Serious Discussion Free xdr by airiam.

I registered for the free version and it looks like an XDR client. It doesn't come with the features a paid EDR client like Checkpoint Harnony has in its dashboard.

Setup and uninstall of the client is a breeze.
 
It's based on Wazuh for the agent and it seem to use Trend Micro for threat detection. However, installation was painful and unsuccessful:

The installer ended prematurely when installing the agent, and I had to run the installer again to get it to work, and once it was installed, the Wazuh "Manage Agent" shortcut just gives me a error, requiring me to go into the Wazuh folder and launch the agent manually, which also fixes the Manage Agent shortcut. And once the Wazuh agent is finally on screen I can't get it to work, since you are not given a authentication key, and the client.keys file is empty and the API key doesn't seem to be what youre supposed to paste in as I just get a "Unable to important authentication key".

It honestly feels like something that's still in development, as many features like GDPR in Compliance is "Coming Soon", and going into the MITRE ATT&CK tab in Threats causes the entire dashboard to go black, forcing you to close the tab and go back into the dashboard.
 
Last edited by a moderator:
It's a buggy mess for me. The installer ended prematurely and I always have to run the installer twice to get it to work, and once it is installed, the "Manage Agent" executable just throws up a error, requiring me to go into the Wazuh folder to actually launch the agent and get the Manage Agent shortcut to work, and once the Wazuh agent is on screen the API key doesn't even work since it never creates a client key and the API key doesn't work.
This sounds like too much drama just to use a free XDR (with a dashboard designed to be less than useful).
 
  • Like
Reactions: [correlate]
oh yeah airiam dont work for me its not showing up in agents :/ anyone else have the same issue or does it take a while
 
  • Thanks
Reactions: kylprq