Red Canary supports several Linux distributions. In terms of distribution version support, the Linux Endpoint Detection and Response (EDR) sensor will work with Linux versions that are still supported by their upstream vendor, including Long Term Support versions. The Linux EDR sensor is not supported on upstream vendor-designated "end-of-life" versions.
Supported Linux distributions
|Google Container-Optimized OS||Fedora|
|Oracle Linux (RHEL & UEK kernels)||
Don’t see your distribution on this list? Contact us!
Supported Linux kernel versions
The following kernel versions are required to collect telemetry using Audit:
- 3.2 and above (mainline)
3.10 and above (mainline) for the file modification telemetry to be collected
Supported Linux kernel versions for eBPF
The following kernel versions are required to collect telemetry using eBPF:
- For x86_64 machines 4.14 and above (mainline)
- For AArch64 machines: 5.8 and above (mainline)
- In some distributions, including CentOS and RHEL, backports for eBPF support exist on earlier kernels. RHEL supports eBPF in kernels 3.10.0-940 and above.