Sekoia Endpoint Agent
The Sekoia Endpoint Agent collects security-related events from Windows, Linux, and macOS endpoints and sends them directly to Sekoia.
Log integrity
The Sekoia Endpoint Agent does not modify or rewrite logs collected from the operating system event log.
Supported OS versions
The agent supports the following operating systems on 64-bit versions only.
Modern release line:
- Windows 10
- Windows 11
- Windows Server 2016
- Windows Server 2019
- Windows Server 2022
- Windows Server 2025
Legacy release line (limited support):
- Windows 8 and 8.1
- Windows Server 2012 and 2012 R2
- Windows Server 2008 and 2008 R2
The agent supports Linux distributions based on kernel version 3.10 or newer. The following list is non-exhaustive:
- Ubuntu 14.04 and newer
- Debian 8 and newer
- CentOS 7 and newer
- Red Hat 7 and newer
- macOS 13 Ventura and newer
Legacy Windows release line
Windows systems older than Windows 10 (build lower than 10240) are automatically served a dedicated legacy build of the agent. This covers Windows 8 and 8.1, Windows Server 2012 and 2012 R2, and Windows Server 2008 and 2008 R2.
Automatic routing
You do not need to do anything. Modern and legacy systems install with the same command, and the platform serves each host the build that matches its operating system. Existing installations keep working.
The legacy release line receives bug fixes and security fixes so these hosts stay compatible and protected. It does not receive new feature enhancements, which ship only to the modern release line on Windows 10, Windows 11 and the current Windows Server versions.
New features
To find out about the changes between each version please check the agent's changelog
Prerequisites
The agent uses HTTPS (port 443) to send events and includes an automatic update mechanism. Open the following network streams before installation.
Events collected
The following lists show a non-exhaustive sample of events the agent detects. The exact events depend on context, configuration, and agent version.
- File creation, deletion, and rename
- Process lifecycle
- Remote thread execution
- DNS resolution
- TCP connection
- PowerShell commands
- WMI activity
- NTLM
- Windows Defender events
- Sysmon events (if Sysmon is configured)
- Root command executions
- File creation, deletion, rename, and change
- Process lifecycle
- TCP connection
- Python and Perl commands
- PIP and APT installs
- Cron configuration and scheduled jobs
- Sudoers file changes
- Passwd operations
- Suspicious activity (curl, Wireshark, and similar tools)
- Root command executions
- File creation, deletion, rename, and change
- DNS resolution
- TCP connection
- PIP and APT installs
- Sudoers file changes
- Passwd operations
- Suspicious activity (curl, Wireshark, and similar tools)
Resource footprint
The agent is designed to minimize impact on monitored systems.
| Resource | Typical usage |
|---|---|
| CPU | Less than 1% on average |
| RAM | Around 36 MB |
| Disk (installation) | ~15 MB for the binary; a few KB for the configuration file |
| Disk (operations) | Log files rotated at 100 MB by default; up to 5 compressed rotated files kept |
Tip
You can customize the log rotation settings. See Configure the Sekoia Endpoint Agent.
Changelog
For a full list of changes between versions, see the agent changelog.
Related articles
Install the Sekoia Endpoint Agent: How to create an intake, download, and install the agent on Windows, Linux, and macOS.
Configure the Sekoia Endpoint Agent: How to set up log file collection, proxy, retention, and optional features.
Update and uninstall the Sekoia Endpoint Agent: How to update the agent manually and remove it from a host.
Troubleshoot the Sekoia Endpoint Agent: How to read agent logs and resolve common errors.
Sekoia Endpoint Agent — events and fields reference: Reference for data source categories, event samples, and extracted ECS fields.
Sekoia Endpoint Agent — built-in detection rules: Reference for all built-in detection rules that match this intake.