🌙
 

Subscribe to the Taegis™ XDR Documentation RSS Feed at .

Learn more about RSS readers or RSS browser extensions.

Taegis Endpoint Agent Introduction

integrations endpoints edr taegis agent secureworks


Existing customers will be upgraded to the Taegis™ XDR Endpoint Agent on a rolling basis to account for service upgrade considerations that need to be addressed for successful migration. Look for a message in Secureworks® Taegis™ XDR in the Endpoint Agents section with further details on how to request to upgrade to the new agent.

Note

Submitting this request does not guarantee immediate access to the Taegis Endpoint Agent. We are being thoughtful about the roll-out of the agent and reviewing requests daily. For further information on next steps after completing the request, contact your Customer Success Manager.

Migrate from Red Cloak Endpoint Agent to Taegis Endpoint Agent

Guidance for migrating from the Red Cloak™ Endpoint Agent to the Taegis Endpoint Agent can be found in the following Knowledge Base article: Red Cloak to Taegis Agent Migration.

Additionally, Secureworks has provided an Agent Migrator PowerShell script intended to support customers with the migration. Customers are encouraged to leverage this script for new Windows deployments. The script is dynamic and can recognize if Red Cloak removal is needed or not. For more information, see Windows Agent Installation.

Benefits

The Taegis Endpoint Agent:

New User Walkthrough

To guide your experience with the Taegis Endpoint Agent, use the following documents and Knowledge Base articles. These are categorized to provide a quick reference to assist with installation, troubleshooting, and use of the Taegis Endpoint Agent:

Agent Setup

When you have access to your XDR tenant, you will be able to start using the Taegis Endpoint Agent. Follow these steps to setup and install the agent:

  1. Review Group Configuration and consider a logical group structure to associate alike types of systems. Or alternatively, register all systems with a single Group Configuration, if desired.

Use the following to understand important terms for creating or editing a Group Configuration:

Consider these additional tenant-level agent settings that impact all groups:

  1. Create one or more required groups.

  2. Once required groups are configured in your XDR tenant, review Agent Downloads to download the Taegis Endpoint Agent installation package to your machine.

  3. Before starting the installation process, check the following points:

  1. Once the preceding points are fulfilled, refer to the relevant documentation for your platform for guidance on installing the Taegis Endpoint Agent on your system:

The Knowledge Base contains several articles supporting Taegis Endpoint Agent deployment and installation via MDM (Mobile Device Management) tools such as SCCM and Workspace ONE. See the following articles if distributing Taegis Endpoint Agent software using MDM tools:

  1. After the installation process, review Manage Endpoint Agents. Use the information to understand how to navigate and manipulate the Endpoint Agents Summary in XDR and validate that deployed and installed agents are reporting into your tenant.

Troubleshoot Installation Issues

If you experience issues during installation, consult the following dedicated troubleshooting documentation and Knowledge Base articles specific to your platform.

Troubleshooting Documentation

Troubleshooting Knowledge Base Articles

If the troubleshooting guidance provided here does not resolve your issue, seek assistance from Product Support via chat or support ticket.

Manage Agents in XDR

Reassign Taegis Endpoint Agent Group

Taegis Endpoint Agents are associated to a group and its configuration by a Registration Key in Group Configuration during installation.

Once installed, you can reassign an agent to another group by following Reassign Taegis Agent Group.

Tagging

Tagging agents can provide context to your endpoints in XDR. This information can be used for filtering the view of your endpoints by specific tags, or as criteria for executing an Automations Playbook, for example.

To add or remove a tag in XDR, see Add and Remove Endpoint Tags.

Additionally, you can perform tagging in bulk for multiple endpoints using an Automations Playbook. See the following Knowledge Base article: How To: Configuring Endpoint Tagging - Multi Automation.

Update Taegis Endpoint Agents

Taegis Endpoint Agents are automatically updated to the latest version of the release channel (Beta, Preview, Production Stable) configured in the group to which they are assigned when the following events occur:

Create Agent Host Isolation and Restore Playbooks

XDR can isolate and restore hosts installed with Taegis Endpoint Agents, preventing them from communicating within or outside of the network environment. Using the Automations capabilities within XDR, you can quickly react to a situation where endpoints are considered to be compromised.  

Isolating or restoring hosts running Taegis Endpoint Agents requires the definition of Automations Playbooks. The following article explains the configuration and operation of the Taegis Endpoint Agent isolation and restore Playbooks: How To: Configure Host Isolation and Restore Playbook - Taegis Endpoint Agent.

Archive or Unarchive Agents

If you wish to remove agents that appear in the Endpoint Agent Summary table from view, such as agents that have been uninstalled, you can archive them.

See Agent Status Options to understand status labels for Taegis Endpoint Agents in your tenant and how to filter by each status, including archived agents.

Note

Permanently removing agents from XDR is not possible. Archive the agents instead.

Archive or unarchive agents manually in XDR by following Archive and Restore Selected Endpoints, or configure Auto Archive at a tenant level or group level.

Uninstall Agents

To uninstall Taegis Endpoint Agents to remove them from the endpoint or system, see Taegis Endpoint Agent Uninstall.

More Information

Technical Information and Taegis Endpoint Agent Specifications

Release Notes for Taegis Endpoint Agent

Tip

If you would like notifications when there is an update to the Taegis Endpoint Agent, subscribe to the Changelog RSS Feed. You'll need an RSS Reader or an RSS Extension for your browser.

Submit a Feature Request

If there is a feature you would like that is not currently available, such as a Linux OS not yet supported, please review Product Roadmap to submit your idea in Product Board.

 

On this page: