Skip to content

Sekoia Endpoint Agent

The Sekoia Endpoint Agent collects security-related events from Windows, Linux, and macOS endpoints and sends them directly to Sekoia.

Log integrity

The Sekoia Endpoint Agent does not modify or rewrite logs collected from the operating system event log.

Supported OS versions

The agent supports the following operating systems on 64-bit versions only.

Modern release line:

  • Windows 10
  • Windows 11
  • Windows Server 2016
  • Windows Server 2019
  • Windows Server 2022
  • Windows Server 2025

Legacy release line (limited support):

  • Windows 8 and 8.1
  • Windows Server 2012 and 2012 R2
  • Windows Server 2008 and 2008 R2

The agent supports Linux distributions based on kernel version 3.10 or newer. The following list is non-exhaustive:

  • Ubuntu 14.04 and newer
  • Debian 8 and newer
  • CentOS 7 and newer
  • Red Hat 7 and newer
  • macOS 13 Ventura and newer

Legacy Windows release line

Windows systems older than Windows 10 (build lower than 10240) are automatically served a dedicated legacy build of the agent. This covers Windows 8 and 8.1, Windows Server 2012 and 2012 R2, and Windows Server 2008 and 2008 R2.

Automatic routing

You do not need to do anything. Modern and legacy systems install with the same command, and the platform serves each host the build that matches its operating system. Existing installations keep working.

The legacy release line receives bug fixes and security fixes so these hosts stay compatible and protected. It does not receive new feature enhancements, which ship only to the modern release line on Windows 10, Windows 11 and the current Windows Server versions.

New features

To find out about the changes between each version please check the agent's changelog

Prerequisites

The agent uses HTTPS (port 443) to send events and includes an automatic update mechanism. Open the following network streams before installation.

Events collected

The following lists show a non-exhaustive sample of events the agent detects. The exact events depend on context, configuration, and agent version.

  • File creation, deletion, and rename
  • Process lifecycle
  • Remote thread execution
  • DNS resolution
  • TCP connection
  • PowerShell commands
  • WMI activity
  • NTLM
  • Windows Defender events
  • Sysmon events (if Sysmon is configured)
  • Root command executions
  • File creation, deletion, rename, and change
  • Process lifecycle
  • TCP connection
  • Python and Perl commands
  • PIP and APT installs
  • Cron configuration and scheduled jobs
  • Sudoers file changes
  • Passwd operations
  • Suspicious activity (curl, Wireshark, and similar tools)
  • Root command executions
  • File creation, deletion, rename, and change
  • DNS resolution
  • TCP connection
  • PIP and APT installs
  • Sudoers file changes
  • Passwd operations
  • Suspicious activity (curl, Wireshark, and similar tools)

Resource footprint

The agent is designed to minimize impact on monitored systems.

Resource Typical usage
CPU Less than 1% on average
RAM Around 36 MB
Disk (installation) ~15 MB for the binary; a few KB for the configuration file
Disk (operations) Log files rotated at 100 MB by default; up to 5 compressed rotated files kept

Tip

You can customize the log rotation settings. See Configure the Sekoia Endpoint Agent.

Changelog

For a full list of changes between versions, see the agent changelog.

Install the Sekoia Endpoint Agent: How to create an intake, download, and install the agent on Windows, Linux, and macOS.

Configure the Sekoia Endpoint Agent: How to set up log file collection, proxy, retention, and optional features.

Update and uninstall the Sekoia Endpoint Agent: How to update the agent manually and remove it from a host.

Troubleshoot the Sekoia Endpoint Agent: How to read agent logs and resolve common errors.

Sekoia Endpoint Agent — events and fields reference: Reference for data source categories, event samples, and extracted ECS fields.

Sekoia Endpoint Agent — built-in detection rules: Reference for all built-in detection rules that match this intake.