SecureWorks to Snare Enterprise agent migration

Due to the announcement that the SecureWorks agent is now EOL, many customers are now migrating to the Snare Enterprise agent. A feature comparison of the 2 agents can be found below:

When migrating, there are a number of options and tools that can help streamline this process and ensure simple transition for customers. When migrating between agents, there are 2 things to consider:

  • the licensing function within the Enterprise agent.

  • the difference in default auditing policies between the SecureWorks agent and Enterprise agent.

 

There are 2 methods of licensing in the new Enterprise agents:

Standalone licensing. This method requires the unique KeyIDs associated with an individual agent be uploaded to a license in the portal. From here a new license will be generated which can be downloaded and applied to the agent via its web UI. Sales/Support will need to prepare licenses to be used in this way so please discuss with your sales person/presales consultant on how you will need to use the software.

Snare Agent Manager (SAM) licensing. The SAM is a free tool available in base form on windows platform or is part of the Snare Central product (separately licensed) to customers to streamline licensing management in larger deployments. Licenses can be added added to the SAM and automatically assigned to agents who have the necessary configuration. The SAM also can provide other useful capabilities such as remote upgrading of Windows agents to later versions (requires an additional license for Agent Management) and license utilisation overviews, more information can be found here Overview - Snare Agent Manager Documentation - Confluence (atlassian.net).

 

The differences in the default policies applied by the SecureWorks and Snare Enterprise agent are highlighted below:

SecureWorks default policies. Collects all Application & System logs, as well as Active Directory Service, Domain Name Server, DFS-Replication, Legacy FRS and all Security events except event IDs 4627,5156 and “Filtering platform events” that are generated by the snare process.

Snare Enterprise agent default policies. Collects all Application, System & Custom logs, as well as Active Directory Service, Domain Name Server, DFS-Replication and high level Security events from Logon_Logoff, Process_Events, User_Group_Management_Events, Reboot_Events, Security_Policy_Events, User_Right_Events & Other_Object_Access_Events.

When choosing a migration method, ensure you select the correct method for the policies you want to inherit.

 

The below list details the various migration methods (with links to each guide) and when they should be used: