CylanceOPTICS sensors Skip Navigation

CylanceOPTICS
sensors

The following sensors are enabled by default in the
CylanceOPTICS
agent when you turn on
CylanceOPTICS
in a device policy. You cannot disable these sensors. For more information about the optional sensors that you can enable, see CylanceOPTICS optional sensors.
For more information about the events, artifacts, and event types associated with both the default and optional sensors, see Data structures that CylanceOPTICS uses to identify threats.
Sensor
Platform
Description
Event types
Device
macOS
Linux
Collects relevant device information
Mount
File
Windows
macOS
Linux
Collects information about file operations
  • Create
  • Delete
  • Overwrite
  • Rename
  • Write
Memory
macOS
Linux
Collects information about memory operations
  • Mmap
  • MProtect
Network
Windows
macOS
Linux
Collects information about network connections
Connect
Process
Windows
macOS
Linux
Collects information about process operations
Supported event types differ by platform. See the Process section of Data structures that CylanceOPTICS uses to identify threats.
  • Abnormal Exit
  • Exit
  • Forced Exit
  • PTrace
  • Start
  • Suspend
  • Unknown Linux Process Event
Registry
Windows
Collects information about registry operations
  • KeyCreated
  • KeyDeleting
  • ValueChanging
  • ValueDeleting