Skip to content

Commit ef5cacc

Browse files
committed
Update run-analyzer-macos-linux.md
1 parent 895e4ac commit ef5cacc

File tree

1 file changed

+41
-25
lines changed

1 file changed

+41
-25
lines changed

defender-endpoint/run-analyzer-macos-linux.md

Lines changed: 41 additions & 25 deletions
Original file line numberDiff line numberDiff line change
@@ -258,11 +258,11 @@ The files generated when using this mode are summarized in the following table:
258258
| ------------- | ------------- |
259259
| `mde_diagnostic.zip` | Defender for Endpoint logs and configs |
260260
| `health.txt` | The health status of Defender for Endpoint [^1] |
261-
| `health_details_features.txt` | The health status of additional MDE features [^1] |
262-
| `permissions.txt` | Permission issues with the folders owned/used by MDE [^1] |
263-
| `crashes` | Crash dumps generated by MDE |
261+
| `health_details_features.txt` | The health status of additional Defender for Endpoint features [^1] |
262+
| `permissions.txt` | Permission issues with the folders owned/used by Defender for Endpoint [^1] |
263+
| `crashes` | Crash dumps generated by Defender for Endpoint |
264264
| `process_information.txt` | Process running in the machine when the tool was run |
265-
| `proc_directory_info.txt` | Mapping of the virtual memory of MDE processes [^1] |
265+
| `proc_directory_info.txt` | Mapping of the virtual memory of Defender for Endpoint processes [^1] |
266266
| `auditd_info.txt` | Auditd health, rules, logs |
267267
| `auditd_log_analysis.txt` | Summary of events processed by auditd |
268268
| `auditd_logs.zip` | Auditd log files |
@@ -273,55 +273,55 @@ The files generated when using this mode are summarized in the following table:
273273
| `ebpf_maps_info.txt` | eBPF maps' id and size info |
274274
| `syslog.zip` | The files usder /var/log/syslog |
275275
| `messages.zip` | The files under /var/log/messages |
276-
| `conflicting_processes_information.txt` | MDE Conflicting Processes |
276+
| `conflicting_processes_information.txt` | Defender for Endpoint Conflicting Processes |
277277
| `exclusions.txt` | List of AV exclusions |
278278
| `definitions.txt` | AV defintion info |
279-
| `mde_directories.txt` | List of files in the MDE directories |
279+
| `mde_directories.txt` | List of files in the Defender for Endpoint directories |
280280
| `disk_usage.txt` | Disk usage details |
281-
| `mde_user.txt` | MDE User Info |
282-
| `mde_definitions_mount.txt` | MDE Definitions Mount Point |
283-
| `service_status.txt` | MDE Service Status |
284-
| `service_file.txt` | MDE Service File |
281+
| `mde_user.txt` | Defender for Endpoint User Info |
282+
| `mde_definitions_mount.txt` | Defender for Endpoint Definitions Mount Point |
283+
| `service_status.txt` | Defender for Endpoint Service Status |
284+
| `service_file.txt` | Defender for Endpoint Service File |
285285
| `hardware_info.txt` | Hardware Information |
286286
| `mount.txt` | Mount point information |
287287
| `uname.txt` | Kernel info |
288288
| `memory.txt` | System memory info |
289289
| `meminfo.txt` | Detailed information about the system's memory usage |
290290
| `cpuinfo.txt` | CPU Information |
291291
| `lsns_info.txt` | Linux namespace information |
292-
| `lsof.txt` | MDE Open File Descriptors Information [^1] |
293-
| `sestatus.txt` | MDE Open File Descriptors Information |
292+
| `lsof.txt` | Defender for Endpoint Open File Descriptors Information [^1] |
293+
| `sestatus.txt` | Defender for Endpoint Open File Descriptors Information |
294294
| `lsmod.txt` | Status of modules in the Linux kernel |
295295
| `dmesg.txt` | Messages from the kernel ring buffer |
296296
| `kernel_lockdown.txt` | kernel lockdown Info |
297-
| `rtp_statistics.txt` | MDE Real Time Protection(RTP) statistics [^1] |
297+
| `rtp_statistics.txt` | Defender for Endpoint Real Time Protection(RTP) statistics [^1] |
298298
| `libc_info.txt` | libc library information |
299299
| `uptime_info.txt` | Time since last restart |
300300
| `last_info.txt` | Listing of last logged in users |
301301
| `locale_info.txt` | Show current locale |
302302
| `tmp_files_owned_by_mdatp.txt` | /tmp files owned by group:mdatp [^1] |
303-
| `mdatp_config.txt` | All the MDE configurations [^1] |
303+
| `mdatp_config.txt` | All the Defender for Endpoint configurations [^1] |
304304
| `mpenginedb.db`, `mpenginedb.db-wal`, `mpenginedb.db-shm` | AV definations file [^1] |
305305
| `iptables_rules.txt` | Linux iptables rules |
306306
| `network_info.txt` | Network information |
307307
| `sysctl_info.txt` | kernel settings info |
308308
| `hostname_diagnostics.txt` | Hostname diagnostics information |
309-
| `mde_event_statistics.txt` | MDE Event statistics [^1] |
310-
| `mde_ebpf_statistics.txt` | MDE eBPF statistics [^1] |
309+
| `mde_event_statistics.txt` | Defender for Endpoint Event statistics [^1] |
310+
| `mde_ebpf_statistics.txt` | Defender for Endpoint eBPF statistics [^1] |
311311
| `kernel_logs.zip` | Kernel logs |
312312
| `mdc_log.zip` | Microsoft Defender for Cloud logs |
313313
| `netext_config.txt` | |
314-
| `threat_list.txt` | List of threats detected by MDE [^1] |
314+
| `threat_list.txt` | List of threats detected by Defender for Endpoint [^1] |
315315
| `top_output.txt `| Process running in the machine when the tool was run |
316316
| `top_summary.txt` | Memeory and CPU usage analytics of the process running |
317317
318-
[^1]: Only when MDE is installed.
318+
[^1]: Only when Defender for Endpoint is installed.
319319
320320
### Positional arguments
321321
322322
#### Collect performance info
323323
324-
Collect extensive machine performance tracing of MDE processes for analysis of a performance scenario that can be reproduced on demand.
324+
Collect extensive machine performance tracing of Defender for Endpoint processes for analysis of a performance scenario that can be reproduced on demand.
325325
326326
```console
327327
-h, --help show this help message and exit
@@ -333,9 +333,11 @@ Collect extensive machine performance tracing of MDE processes for analysis of a
333333
Usage example: `sudo ./MDESupportTool performance --frequency 500`
334334
335335
The files generated when using this mode:
336+
336337
| File | Remarks |
337-
| ------------- | ------------- |
338-
| perf_benchmark.tar.gz | MDE processes performance data |
338+
| ------ | ------ |
339+
| `perf_benchmark.tar.gz` | Defender for Endpoint processes performance data |
340+
339341
> [!NOTE]
340342
> The files corresponding to diagnostic mode will also be generated.
341343
@@ -345,37 +347,43 @@ The data file can be read using the command:
345347
`perf report -i <pid>.data`
346348
347349
#### Run connectivity test
348-
This modes test if the cloud resources needed by MDE is reachable or not.
350+
This modes test if the cloud resources needed by Defender for Endpoint is reachable or not.
349351
350352
```console
353+
351354
-h, --help show this help message and exit
352355
-o ONBOARDING_SCRIPT, --onboarding-script ONBOARDING_SCRIPT
353356
Path to onboarding script
354357
-g GEO, --geo GEO Geo string to test <US|UK|EU|AU|CH|IN>
358+
355359
```
360+
356361
Usage example: `sudo ./MDESupportTool connectivitytest -o ~/MicrosoftDefenderATPOnboardingLinuxServer.py`
357362
358363
The result will be printed in the screen.
359364
360365
361366
#### Collect different installation/onboarding reports
367+
362368
This mode collects installation related info like disto info, system requirements, etc.
363369
364370
```console
371+
365372
-h, --help show this help message and exit
366373
-d, --distro Check for distro support
367374
-a, --all Run all checks
375+
368376
```
369377
370378
Usage example: `sudo ./MDESupportTool installation --all`
371379
372-
A single report `installation_report.json` will be generated. The keys in the file are as:
380+
A single report `installation_report.json` is generated. The keys in the file are as:
381+
373382
| Key | Remarks |
374383
| ------------- | ------------- |
375-
| agent_version | Version of MDE installed |
384+
| agent_version | Version of Defender for Endpoint installed |
376385
| onboarding_status | The onboarding and ring info |
377386
378-
379387
#### Use OS trace (for macOS only)
380388
381389
Use OS tracing facilities to record Defender for Endpoint performance traces.
@@ -384,9 +392,11 @@ Use OS tracing facilities to record Defender for Endpoint performance traces.
384392
> This functionality exists in the Python solution only.
385393
386394
```console
395+
387396
-h, --help show this help message and exit
388397
--length LENGTH Length of time to record the trace (in seconds).
389398
--mask MASK Mask to select with event to trace. Defaults to all
399+
390400
```
391401
392402
On running this command for the first time, it installs a Profile configuration.
@@ -403,6 +413,7 @@ Add exclusions for audit-d monitoring.
403413
> This functionality exists for Linux only.
404414
405415
```console
416+
406417
-h, --help show this help message and exit
407418
-e <executable>, --exe <executable>
408419
exclude by executable name, i.e: bash
@@ -420,6 +431,7 @@ Add exclusions for audit-d monitoring.
420431
-o, --override Override the existing auditd exclusion rules file for mdatp
421432
-c <syscall number>, --syscall <syscall number>
422433
exclude all process of the given syscall
434+
423435
```
424436
425437
Usage example: `sudo ./MDESupportTool exclude -d /var/foo/bar`
@@ -432,8 +444,10 @@ Syntax that can be used to limit the number of events being reported by the audi
432444
> This functionality exists for Linux only.
433445
434446
```console
447+
435448
-h, --help show this help message and exit
436449
-e <true/false>, --enable <true/false> enable/disable the rate limit with default values
450+
437451
```
438452
439453
Usage example: `sudo ./mde_support_tool.sh ratelimit -e true`
@@ -449,8 +463,10 @@ This option enables you to skip the faulty rules added in the auditd rules file
449463
> This functionality is only available on Linux.
450464
451465
```console
466+
452467
-h, --help show this help message and exit
453468
-e <true/false>, --enable <true/false> enable/disable the option to skip the faulty rules. In case no argumanet is passed, the option will be true by default.
469+
454470
```
455471
456472
Usage example: `sudo ./mde_support_tool.sh skipfaultyrules -e true`

0 commit comments

Comments
 (0)