Views:
User mode provides event generation and basic functions for Activity Monitoring and Anti-Malware without any driver requirements. This solution allows some protection for systems that lack the driver support required to run in kernel mode and provides the auto option to automatically enable the best protection available at any given time.
For details on basic functions, see Activity Monitoring events and Anti-Malware events.

Available modes

  • Kernel mode: Generates events and provides full Activity Monitoring and Anti-Malware functionality, but can only be enabled on systems with the required driver support.
  • User mode: Generates events and enables basic functions for Anti-Malware & Activity Monitoring without any driver requirements.
    Note
    Note
    User mode can be enabled to run on a system without using drivers, even if the system supports the drivers required to run in kernel mode.
  • Auto: Switches between kernel mode and user mode to provide the best protection available at any given time. Kernel mode is prioritized, but Server & Workload Protection will switch to user mode automatically during any driver support gaps that prevent kernel mode operation. If a system that lacks the required drivers to run in kernel mode later obtains them (from a system update, for example), then the agent automatically switches to use kernel mode and give the system full protection from Activity Monitoring and Anti-Malware.

Choose whether to use drivers for system protection

To configure the driver mode from Server & Workload Protection:
  1. From the Policies page, select a policy and then click Details.
  2. In the window that appears, click Settings.
  3. Under Choose whether to use drivers for system protection, select Auto, Kernel Mode, or User Mode from the drop-down menu.

Supported agents

Operating systems that support Anti-Malware and Activity Monitoring in user mode:
  • Amazon Linux 2 (64-bit)
  • Amazon Linux 2023 (64-bit)
  • Debian 10 (64-bit)
  • Debian 11 (64-bit)
  • Debian 12 (64-bit)
  • Oracle Linux 8 (64-bit)
  • Oracle Linux 9 (64-bit)
  • Red Hat Enterprise Linux 9 (64-bit)
  • SUSE Linux Enterprise Server 15 (64-bit)
  • Ubuntu 20.04 (64-bit)
  • Ubuntu 22.04 (64-bit)