G DATA MXDR

Migration guide from G DATA Essentials to G DATA MXDR

To ensure a smooth transition from G DATA 365 Essentials to our new product G DATA MXDR for customers with service level G5, we provide you with a guide here. Using this guide, you can carry out the migration of the client software even without our support.

Definition of terms Prevent - Detect - Respond in the context of MXDR configuration options

The following is an optional definition of terms for various configuration options when setting up G DATA MXDR in the context of Prevent - Detect - Respond.

  • Prevent → Minimize vulnerabilities and prevent incidents.

  • Stop malware → By default, malware is stopped and, if possible, moved to quarantine. If this function is disabled on a system, malware will continue to be logged and analyzed by our analysts.

  • Learning mode (applies to service level G7 and G5 over 50 seats) → "Stop malware" is disabled during the first two weeks. Potential false positives can be resolved during this period without negatively impacting production.

  • Risk: A previously known piece of malware or riskware can be executed on the system and thereby used for data exfiltration, abuse of access rights, or privilege escalation.

Example of a classic antivirus solution: The software detects known malware and automatically moves it to quarantine.

  • Detect → Make incidents visible using sensors and detection patterns.

  • Exclusions → Certain applications or folders are no longer monitored.

  • Risk: In the event of a vulnerability, software can be exploited, or a folder can be used to execute or distribute malicious content. Execution of the malicious content is then not prevented and, in addition, is not detected.

Example: Our sensors detect not only malware, but also attacker behavior. Exclusions for entire drives therefore provide a large attack surface because they cannot be seen by the Agent.

  • Respond → Respond to incidents and limit damage.

  • Response by analysts → On systems where remote analysis & response is disabled, no response actions such as network isolation or data collection may take place. Response by analysts is enabled by default (24/7).

  • Risk: At the relevant time, no decision can be made by G DATA, and therefore an incident cannot be stopped / contained at the time it is detected. In such a case, G DATA sends a response recommendation to the Customer, which can then only be implemented with a time delay.

Example: With permitted access for our analysts, they can respond to an incident even at three o’clock on Sunday night without contacting you in advance and asking for approval or assistance.

Uninstalling the existing G DATA Security Clients

To install the Agents for G DATA MXDR, you must first uninstall the old G DATA Security Clients. It is important that the respective system is restarted after uninstallation.

After uninstalling the clients and before installing the new software, the system must be restarted!

Installing the G DATA Agent

After restarting the system, the Agents for G DATA MXDR can now be installed.

The Agent is installed on Windows endpoints for single installations either via GUI or via the command line. At larger scale, the Agent can be deployed via script, for example via a Group Policy. Starting at service level G7, our G DATA Security Operations Team can support you if required.

You can obtain a setup file as well as the required Setup ID in the G DATA Web-Portal in the "New endpoint installation" view.
If you want to install the G DATA Agent on an ARM architecture, Windows 11 is mandatory!

Important information on using templates.

The G DATA Agent must not be installed on system images/templates that are then used for cloning on other systems. The installation of the G DATA Agent must always be performed after a cloning process to ensure unique identification of Incidents.

If you have installed the G DATA Security Client, uninstall it first and restart the system before installing the G DATA Agent.

Installing the .msi file

If you prefer a graphical user interface during installation, either double-click the .msi file or do not use the "/exenoui" or "/qn" parameters when calling msiexec.exe.
Then follow the instructions in the GUI.

1

Download the desired installation file in the "New endpoint installation" view.

2

Open Command Prompt with administrative privileges.

3

Change to the directory where the setup file is located.

4

You have two options to start the installation command: directly via the .msi installation file or via the msiexec.exe.

Call via msiexec.exe:

msiexec.exe /i "gdata_agent_setup.msi" SETUPID="guid" /qn

Call with the .msi installation file:

gdata_agent_setup.msi /q SETUPID="guid"

In both cases, replace "guid" with your Setup ID.

The commands presented are rudimentary and install without any additional configuration. You can read about all configuration parameters, such as proxy settings, in this article.

5

Confirm the input; the Agent will now be installed on the system. Restart the computer to complete the installation.

Installing with the .exe file

The installation described below is deprecated (obsolete). We recommend selecting the method described above.
GUI installation

1

Download the desired installation file in the "New endpoint installation" view.

2

Open the installation file and select the desired language.

Language selection

3

Select Installation.

Select installation

4

Select a destination folder for the installation.

Select folder

5

Enter the Setup ID that you received from G DATA. It is available in the G DATA Web-Portal in the "New endpoint installation" view.

Enter Setup ID

6

After you enter the Setup ID, the Agent is installed on the system. You can still configure the G DATA Agent, for example to set proxy settings. How to do this is explained here. Restart the computer to complete the installation.

Command-line installation

1

Download the desired installation file in the "New endpoint installation" view.

2

Open Command Prompt with administrative privileges.

3

Change to the directory where the setup file is located.

4

Start the setup with the following command:

[NameDerSetupDatei].exe /i /s /id=????????-????-????-????????????

Replace ????????-????-????-???????????? with your Setup ID. It is available in the G DATA Web-Portal in the "New endpoint installation" view.

5

Confirm the input; the Agent will now be installed on the system. You can still configure the G DATA Agent, for example to set proxy settings. How to do this is explained here. Restart the computer to complete the installation.

Documentation

Online documentation for G DATA MXDR is available at Dokumentationsportal. There you will find the documentation for the elements of G DATA Web-Portal as well as for the administrative level.

The documentation covers all aspects of G DATA MXDR. If some of the documented elements and features are not available in your environment, this is probably due to the specific configuration of your version. If you are interested in additional modules such as integration of G DATA Mobile Device Management or other features, please feel free to contact us.