Aurora Focus optional sensors
You can enable any of the following Aurora Focus sensors to collect additional data beyond standard process, file, network, and registry events. Enabling optional sensors can impact performance and resource usage on devices, as well as the amount of data stored in the Aurora Focus database. Arctic Wolf recommends enabling optional sensors on a small number of devices initially to assess the impact.
The optional sensors are supported for Windows 64-bit operating systems only, unless otherwise noted.
|
Sensor |
Description |
Best practices |
Notes |
|---|---|---|---|
|
Advanced Portable Executable Parsing |
The Aurora Focus agent records data fields associated with portable executable files, such as file version, import functions, and packer types. Signal to noise ratio: Moderate Potential data retention and performance impact: Low |
Recommended for:
|
|
|
Advanced PowerShell Visibility |
The Aurora Focus agent records commands, arguments, scripts, and content from JScript, PowerShell (console and integrated scripting environment), VBScript, and VBA macro script execution. Signal to noise ratio: High Potential data retention and performance impact: Low to moderate |
Recommended for:
Not recommended for Microsoft Exchange and email servers. |
|
|
Advanced WMI Visibility |
The Aurora Focus agent records additional WMI attributes and parameters. Signal to noise ratio: High Potential data retention and performance impact: Low |
Recommended for:
|
|
|
API Sensor |
The Aurora Focus agent monitors an identified set of Windows API calls. Signal to noise ratio: Moderate Potential data retention and performance impact: Enabling this sensor may impact a device's CPU performance |
Recommended for:
|
|
|
COM Object Visibility |
The Aurora Focus agent monitors COM interface and API calls to detect malicious behaviors such as scheduled task creation. Signal to noise ratio: High Potential data retention and performance impact: Enabling this sensor may impact CPU performance. |
Recommended for:
Not recommended for servers. |
|
|
DNS Visibility |
The Aurora Focus agent records DNS requests, responses, and associated data fields such as Domain Name, Resolved Addresses, and Record Type. Signal to noise ratio: Moderate Potential data retention and performance impact: Moderate |
Recommended for:
Not recommended for DNS servers. |
|
|
Enhanced File Read Visibility |
The Aurora Focus agent monitors file reads within an identified set of directories. Signal to noise ratio: Moderate Potential data retention and performance impact: Low |
Recommended for:
|
|
|
Enhanced Process and Hooking Visibility |
The Aurora Focus agent records process information from the Win32 API and Kernel Audit messages to detect forms of process hooking and injection. Signal to noise ratio: Moderate Potential data retention and performance impact: Low |
Recommended for:
|
|
|
HTTP Visibility |
The Aurora Focus agent tracks Windows HTTP transactions, including Event Tracing for Windows, WinINet APIs, and WinHTTP APIs. Signal to noise ratio: High Potential data retention and performance impact: Enabling this sensor may impact CPU performance. |
Recommended for:
Not recommended for servers. |
|
|
Module Load Visibility |
The Aurora Focus agent monitors module loads. Signal to noise ratio: High Potential data retention and performance impact: Enabling this sensor may impact CPU performance. |
Recommended for:
|
|
|
Private Network Address Visibility |
The Aurora Focus agent records network connections within the RFC 1918 and RFC 4193 address spaces. Signal to noise ratio: Low Potential data retention and performance impact: Low |
Recommended for desktops.
Not recommended for:
|
|
|
Windows Advanced Audit Visibility |
The Aurora Focus agent monitors additional Windows event types and categories. Signal to noise ratio: Moderate Potential data retention and performance impact: Low |
Recommended for:
|
This sensor enables monitoring of the following event IDs:
|
|
Windows Event Log Visibility |
The Aurora Focus agent records Windows security events and their associated attributes. Signal to noise ratio: Moderate Potential data retention and performance impact: Moderate |
Recommended for:
Not recommended for:
|
|