View Agent Audits

  1. Sign in to the Risk Dashboard.
  2. In the navigation menu, click Assets.
  3. In the Asset Catalog section, in the Source column, click any Agent.

    If Arctic Wolf® Agent discovered the asset and the asset information is available, it is provided in one of these sections:

Task List table

The Task List table displays when you view Agent Audits and the asset information is available. The table columns are different, depending on the OS that is scanned. The table can have any of these columns:

Column

Description

Command

The command associated with the task.

Handle Count

The number of object handles in the object table of the task.

Name

The name of the task.

PCPU

The percent of central processing unit (CPU) that is used.

PID

The process identifier (PID) associated with the process.

PMEM

The percent of the process’s RSS to physical memory (MEM) that is used.

PPID

The parent process identifier (PPID).

Priority

The priority of the task.

Process ID

The process ID of the task.

RSS

The resident set size (RSS) or portion of random access memory (RAM) that the process uses.

Session ID

The session ID that the task is using.

STAT

The current status (STAT) of the process.

Thread Count

The number of threads working on the task.

Time

The time since the process started.

TT

The task type (TT).

VSZ

The virtual memory size (VSZ) or the size of memory allocated to a process, even if it does not use it.

Working Set Size

The amount of memory that the task needs to function.

Wireless Networks table

The Wireless Networks table displays when you view Agent Audits and the asset information is available. The table columns are different, depending on the operating system (OS) that is scanned.

The table can have any of these columns:

Column

Description

Authentication

The authentication type of the network.

BSSID

The basic service set identifier (BSSID) that uniquely identifies the radio of the access point using a media access control (MAC) address.

Channel

The small band within a larger frequency band that the wireless network uses to transmit wireless signals.

Country

The country code of the wireless device.

Encryption

The encryption type of the network.

IsCurrent

Whether the network is currently connected to the machine (True) or not (False).

MCS Index

The modulation coding scheme (MCS) index that is supported.

Message

The number of available networks. For example, There are 3 networks currently visible.

Mode

The wireless mode.

Name

The name of the network.

Network Type

The type of network.

Network

The network name.

Noise

The signal in decibels (-dBm) that is not WiFi traffic. The closer to 0, the greater the noise.

Security

The wireless security protocol provided by the wireless network.

Signal

The current signal strength in (-dBm). The closer to 0, the better the signal.

SSID Name

The service set identifier (SSID) that uniquely names the wireless local area network (WLAN) that devices connect to.

Transit Rate

The throughput capability of wireless devices connected to the network.

USB Devices table

The USB Devices table displays when you view Agent Audits and the asset information is available. The table columns are different, depending on the operating system (OS) that is scanned.

The table can have any of these columns:

Column

Description

Bus

The universal serial bus (BUS) identifier.

Device ID

The unique ID of the USB device.

Device

The device name.

Manufacturer

The manufacturer of the USB device.

Name

The name of the USB device.

Product ID

The product identification number.

Serial Number

The serial number of the USB, if available.

Speed

The speed of the USB in Mb/s.

Status

The status of the USB device.

Vendor ID

The identification number of the vendor.

Version

The software version on the USB device.

Software Packages table

The Software Packages table displays when you view Agent Audits and the asset information is available. The table columns are different, depending on the operating system (OS) that is scanned.

The table can have any of these columns:

Column

Description

Arch

The hardware architecture.

Install Location

The location that the software package is installed on the device.

Install Source

The location of the file that the software package was installed from.

Installed

The date that the software package was installed, formatted as YYYYMMDD.

Intel 64bit

Whether the software can run on Intel 64bit CPUs.

Kind

The type of software package.

Last Modified

The date and time that the software package was last modified.

Location

The file path of the software.

Name

The name of the software package.

Obtained From

The source of the software package.

Signed By

The signing authority of the software package.

Summary

A description of the software.

Vendor

The vendor of the software package.

Version

The version number of the software package.