Australia)](https://arcticwolf.com/au/ "Switch to Australia (EN-AU)")<br>      - [Español(Spanish)](https://arcticwolf.com/es/ "Switch to Spanish (Español)") |

- Ready to get started?      [Request a Demo](https://arcticwolf.com/request-demo/)
- [Solutions](https://arcticwolf.com/solutions/)
  - #### Reduce Attack Frequency

- [Exposure Management](https://arcticwolf.com/solutions/managed-risk/)
  - Continuously discover, prioritize, and reduce exposure across your attack surface.

- [Incident360 Retainer](https://arcticwolf.com/solutions/incident-response-retainer/)
  - Receive end-to-end IR coverage for one incident, no matter the incident type.

- [Security Awareness and Training](https://arcticwolf.com/solutions/security-awareness-and-training/)
  - Engage and prepare employees to recognize and neutralize social engineering attacks.
  - #### Reduce Attack Severity

- [Endpoint Security](https://arcticwolf.com/solutions/endpoint-security/)
  - AI-driven prevention, detection, and response to stop endpoint threats before they disrupt your business.

- [Managed Detection and Response​](https://arcticwolf.com/solutions/managed-detection-and-response/)
  - Quickly detect, respond, and recover from advanced threats.

- [Incident Response](https://arcticwolf.com/solutions/incident-response/)
  - Recover quickly from cyber attacks and breaches, from threat containment to business restoration.

- [Experienced a Breach?](https://arcticwolf.com/emergency-incident-response/)
  - #### Transfer Risk

- [Security Operations Warranty](https://arcticwolf.com/why-arctic-wolf/security-operations-warranty/)
  - Stay covered at no cost with up to $3M in financial assistance for cybersecurity incidents.

- [Cyber Insurance](https://arcticwolf.com/cyber-insurance/)
  - Increase the likelihood of insurability, and potentially lower your rates.

- [Cyber JumpStart](https://arcticwolf.com/solutions/cyber-jumpstart/)
  - Access a complimentary suite of tools to reduce risk and improve insurability.
  - #### Get Started
  - [View All Arctic Wolf Solutions](https://arcticwolf.com/solutions/) [Explore Arctic Wolf Bundles](https://arcticwolf.com/solutions/bundles/) [Calculate Your Security ROI](https://arcticwolf.com/roi-calculator/)
  - |     |
        | --- |
        | - [EN](https://arcticwolf.com/solutions/endpoint-security/# "Switch to EN (EN)")      - [EN-GB(United Kingdom)](https://arcticwolf.com/uk/solutions/endpoint-security/ "Switch to United Kingdom (EN-GB)")<br>      - [FR(Français)](https://arcticwolf.com/fr/ "Switch to Français (FR)")<br>      - [DE(Deutsch)](https://arcticwolf.com/de/ "Switch to Deutsch (DE)")<br>      - [Dansk(Danish)](https://arcticwolf.com/da/ "Switch to Danish (Dansk)")<br>      - [Nederlands(Dutch)](https://arcticwolf.com/nl/ "Switch to Dutch (Nederlands)")<br>      - [Suomi(Finnish)](https://arcticwolf.com/fi/ "Switch to Finnish (Suomi)")<br>      - [日本語(Japanese)](https://arcticwolf.com/ja/ "Switch to Japanese (日本語)")<br>      - [Norsk(Norwegian)](https://arcticwolf.com/no/ "Switch to Norwegian (Norsk)")<br>      - [Svenska(Swedish)](https://arcticwolf.com/sv/ "Switch to Swedish (Svenska)")<br>      - [EN-AU(Australia)](https://arcticwolf.com/au/ "Switch to Australia (EN-AU)")<br>      - [Español(Spanish)](https://arcticwolf.com/es/ "Switch to Spanish (Español)") |

- Ready to get started?      [Request a Demo](https://arcticwolf.com/request-demo/)
- [Why Arctic Wolf](https://arcticwolf.com/why-arctic-wolf/)
  - #### Why Arctic Wolf

- [Industry Analysis](https://arcticwolf.com/why-arctic-wolf/#industry-analysis)
  - [Awards & Recognition](https://arcticwolf.com/why-arctic-wolf/#awards-recognition)
  - [Customer Perspectives](https://arcticwolf.com/customers/)
  - [Security Operations Warranty](https://arcticwolf.com/why-arctic-wolf/security-operations-warranty/)
  - [Arctic Wolf Labs](https://arcticwolf.com/labs/)
  - #### Expertise by Topic

- [Compliance Solutions](https://arcticwolf.com/compliance/)
  - [Ransomware Explained](https://arcticwolf.com/ransomware-explained-understanding-the-ransomware-ecosystem/)

- #### Incident Response Timelines

- [Ransomware Attack & Containment](https://arcticwolf.com/incident-response-timeline-ransomware-attack-containment/)
  - [Business Email Compromise](https://arcticwolf.com/incident-response-timeline-business-email-compromise/)
  - #### Expertise by Industry

- [Financial Services](https://arcticwolf.com/solutions/industries/financial-services/)
  - [Healthcare](https://arcticwolf.com/solutions/industries/healthcare/)
  - [State & Local Government](https://arcticwolf.com/solutions/industries/government/)
  - [Manufacturing](https://arcticwolf.com/solutions/industries/manufacturing/)
  - [Legal](https://arcticwolf.com/solutions/industries/legal/)
  - [View All](https://arcticwolf.com/solutions/industries/)
  - |     |
        | --- |
        | - [EN](https://arcticwolf.com/solutions/endpoint-security/# "Switch to EN (EN)")      - [EN-GB(United Kingdom)](https://arcticwolf.com/uk/solutions/endpoint-security/ "Switch to United Kingdom (EN-GB)")<br>      - [FR(Français)](https://arcticwolf.com/fr/ "Switch to Français (FR)")<br>      - [DE(Deutsch)](https://arcticwolf.com/de/ "Switch to Deutsch (DE)")<br>      - [Dansk(Danish)](https://arcticwolf.com/da/ "Switch to Danish (Dansk)")<br>      - [Nederlands(Dutch)](https://arcticwolf.com/nl/ "Switch to Dutch (Nederlands)")<br>      - [Suomi(Finnish)](https://arcticwolf.com/fi/ "Switch to Finnish (Suomi)")<br>      - [日本語(Japanese)](https://arcticwolf.com/ja/ "Switch to Japanese (日本語)")<br>      - [Norsk(Norwegian)](https://arcticwolf.com/no/ "Switch to Norwegian (Norsk)")<br>      - [Svenska(Swedish)](https://arcticwolf.com/sv/ "Switch to Swedish (Svenska)")<br>      - [EN-AU(Australia)](https://arcticwolf.com/au/ "Switch to Australia (EN-AU)")<br>      - [Español(Spanish)](https://arcticwolf.com/es/ "Switch to Spanish (Español)") |

- Ready to get started?      [Request a Demo](https://arcticwolf.com/request-demo/)
- [Resources](https://arcticwolf.com/resources/)
  - #### Resource Center

- [ROI Calculator](https://arcticwolf.com/roi-calculator/)
  - [Blog](https://arcticwolf.com/resources/blog/)
  - [Case Studies](https://arcticwolf.com/resources/case-studies/)
  - [Events](https://arcticwolf.com/resources/tag/event/)
  - [Analyst Reports](https://arcticwolf.com/resources/report/)
  - [Webinars](https://arcticwolf.com/resources/webinars/)
  - [Podcasts](https://arcticwolf.com/resources/tag/podcasts/)
  - [Glossary](https://arcticwolf.com/resources/glossary/)
  - [Technical Videos](https://arcticwolf.com/resources/technical-videos/)
  - [View All](https://arcticwolf.com/resources/)
  - #### Trending Resources

- |     |
    | --- |
    | [2025 Arctic Wolf Threat Report](https://arcticwolf.com/resource/aw/arctic-wolf-threat-report-2025?lb-mode=overlay) <br>##### The Arctic Wolf Threat Report draws upon the first-hand experience of our security experts, augmented by research from our threat intelligence team.<br>[The Arctic Wolf State of Cybersecurity: 2025 Trends Report](https://arcticwolf.com/resource/aw/arctic-wolf-2025-trends-report?lb-mode=overlay) <br>##### The Arctic Wolf State of Cybersecurity: 2025 Trends Report serves as an opportunity for decision makers to share their experiences over the past 12 months and their perspectives on some of the most important issues shaping the IT and security landscape.<br>[Aurora: A New Dawn For Cybersecurity](https://arcticwolf.com/discoveraurora/)<br>##### Join Arctic Wolf on an interactive journey to discover a better path past the hazards of the modern threat landscape. |

- [View All Resources](https://arcticwolf.com/resources/)
  - #### Security Bulletins

- May 7, 2026

[**CVE-2026-0300 — Critical Buffer Overflow in PAN-OS User-ID Authentication Portal**](https://arcticwolf.com/resources/blog/cve-2026-0300/)

May 1, 2026

[**Beyond the Bug: Why Cybersecurity Still Matters Even If AI Improves Secure Development**](https://arcticwolf.com/resources/blog/why-cybersecurity-still-matters-even-if-ai-improves-secure-development/)

April 14, 2026

[**Microsoft Patch Tuesday: April 2026**](https://arcticwolf.com/resources/blog/microsoft-patch-tuesday-april-2026/)

[VIEW ALL](https://arcticwolf.com/resources/tag/security-bulletins/)

- [View All Bulletins](https://arcticwolf.com/resources/tag/security-bulletins/)
  - |     |
        | --- |
        | - [EN](https://arcticwolf.com/solutions/endpoint-security/# "Switch to EN (EN)")      - [EN-GB(United Kingdom)](https://arcticwolf.com/uk/solutions/endpoint-security/ "Switch to United Kingdom (EN-GB)")<br>      - [FR(Français)](https://arcticwolf.com/fr/ "Switch to Français (FR)")<br>      - [DE(Deutsch)](https://arcticwolf.com/de/ "Switch to Deutsch (DE)")<br>      - [Dansk(Danish)](https://arcticwolf.com/da/ "Switch to Danish (Dansk)")<br>      - [Nederlands(Dutch)](https://arcticwolf.com/nl/ "Switch to Dutch (Nederlands)")<br>      - [Suomi(Finnish)](https://arcticwolf.com/fi/ "Switch to Finnish (Suomi)")<br>      - [日本語(Japanese)](https://arcticwolf.com/ja/ "Switch to Japanese (日本語)")<br>      - [Norsk(Norwegian)](https://arcticwolf.com/no/ "Switch to Norwegian (Norsk)")<br>      - [Svenska(Swedish)](https://arcticwolf.com/sv/ "Switch to Swedish (Svenska)")<br>      - [EN-AU(Australia)](https://arcticwolf.com/au/ "Switch to Australia (EN-AU)")<br>      - [Español(Spanish)](https://arcticwolf.com/es/ "Switch to Spanish (Español)") |

- Ready to get started?      [Request a Demo](https://arcticwolf.com/request-demo/)
- [Partners](https://arcticwolf.com/partners/)
  - #### Partners
  - [Solution Providers](https://arcticwolf.com/partners/solution-providers/)
  - Helping Solution Providers scale their business with a comprehensive portfolio of products and services.

- [Cyber Insurance Providers](https://arcticwolf.com/cyber-insurance-providers/)
  - Arctic Wolf provides the Insurance Partner Program for Brokers and Carriers to support them within the Cyber JumpStart portal.

- [Technology Alliance Partners](https://arcticwolf.com/partners/technology-integrations/)
  - Ecosystem integrations and technology partnerships.
  - [Managed Service Providers](https://arcticwolf.com/partners/managed-service-providers/)
  - Grow your business and solve your customers’ cybersecurity challenges with industry-leading turnkey security operations.

- [OEM Solutions](https://arcticwolf.com/partners/oem-solutions/)
  - Arctic Wolf OEM Solutions enable ISVs, MSSPs, U.S. Federal Agencies, and security companies.
  - [Become a Partner](https://partners.arcticwolf.com/ArcticWolfPartnerPortal/s/login/SelfRegister)
  - |     |
        | --- |
        | - [EN](https://arcticwolf.com/solutions/endpoint-security/# "Switch to EN (EN)")      - [EN-GB(United Kingdom)](https://arcticwolf.com/uk/solutions/endpoint-security/ "Switch to United Kingdom (EN-GB)")<br>      - [FR(Français)](https://arcticwolf.com/fr/ "Switch to Français (FR)")<br>      - [DE(Deutsch)](https://arcticwolf.com/de/ "Switch to Deutsch (DE)")<br>      - [Dansk(Danish)](https://arcticwolf.com/da/ "Switch to Danish (Dansk)")<br>      - [Nederlands(Dutch)](https://arcticwolf.com/nl/ "Switch to Dutch (Nederlands)")<br>      - [Suomi(Finnish)](https://arcticwolf.com/fi/ "Switch to Finnish (Suomi)")<br>      - [日本語(Japanese)](https://arcticwolf.com/ja/ "Switch to Japanese (日本語)")<br>      - [Norsk(Norwegian)](https://arcticwolf.com/no/ "Switch to Norwegian (Norsk)")<br>      - [Svenska(Swedish)](https://arcticwolf.com/sv/ "Switch to Swedish (Svenska)")<br>      - [EN-AU(Australia)](https://arcticwolf.com/au/ "Switch to Australia (EN-AU)")<br>      - [Español(Spanish)](https://arcticwolf.com/es/ "Switch to Spanish (Español)") |

- Ready to get started?      [Request a Demo](https://arcticwolf.com/request-demo/)
- [Company](https://arcticwolf.com/company/overview/)
  - #### Company

- [About Us](https://arcticwolf.com/company/overview/)
  - [Contact Us](https://arcticwolf.com/company/contact-us/)
  - [Leadership](https://arcticwolf.com/company/companyleadership/)
  - [Customers](https://arcticwolf.com/customers/)
  - [FAQ](https://arcticwolf.com/company/faq/)
  - #### Careers

- [Working at Arctic Wolf](https://arcticwolf.com/company/careers/)
  - [Open Jobs](https://arcticwolf.wd1.myworkdayjobs.com/External)
  - [Our Values](https://arcticwolf.com/company/careers/#our-values)
  - [Pack Impact](https://arcticwolf.com/company/the-pack-impact/)
  - #### Press

- [Newsroom](https://arcticwolf.com/resources/news-awards)
  - [Press Releases](https://arcticwolf.com/resources/press-releases/)
  - #### Brand Partnerships

- [BWT Alpine Formula One Team](https://arcticwolf.com/alpine/)
  - [Meyer Shank Racing](https://arcticwolf.com/msr/)
  - [Minnesota Wild](https://arcticwolf.com/wild/)
  - [Alabama Crimson Tide](https://arcticwolf.com/rolltide/)
  - |     |
        | --- |
        | - [EN](https://arcticwolf.com/solutions/endpoint-security/# "Switch to EN (EN)")      - [EN-GB(United Kingdom)](https://arcticwolf.com/uk/solutions/endpoint-security/ "Switch to United Kingdom (EN-GB)")<br>      - [FR(Français)](https://arcticwolf.com/fr/ "Switch to Français (FR)")<br>      - [DE(Deutsch)](https://arcticwolf.com/de/ "Switch to Deutsch (DE)")<br>      - [Dansk(Danish)](https://arcticwolf.com/da/ "Switch to Danish (Dansk)")<br>      - [Nederlands(Dutch)](https://arcticwolf.com/nl/ "Switch to Dutch (Nederlands)")<br>      - [Suomi(Finnish)](https://arcticwolf.com/fi/ "Switch to Finnish (Suomi)")<br>      - [日本語(Japanese)](https://arcticwolf.com/ja/ "Switch to Japanese (日本語)")<br>      - [Norsk(Norwegian)](https://arcticwolf.com/no/ "Switch to Norwegian (Norsk)")<br>      - [Svenska(Swedish)](https://arcticwolf.com/sv/ "Switch to Swedish (Svenska)")<br>      - [EN-AU(Australia)](https://arcticwolf.com/au/ "Switch to Australia (EN-AU)")<br>      - [Español(Spanish)](https://arcticwolf.com/es/ "Switch to Spanish (Español)") |

- Ready to get started?      [Request a Demo](https://arcticwolf.com/request-demo/)
- [EXPERIENCED A BREACH?](https://arcticwolf.com/emergency-incident-response/)
- [REQUEST A DEMO](https://arcticwolf.com/request-demo/)

#### ARCTIC WOLF

# Aurora® Endpoint Security

### Battle-Proven, AI-Powered Endpoint Security

## Stop ransomware and zero‑day threats with a 99% true‑positive rate, world class security ROI, and access to the Aurora® Agentic SOC.

[Request a demo](https://arcticwolf.com/request-demo/)

#### Report Available

## Aurora Endpoint Security Achieves 100% Threat Protection

#### In Independent Evaluation

Download independent testing from the Tolly Group to evaluate both the protection efficacy and system resource utilization of Arctic Wolf Endpoint Security.

[Download Report](https://arcticwolf.com/resource/aw/tolly-group-evaluation-of-arctic-wolf-endpoint-security?lb-mode=overlay)

## Arctic Wolf

## Aurora Endpoint Security

### Endpoint Security

### Managed Endpoint Security

### Aurora Protect

### Features

- Endpoint Protection Platform

- Next-Generation Antivirus

- Aurora AI for Endpoint

- Windows, macOS, Broad Linux support​

- Advanced Threat Protection ​ (PE, Memory, Script Control)

- Device Control

- Application Control

### Aurora Endpoint Defense

- Aurora Protect

### Features

- Endpoint Detection and Response​

- Behavioral Detection Engine

- Threat Hunting Tooling

- MITRE ATT&CK Mapping

- 30-Day Data Retention

- Playbook Automation

### Managed Endpoint Security

### Aurora Managed Endpoint Defense

- Aurora Protect

- Aurora Endpoint Defense

### Features

- Managed Endpoint Security​

- 24x7 Monitoring

- Alert Triage by Aurora Agentic SOC

- Endpoint Security Investigations

- Response Actions

- Guided Remediation

- Tactical Threat Insights

- Ongoing Configuration Assistance​

### Endpoint Security

### Managed Endpoint Security

### Aurora Protect  (formerly CylanceProtect)

### Features

- Endpoint Protection Platform

- Next-Generation Antivirus

- Alpha AI (formerly Cylance AI) for Endpoint

- Windows, macOS, Broad Linux Support

- Advanced Threat Protection (PE, Memory, Script Control)

- Device Control

- Application Control

### Aurora Endpoint Defense  (formerly CylanceProtect + Optics)

- Aurora Protect

### Features

- Endpoint Detection and Response

- Behavioral Detection Engine

- Threat Hunting Tooling

- MITRE ATT&CK Mapping

- 30-Day Data Retention

- Playbook Automation

### Managed Endpoint Security

### Aurora Managed Endpoint Defense On-Demand  (formerly CylanceMDR On Demand)

- Aurora Protect

- Aurora Endpoint Defense

### Features

- On-Demand Security Escalations

- Security Investigation Requests

- Guided Remediation

- Tactical Threat Insights

- Incident Analysis Report

- Ongoing Configuration Assistance​

- Onboarding

### Aurora Managed Endpoint Defense  (formerly CylanceMDR Standard)

- Aurora Protect

- Aurora Endpoint Defense

### Features

- 24x7 Monitoring

- Alert Triage by Arctic Wolf SOC

- Endpoint Security Investigations

- Response Actions

- Guided Remediation

- Tactical Threat Insights

- Incident Analyst Reports

- Campaign-Focused Threat Hunting

- Onboarding

## Mobile‑First Security.  Designed for Security and Privacy.

With Aurora Endpoint Security, organizations can secure smartphones and tablets alongside desktop PCs and laptops, across a wide range of chipsets and processors.

[get a demo](https://arcticwolf.com/company/contact-us/)

### Aurora Mobile ​ Threat Defense

- Mobile Threat Defense
- Rogue & Unsafe Network Defense​
- Identify Non-Compliant Apps
- Prevent Mishing Attacks​
- Malware Detection & Classification​
- Privacy Friendly Forensic Analysis​

- Mobile Threat Defense
- Rogue & Unsafe Network Defense​
- Identify Non-Compliant Apps

- Prevent Mishing Attacks​
- Malware Detection & Classification​
- Privacy Friendly Forensic Analysis​

## Secure Your Endpoints Against Modern Threats

### Battle-Proven Aurora AI

- Zero-day threat prevention with a 99% true positive rate

- On average, quarantined 250 malicious files pre-execution per customer last year

- 30% faster incident investigation and 90% reduction in alert fatigue

### Maximum Security Value

- Arctic Wolf customers, on average, see more than a 13x ROI on their security investment compared to a DIY approach.

- Savings of over 8,000 hours from elimination of AV updates.1

### Efficient, Effective Security

- 27% lower resource consumption than the industry composite.2

- 50% less labor burden from AI-driven efficacy and automation.3

Sources

1. [1: BlackBerry](https://www.blackberry.com/us/en/pdfviewer?file=/content/dam/resources/blackberry-com/resource-library/en/cyber/2022/standard/rp/rp-forrester-total-economic-impact-study-of-cylance-protect.pdf)
2. [2: The Tolly Group](https://tolly.com/publications/225147)
3. [3: BlackBerry](https://www.blackberry.com/us/en/pdfviewer?file=/content/dam/resources/blackberry-com/resource-library/en/cyber/2022/standard/rp/rp-forrester-total-economic-impact-study-of-cylance-protect.pdf)

## Your Endpoints.  Our Expertise.

Unlock Security Delivered by the Aurora Agentic SOC with ongoing tuning and configuration support.

“The onboarding for this product was one of the best I have experienced. We are confident our endpoints are protected.”

5.0★★★★★

Function

IT Security & Risk Management

Industry

Retail

Firm Size

<50M USD

Deployment Architecture

Cloud (SaaS or PaaS or IaaS)

[Read full review →](https://www.gartner.com/reviews/market/endpoint-protection-platforms/vendor/arctic-wolf-networks/product/aurora-endpoint-security/review/view/6435592)

## See the Power of Battle Proven, AI-Powered Endpoint Security

Explore our hands-on experience that allows you to see our market-leading AI-driven endpoint solution in action.

## Start Your Free Experience Today!

See how Aurora Endpoint Defense protects, detects, and responds to real malware as well as adversary tactics and techniques, through six documented use cases.

\*
Email Address

\*
First Name

\*
Last Name

\*
Job Title

\*
Phone Number

\*
Company Name

\*
Select Country

United StatesCanadaUnited KingdomAfghanistanAlandIslandsAlbaniaAlgeriaAmericanSamoaAndorraAngolaAnguillaAntarcticaAntiguaandBarbudaArmeniaArubaAustraliaAustriaAzerbaijanBahrainBangladeshBelarusBelgiumBeninBhutanBolivia,PlurinationalStateofBonaire,SintEustatiusandSabaBosniaandHerzegovinaBouvetIslandBritishIndianOceanTerritoryBruneiDarussalamBurkinaFasoBurundiCambodiaCameroonCapeVerdeChadChristmasIslandCocos(Keeling)IslandsComorosCongo,theDemocraticRepublicoftheCongoCookIslandsCoted'IvoireCubaCuraçaoCyprusDenmarkDjiboutiDominicaEquatorialGuineaEritreaEthiopiaFalklandIslands(Malvinas)FaroeIslandsFijiFinlandFranceFrenchGuianaFrenchPolynesiaFrenchSouthernTerritoriesGabonGambiaGermanyGhanaGreenlandGrenadaGuadeloupeGuernseyGuinea-BissauGuineaHaitiHeardIslandandMcDonaldIslandsHolySee(VaticanCityState)IcelandIndiaIndonesiaIran,IslamicRepublicofIraqIrelandIsleofManItalyIvoryCoastJapanJerseyJordanKazakhstanKenyaKiribatiKorea,DemocraticPeople'sRepublicofKosovoKyrgyzstanLaoPeople'sDemocraticRepublicLatviaLebanonLesothoLiberiaLibyaLiechtensteinLithuaniaLuxembourgMacaoMacedonia,theformerYugoslavRepublicofMadagascarMalawiMalaysiaMaldivesMaliMaltaMarshallIslandsMartiniqueMauritaniaMauritiusMicronesiaMoldova,RepublicofMontenegroMontserratMoroccoMozambiqueMyanmarNamibiaNauruNepalNetherlandsNewCaledoniaNewZealandNigerNiueNorfolkIslandNorthernMarianaIslandsNorwayPakistanPalauPalestinePapuaNewGuineaPhilippinesPitcairnQatarRussianFederationRwandaSaintBarthélemySaintHelena,AscensionandTristandaCunhaSaintKittsandNevisSaintLuciaSaintMartin(Frenchpart)SaintPierreandMiquelonSaintVincentandtheGrenadinesSamoaSanMarinoSaoTomeandPrincipeSenegalSerbiaSeychellesSierraLeoneSingaporeSintMaarten(Dutchpart)SloveniaSolomonIslandsSomaliaSouthAfricaSouthGeorgiaandtheSouthSandwichIslandsSouthSudanSudanSvalbardandJanMayenSwazilandSwedenSwitzerlandSyrianArabRepublicTajikistanTanzania,UnitedRepublicofThailandTimor-LesteTogoTokelauTongaTrinidadandTobagoTunisiaTurkeyTurkmenistanTurksandCaicosIslandsTuvaluUgandaUnitedArabEmiratesUSVirginIslandsUzbekistanVanuatuVietNamVirginIslands,BritishWallisandFutunaWesternSaharaYemenZambiaZimbabwe

\*

By checking this box, you agree to the [Aurora Endpoint Experience Agreement](https://arcticwolf.com/terms/test-drive-agreement/) which governs your access.

\*

Yes, I would like to receive marketing emails from Arctic Wolf about solutions that may be of interest to me.

By submitting this form, you agree to the [Arctic Wolf Website Terms of Use](https://arcticwolf.com/terms-of-use/) and [Arctic Wolf Privacy Policy](https://arcticwolf.com/privacy-policy/).

Submit

### Start Your Free Aurora Endpoint Experience

### See an interactive demo of the Aurora Endpoint Defense Console

Step through this interactive demo to get a sneak preview of the user interface. Following the prompts will guide you through different aspects of the solution from alert management to policy configuration as well as automated response and Aurora AI capabilities.

[Interactive Demo](https://arcticwolf.com/solutions/endpoint-security/#endpoint-interactive-demo)

### An easy to navigate interface for all of your endpoint security needs:

Aurora AI powered endpoint security that delivers prevention and advanced threat protection

Online and offline protection delivered through the lightweight agent with support for all major operating systems

Behavioral Detection Engine that lowers operational overhead and enables the ability to implement automatic response actions

Detection and investigation capabilities including forensic data analysis, sandbox reports, and threat hunting

### Interactive Demo:

### Aurora Endpoint Defense Console

Dashboard \| Aurora Endpoint Defense

Nested Runtime Canvas

Dashboard \| Aurora Endpoint Defense

[**Dashboard**](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)

[**Alerts**](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)

[**Protection**](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)

[**ZONES**](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)

[**Assets**](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)

[**Focus**](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)

[**REPORTS**](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)

[**Policies**](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)

[**Settings**](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)

### Dashboard

[**Running Threats** \\
\\
0\\
\\
Total](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)

[**Running Threats** \\
\\
0\\
\\
Last 24 hours](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)

[**Auto-Run Threats** \\
\\
1\\
\\
Total](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)

[**Auto-Run Threats** \\
\\
0\\
\\
Last 24 hours](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)

[**Quarantined Threats** \\
\\
867\\
\\
Total](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)

[**Quarantined Threats** \\
\\
6\\
\\
Last 24 hours](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)

[**Unique to Endpoint Defense** \\
\\
1\\
\\
Total](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)

[**Unique to Endpoint Defense** \\
\\
0\\
\\
Last 24 hours](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)

#### Total Files Analyzed

380,865

#### Threat Protection

92%

0100

#### Device Protection

99%

0100

#### Threat Events

7/157/167/177/187/197/207/217/227/237/247/257/267/277/287/297/307/318/18/28/38/48/58/68/78/88/98/108/118/128/138/148/150100200300400500600700800900UnsafeAbnormalQuarantinedWaivedCleared

#### [Threats By Priority](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/\# "How do we determine priority?")

#### [68](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/\#)  Total

High

[1](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)

[1.47% of total files](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)  \|
[1 affected devices](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)

Medium

[1](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)

[1.47% of total files](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)  \|
[1affected devices](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)

Low

[66](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)

[97.06% of total files](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)  \|
[1affected devices](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)

#### Threat Classifications

Malware

Trojan

Ransom

Worm

Ransom

Infostealer

Virus

Worm

Backdoor

Backdoor

Trojan

Exploit

Infostealer

Infostealer

Virus

Trojan

Trojan

Backdoor

Backdoor

Trojan

Trojan

Trojan

Trojan

Backdoor

Backdoor

Backdoor

Infostealer

Trojan

Trojan

Trojan

Trojan

Trojan

Virus

Virus

Hacking Tool

Backdoor

Backdoor

Infostealer

Infostealer

Infostealer

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Trojan

Worm

Worm

Virus

Virus

Virus

Virus

Virus

Virus

Bot

Ransom

Generic

PUP

Generic

Hacking Tool

#### Top Ten Lists

- [Threats](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)
- [Devices](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)
- [Zones](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)

**Threats found on the most devices**

01. [T1218-2.dll](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/# "T1218-2.dll")
02. [T1574.012x64.dll](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/# "T1574.012x64.dll")
03. [o.dll](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/# "o.dll")
04. [uacme.zip](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/# "uacme.zip")
05. [phant0m.exe](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/# "phant0m.exe")
06. [uacme.zip](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/# "uacme.zip")
07. [EtwpCreateEtwThread.exe](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/# "EtwpCreateEtwThread.exe")
08. [AllTheThingsx64.dll](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/# "AllTheThingsx64.dll")
09. [T1055.011\_x86.exe](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/# "T1055.011_x86.exe")
10. [uacme.zip](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/# "uacme.zip")

**Devices with the most threats**

1. [AWN-F40B7BD](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/# "AWN-F40B7BD")

**Zones with the most threats**

1. [Testdrive](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/# "Testdrive")
2. [Windows Zone (Default)](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/# "Windows Zone (Default)")

Welcome to Aurora Endpoint Defense

[Close](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)

Our section-by-section tutorials will help you get started in securing your network!

- [Viewing Threats](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)
- [Threat Actions](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)
- [Zones](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)
- [Devices](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)
- [Users](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)
- [User Permissions](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)
- [Policies](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)
- [Update](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)
- [Audit Log](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)

##### Viewing Threats

Threats are viewable based on the Zones you're assigned to. An Admin can see threats across all Zones and Devices, including the "Unzoned" Zone. Users and Zone Managers are limited to the Zones they are assigned to.

**Dashboard**

The Dashboard provides a summary of the protection status of your organization.

**Protection**

The Protection page shows the number of threats found per day, for the last 30 days. The threats table lists all threats, plus file reputation, threat priority, signed status, and AV Industry status. By clicking on the down arrow, you are able to sort by ascending/descending, filter, and add/remove columns.

When selecting a row, you will see an overview of the threat you selected. To view the full threat details, click on the threat name.

The Threat Details page will help you decide what action to take on the threat. Stats will show how the threat has been marked within your own account, as well as across all Endpoint Defense users. The "Affected Devices and Zones" table shows the devices and Zones where the threat is Unsafe, Quarantined, Waived, or Abnormal. The "Detailed Threat Data" tab will show you more information on the threat.

**Zones**

The Zones page will show the at-risk Zones. Most at-risk is determined by the number of threats found in a Zone. The chart will show the number of unsafe and safe devices in each of the 5 most at-risk Zones. The "Zones List" is the list of all Zones that are accessible to you based on your User role.

The Zone Details page shows total threats and average threats per device in the Zone. You will also see a list of all Devices in that Zone.

**Devices**

The Devices page lists all of the devices starting with the device with the most threats. If you are both a User and Zone Manager for several different Zones, you will also see that role listed.

The Device Details page will show you the actual threats that are found on that particular device. The four different states a threat can be in are shown as well: Unsafe Threats, Abnormal, Quarantined, Waived.

##### Threat Actions

You can take actions against threats on the Device Details, Threats, and Threat Details pages. All three pages allow you to choose multiple threats or devices and take the same action.

The following states are available for threats:

- **Unsafe Threats**\- Threats that have been found and are currently running (or) runnable on the device(s) listed.
- **Abnormal**\- When the file reputation of an analyzed file is < 60, Endpoint Defense classifies the file as Abnormal. This indicates that the file may have abnormal features with a lower risk of threat.
- **Quarantined**\- You can choose to quarantine an Unsafe or Abnormal file on the devices it was found. If you are an Admin, you can also choose to Global Quarantine the threat, in which case, the file will be quarantined on any device whenever it is found.
- **Waived**\- You can provide a waiver to a file on the devices it is found. An Admin can also choose to add a file to the Safe List, which would allow it to run on any system in your network. Waivers/Safelisting is typically done for Abnormal files.

**Global Quarantine List/Safe List** (Admin only)

You can place any file into your Global Quarantine List or Safe List if you want to allow it to be quarantined or allowed on all systems. The global lists can be found in Settings > Global List.

##### Zones

**What is a Zone?**

A Zone is a way to organize and manage your devices. You can assign Users to Zones so they can view only what's been assigned to that Zone.

By default, there is an "Unzoned" Zone created. However, only an Admin is able to view devices in this default Zone. You will need to create at least one Zone to allow anyone with a "User" or "Zone Manager" role to view it.

**Add a Zone**(Admin only)

In the navigation bar, click on "Zones". Once you are on the Zones page, scroll down to the Zones List. Click on the "Add New Zone" button. This will trigger a popup that will allow you to name your new Zone.

**Tips for Zones**

You can create Zones based on region (West Coast, East Coast, North America, South America), department (Accounting, Engineering, Marketing), or any type of separation that works for you. This will help you decide who has permissions to see specific devices.

**Remove a Zone**(Admin only)

To remove a Zone, go to the main Zones page. Under the "Zones List", select the Zones you want to remove and click "Remove".

This action removes a Zone completely from your Endpoint Defense console.

##### Devices

**Adding Devices**

If you are an Admin, you can generate an installation token to add a device. Go to Settings > Application. There, you will see a link to generate a token. Once you've generated a token, you will need to copy and enter it during the installation of the Endpoint Defense app.

If you decide to delete or regenerate a token, the previous token will no longer be valid.

If you are a Zone Manager or User, you cannot generate an installation token. You will need to ask your Admin to generate one if one does not exist yet.

**Adding Devices to a Zone**(Admin and Zone Manager)

To add an existing device to a Zone, go to Zones and in the "Zones List", select the Zone you want to add the device to. In the Zone Details page, click on "Add Device to Zone" at the bottom of the "Zones Device List". In the popup, select all the devices you would like to add to the Zone.

**Removing a Device** (Admin only)

You can remove a device by going to the details page of the device. At the bottom of the "Device Info" box, you will see a "Remove this device" link.

This action will remove the device completely from your Endpoint Defense console.

**Removing a Device from a Zone** (Admin and Zone Manager)

To remove a device from a Zone, go to the Zone Details page and scroll to the "Zones Device List". Check the devices you would like remove and click "Remove".

If you want to remove a device from multiple Zones, you will need to go to each Zones details page and remove it from there.

**Edit a Device Name and Changing Policy** (Admin and Zone Manager)

You can do both actions by going to the Device Details page. In the "Device Info" box, you can see the current device name in an editable text field.

In the same section, there is a dropdown menu for Policy.

Once you've completed your changes, be sure to click "Save".

##### Users

The following four roles are available:

- **Administrators** have global permissions. Admins can add or remove users, assign users to Zones (either as a User or a Zone Manager), add or remove devices, create policies, and create zones. Admins can also delete users, devices, policies, and zones permanently from the site.
- **Zone Managers** have permissions within any Zone they manage. They can remove devices, edit policy, and edit device names. Zone Managers can also assign Users to view their zones as well as give other Zone Managers permission to access their zones.
- **Users** are assigned to Zones from an Admin or a Zone Manager. Within an assigned Zone, Users can quarantine or waive threats. If a User is not assigned to any Zone, then there will be no devices to view nor actions to take against threats.
- **Read-only** users have permissions to view the Endpoint Defense console but cannot take any actions nor change any settings.

**Adding Users** (Admin only)

As an Admin, you can add users by going to Settings > User Management. In the "Add Users" box, enter the email address of the user you'd like to add (at the moment, only one email can be entered at a time). You will be required to select a Role and a Zone for the Zone Manager and User roles. This requirement is put into place since any user with a Zone Manager or User role will need to be in a Zone in order to see any devices.

**Adding Users to a Zone** (Admin and Zone Manager)

To add users to specific Zones, go to Settings > User Management. Click on the user you'd like to add to a Zone. On the User Details page, you will see a list of Zones and the user's role in each Zone. Select the user's role for each Zone. Your changes will not go into effect until you click "Save."

**Removing Users** (Admin only)
This action will completely remove users from your Endpoint Defense console.
To remove users, go to Settings > User Management. Check the users you'd like to remove and click "Remove."

**Removing Users from a Zone** (Admin and Zone Manager)

You can remove a user from a Zone by going to Settings > User Management. Click on the user you'd like to remove from a zone. On the User Details page, change the user's role to "None" for each Zone you'd like the user removed from. Your changes will not go into effect until you click "Save."

##### User Permissions

Use this chart as a guideline to help you decide what Roles you assign to users.

|  | Admin | Zone Manager | User - Zone | Read-only |
| --- | --- | --- | --- | --- |

|     |     |     |     |     |
| --- | --- | --- | --- | --- |
| Agent Update |
| View/Edit | X |  |  | X (View Only) |
| Audit Logging |
| View | X |  |  | X |
| Devices |
| Add Devices - Global | X |  |  |  |
| Add Devices to a Zone | X |  |  |  |
| Remove Devices - Global | X |  |  |  |
| Remove Devices from a Zone | X | X |  |  |
| Edit Device Name | X | X |  |  |
| Zones |
| Create Zone | X |  |  |  |
| Delete Zone | X |  |  |  |
| Edit Zone Name - Any | X |  |  |  |
| Edit Assigned Zone Name | X | X |  |  |
| Policy |
| Create Policy - Global | X |  |  |  |
| Create Policy for a Zone | X |  |  |  |
| Add Policy - Global | X |  |  |  |
| Add Policy to a Zone | X | X |  |  |
| Remove Policy - Global | X |  |  |  |
| Remove Policy from a Zone | X | X |  |  |
| Threats |
| Quarantine Files - Global | X |  |  |  |
| Quarantine Files in a Zone | X | X | X |  |
| Waive Files - Global | X |  |  |  |
| Waive Files in a Zone | X | X | X |  |
| Global Quarantine/Safe | X |  |  |  |
| Settings |
| Generate or delete install token | X |  |  |  |
| Generate or delete invite URL | X |  |  |  |
| Copy install token | X | X | X |  |
| Copy invite URL | X |  |  |  |
| User Management |
| Assign users to any Zone | X |  |  |  |
| Assign users to managed Zone | X | X |  |  |
| Assign Zone Managers - Global | X |  |  |  |
| Assign Zones Managers to managed Zones | X | X |  |  |
| Delete users from Aurora Endpoint Defense | X |  |  |  |
| Remove Users from Zone - Global | X |  |  |  |
| Remove Users from managed Zone | X | X |  |  |

##### Policies

**Create Policy** (Admin only)

Create a Policy by going to Settings > Device Policy. At the bottom of the "Active Policies" list, click on "Add New Policy". In the popup, enter the name of your Policy and choose the actions you want, and click "Save".

**Edit Policy** (Admin only)

In Settings > Device Policy, choose the Policy you'd like to edit in the "Active Policies" list. In the popup, check or uncheck the actions you'd like to edit and click "Save".

When editing a Policy, you will see a "Save As" option. This option helps speed up creating a Policy if you'd like to create a duplicate of another. If you choose "Save As", be sure to give this new Policy a different name.

**Assign Policy** (Admin and Zone Manager)

To assign a Policy to a Device, go to the Devices page. In the "Device List", select the Device(s) you'd like to edit, and choose "Assign Policy". You can also go to Device Details and assign Policy in the "Device Info" box.

You can also assign a Policy to a Zone. Go to the Zone Details page and in the "Zone Info" box, select the Policy you'd like. "Apply selected policy to all devices in zone" is checked by default. Your changes will not be saved until you click "Save".

**Remove Policy** (Admin only)

To remove a policy, go to Settings > Device Policy. In the "Active Policies" list, select the policy or policies you'd like to remove and click "Remove". Any Devices or Zones that were using a deleted policy will be assigned to the "default" policy.

This action removes the policy completely from your console.

##### Update

**This feature is for Admins only**

Aurora Endpoint Defense releases updates to the Protect Agent on a regular basis. By default, auto-updating is enabled. If you want to have a more controlled rollout of a new Agent release, you can do so with the Agent Update.

**Test**

To start testing the Agent release, you can select a Zone and start rolling out the latest Agent release to that Zone. Once you've verified that all devices in that Zone have updated successfully, you can test another Zone in "Pilot".

**Pilot**

After rolling out the Agent release to the Zone you selected in "Test", you can select another Zone in "Pilot" to further test the rollout.

**Production**

By default, only the Production tier is "active". Here is where auto-update is enabled. In order to rollout the Agent to selected Zones, you will need to change the default "Auto-Update" selection to a specific agent version in the dropdown. Once you've made the change, "Test" and "Pilot" are now enabled for you.

**Notes**

- When assigning a Zone in "Pilot", there is a possibility that a device will exist in that Zone, plus the Zone selected in "Test". In that case, the selection in "Test" takes precedence. This also applies when you make an Agent selection in "Production".
- An Agent can only be updated on devices that are not offline. You will see a running count of devices that have been successfully updated. If the specified Zone has offline devices, you will also see a count for those devices. Once a device comes back online, it will receive the update.
- Supported Agent Versions go back to one previous version, so you will be able to update to the latest release or the release prior.
- If you have Zones selected in either "Test" or "Pilot", but have yet to update all remaining Zones, all devices will be updated to the latest release after 30 days.

##### Audit Log

**This feature is for Admins only**

You can access the Audit Log in the top right dropdown in the navigation.

Audit Log captures all user interactions in the Endpoint Defense Console. You can see when a user has successfully or failed to login, when a user takes action on a threat, when new zones, or policies are added/created and when a device is removed or edited.

**Do not show again.**   You can always return to this guide by going to your profile icon and selecting " [How-to Guide](https://c.rprs-cdn.com/kX02g6z/x64Wv5y/nLD341n/7031832b828443fa8edf6330d2d646b4/#)".

## Welcome to Aurora Endpoint Defense

This dashboard is designed to give you a summary view of endpoint security in your environment. From this page, you can investigate new alerts, research threats and review protection levels to guide policy or configuration changes.

Alert Triage

Reprise Plugin Starter

## See Aurora Endpoint Security in Action Today

Take the next step to learn more about Aurora Endpoint Security.

## Aurora Endpoint Interactive Demo

See an interactive demo of the Aurora Endpoint Defense Console

[Get Started](https://arcticwolf.com/solutions/endpoint-security/#interactive-demo)

## Aurora Endpoint Experience

Experience the power of outcome driven endpoint security

[Try Now](https://arcticwolf.com/solutions/endpoint-security/#endpoint-experience)

## Aurora Endpoint Defense Capabilities

See Aurora Endpoint Defense's detection and response capabilities in action

[Watch now](https://arcticwolf.com/resource/aw/aurora-endpoint-defense-demo?lb-mode=overlay)

## Join Our Weekly Live Endpoint Demo

Discover Aurora’s AI-powered endpoint protection in a live weekly walkthrough.

[Register Today](https://arcticwolf.com/solutions/endpoint-security/#weekly-webinar)

Unify Cybersecurity to deliver outcomes

### Technology

### Platform

### Operations

Accelerate with Aurora AI

## Easily Scale your Cybersecurity with the Aurora® Superintelligence Platform

Aurora Endpoint Security is integrated with the Aurora Superintelligence Platform, enabling you to quickly and easily scale your cyber security program. At Arctic Wolf we partner with you to operationalize your security, from our world-class endpoint experience, to Managed Detection and Response, to attack surface and vulnerability management, shifting the approach from managing point tools to executing your security strategy.

#### [Explore Aurora Endpoint Security in Action](https://event.on24.com/wcc/r/5247168/9C8845B2886769714A433F82EB915FB5)

Wednesdays at 12:00 PM CDT

Discover the power of Aurora Endpoint Security through an informative demo with one of our security experts. Register for one of our weekly demo sessions!

[REGISTER NOW](https://event.on24.com/wcc/r/5247168/9C8845B2886769714A433F82EB915FB5)

### Additional Resources for

### Aurora Endpoint Security
