Skip to main content

Windows Sensor Processes and Paths

Here is the complete list of Windows Sensor processes and paths that you should exclude from your EDR tools and other security applications.

Sensor Processes

Process NameDescription
Cyberhaven.exeService that manages all other Cyberhaven processes below
CyberhavenBackendConnector.exeTransfers data to the Cyberhaven backend on behalf of all other processes
CyberhavenSystemMonitor.exeMonitors file system and application file access
CyberhavenHealthMonitor.exeActs as watchdog for other Cyberhaven processes & sends telemetry to backend
CyberhavenNativeProxy.exeBridge process connecting to the browser extension
CyberhavenSessionMonitor.exeUser session monitoring processes
CyberhavenAutoUpdater.exeSensor self-upgrade process
CyberhavenDis32.exePrevention driver (32-bit)
CyberhavenDis64.exePrevention driver (64-bit)
CyberhavenApiMonitorInjector32.exeProcess hooking support (32-bit version)
CyberhavenApiMonitorInjector64.exeProcess hooking support (64-bit version)
CyberhavenDumpstk.exeTool used for inspecting system crashes
CyberhavenPwdHash.exeTool used to generate a password hash for the uninstall password protection
CyberhavenHealthChecker.exeTool for manually running health checks
CyberhavenUpdaterService.exeAuto Update helper service. Runs from C:\Windows\Temp.
CyberhavenNetworkRedirector.exeThis process redirects HTTPS traffic to Cyberhaven when coverage for certain apps is enabled, like Microsoft Teams.
CyberhavenNetworkInspector.exeThis process inspects the redirected HTTPS traffic for sensitive information and applies policies accordingly when coverage for certain apps is enabled, like Microsoft Teams.
CyberhavenContentScanner.exePerforms Data at Rest scanning on the endpoint device, when the feature is enabled.

Sensor Paths

A Windows device that is running Cyberhaven will have application and configuration data stored in the following paths.

Directory
%PROGRAMFILES%\Cyberhaven
%PROGRAMFILES%\CyberhavenAutoUpdater
%PROGRAMDATA%\Cyberhaven
%PROGRAMFILES(x86)%\Cyberhaven
C:\WINDOWS\SYSTEM32\drivers\Cyberhaven