Install Arctic Wolf Agent on a single macOS endpoint
You can install Arctic Wolf® Agent on a single macOS endpoint.
Agent is designed to maintain a minimal footprint on all systems, but Arctic Wolf recommends some OS requirements. Arctic Wolf cannot guarantee functionality on virtual machine (VM) environments if resources do not meet recommended levels.
These resources are required:
-
To correctly view Agent risks in the Unified Portal, macOS Agent version 2024-01_27 or later is required
-
Administrator permissions or the ability to do administrator or root level functions
-
A supported macOS version. For more information, see Agent support for macOS.
-
The minimum system resources. For more information, see Agent hardware requirements.
These actions are required:
-
For versions 2024-01_27 or higher, make sure outbound access is available for port 443. For lower versions, make sure outbound access is available for ports 443 and 1514.
Configure your environment firewall
Configure your firewall to allow traffic to Agent DNS hostnames.
Add Agent processes to the allowlist
If you install Agent and an antivirus, endpoint scanner, Endpoint Detection and Response (EDR) solution, Unified Threat Management (UTM) solution, or similar software, add Agent processes to the allowlist in those applications to maintain stable CPU and memory utilization:
Configure PPPC
If you are an Aurora Vulnerability Management (Aurora VM) customer, to detect all vulnerabilities during scans, you must enable Full Disk Access in Privacy Preferences Policy Control (PPPC) settings.
Download and install Agent
- Download the Agent installer:
- Extract the Agent zip contents into a folder to access the PKG and customer.json files.
- Right-click the PKG file.
- Click Open to run the installation.
- Follow the prompts to proceed with the installation.
- Contact your Arctic Wolf Customer Success Manager or your Concierge Security® Team (CST) at security@arcticwolf.com to confirm that Agent data is reaching Arctic Wolf.