All Products
Search
Document Center

Security Center:Processes of the Security Center agent

Last Updated:Sep 08, 2026

After you install the Security Center agent, it starts processes such as AliYunDun and AliYunDunMonitor on your server to collect system information and detect threats. You can check the process status to determine whether security protection is active. This topic provides a detailed description of the files and processes of the Security Center agent.

Agent architecture

The Security Center agent uses a modular architecture that consists of core resident processes and functional processes to ensure the stable operation of basic features and the efficient scheduling of advanced features.

  • Resident processes: AliYunDun, AliYunDunMonitor, and AliYunDunUpdate communicate with the Security Center server, maintain heartbeats, report basic security data, and perform self-updates to provide the basic running capabilities for the agent.

  • Functional processes (non-resident processes): AliHips and AliNet are downloaded and started on demand only after you enable the corresponding advanced defense features in the console, such as malicious host behavior prevention and web tamper proofing.

Process details

Important
  • To prevent agent function exceptions, do not manually terminate or delete the related processes and files.

  • To delete agent-related files, see Client configuration to disable agent self-protection.

Core processes

Core processes ensure communication between the agent and the cloud and the normal operation of basic monitoring capabilities. They start automatically after the agent is installed.

Note

Starting from aegis_12_3x, the AliSecureCheckAdvanced and AliDetect processes are merged into AliSecCheck. Earlier versions are not affected.

Process name

Folder

Description

AliYunDun

aegis_client

Communicates with the Security Center server, reports heartbeats, receives instructions, reports data, and enforces agent self-protection.

AliYunDunMonitor

aegis_client

Monitors host security, including the collection and detection of information such as assets, processes, ports, and accounts.

AliYunDunUpdate

aegis_update

Automatically updates the agent version and rule libraries.

AliSecCheck

  • AliSecCheck

  • AliSecCheckTmp

  • AliSecCheck (Detect plug-in)

Runs security scan and detection tasks, including vulnerability scans, compliance baseline checks, and runtime detection of malicious programs such as mining programs and trojans

Functional processes

Functional processes are tied to specific paid features and start only after you enable the corresponding feature.

Process name

Folder

Description

Start condition

AliNet

AliNet

Provides network-layer protection to block network behaviors such as malicious IP access and outbound attacks.

Enable Malicious Network Behavior Prevention.

AliHips

AliHips

Provides host intrusion prevention to block malicious host behaviors, prevent ransomware, and defend against web shell connections.

Enable any one of Malicious Host Behavior Prevention, Anti-Ransomware (Bait Capture), Webshell Connection Prevention.

AliWebGuard

AliWebGuard

Performs web tamper proofing and core file monitoring.

Enable Web Tamper Proofing or Core File Monitoring.

ids

hbrclient

Runs tasks such as security reports, anomaly detection, and real-time monitoring.

Enable Anti-ransomware for Servers.

hbrclient

hbrclient

Runs tasks such as data backup, data restoration, fault monitoring, and task scheduling.

dbackup3-agent

dbackup3-agent

Database backup proxy process that runs tasks such as initial database backup, incremental backup, database backup restoration, scheduling and management, and logging and monitoring.

Enable Anti-ransomware for Databases.

Relationship between processes and features

Feature name

Related process

Edition/protection level limits

Documentation

Self-Protection Status

AliYunDun

None

Client configuration

Malicious Network Behavior Prevention

AliNet

  • Editions (subscription): Advanced, Enterprise, Ultimate.

  • Protection levels (pay-as-you-go): Comprehensive Host Protection or Full Protection for Hosts and Containers.

Host protection settings

Malicious Host Behavior Prevention

AliHips

  • Editions (subscription): Anti-virus, Advanced, Enterprise, Ultimate.

  • Protection levels (pay-as-you-go): Antivirus, Comprehensive Host Protection, Full Protection for Hosts and Containers.

Anti-Ransomware (Bait Capture)

AliHips

  • Editions (subscription): Anti-virus, Advanced, Enterprise, Ultimate.

  • Protection levels (pay-as-you-go): Antivirus, Comprehensive Host Protection, Full Protection for Hosts and Containers

Webshell Connection Prevention

AliHips

  • Editions (subscription): Enterprise, Ultimate.

  • Protection levels (pay-as-you-go): Comprehensive Host Protection, Full Protection for Hosts and Containers.

Web Tamper Proofing

AliWebGuard

None

Important

This feature is a value-added service that must be purchased separately.

File tamper-proofing

File Tamper Proofing

AliWebGuard

  • Editions (subscription): Enterprise, Ultimate.

  • Protection levels (pay-as-you-go): Comprehensive Host Protection, Full Protection for Hosts and Containers.

Use the core file monitoring feature

Anti-ransomware for Servers

  • hbrclient

  • ids

None

Important

This feature is a value-added service (Managed Anti-ransomware) that must be purchased separately.

Anti-ransomware for Servers

Anti-ransomware for Databases

dbackup3-agent

None

Important

This feature is a value-added service (Managed Anti-ransomware) that must be purchased separately.

Anti-ransomware for Databases

Relationship between processes and agent status

Security Center evaluates the online status of the agent by monitoring the communication between the AliYunDun process and the server. The agent status changes from Online to Offline when either of the following situations occurs.

Note

You can view the agent status of your servers on the Host page: Offline (未防护图标.png), Online (已防护图标.png).

  • The server detects that the communication with the agent is interrupted, for example, due to network exceptions, the AliYunDun process being terminated, or the agent being uninstalled.

  • The server has not received any information reported by the agent, such as heartbeats or security data, within 10 hours.

Running permissions and file paths

Process permissions

To provide comprehensive security monitoring and protection, the agent processes must run with high privileges in the operating system. The high privileges are used to perform low-level operations such as kernel-level monitoring, file system protection, network behavior analysis, and process self-protection.

  • On Linux, processes run as the root account.

  • On Windows, processes run as the SYSTEM account.

Default process file paths

  • Windows:

    • 32-bit: C:\Program Files\Alibaba\aegis.

    • 64-bit: C:\Program Files (x86)\Alibaba\aegis.

  • Linux: /usr/local/aegis.

How to check process status

You can use the following commands to quickly check whether the agent processes and services are running properly. The following examples use the core processes.

Linux

Commands to check processes:

# Check that AliYunDun, AliYunDunMonitor, and AliYunDunUpdate are all running.
ps -ef | grep -E 'AliYunDun|YunDunMonitor|YunDunUpdate'
# Check the service status. The output should show "active (running)".
systemctl status aegis

Sample output in normal state:

root        5472       1  0 Sep10 ?        00:00:18 /usr/local/aegis/aegis_update/AliYunDunUpdate
root        5524       1  0 Sep10 ?        00:01:34 /usr/local/aegis/aegis_client/aegis_12_61/AliYunDun
root        5546       1  0 Sep10 ?        00:03:13 /usr/local/aegis/aegis_client/aegis_12_61/AliYunDunMonitor
● aegis.service - LSB: Aegis service
   Loaded: loaded (/etc/rc.d/init.d/aegis; generated)
   Active: active (running) since Mon 2023-10-30 10:00:00 CST; 1 day 2h ago

Windows

  • Method 1: Check the processes in Task Manager. Open Windows Task Manager and go to the Processes tab. Confirm that the following Aegis-related processes are running normally: Alibaba Security Aegis Detect Service, Alibaba Security Aegis Update Service, Alibaba Security Monitor Detect Service, AliDetect.exe, AliWebGuard.exe. The CPU usage of each process should be close to 0%, and the memory usage should range from several MB to tens of MB.

  • Method 2: Run the following commands in PowerShell

    Commands to check processes:

    # Check that the three core processes are running.
    Get-Process | Where-Object {$_.Name -match '^(AliYunDun|AliYunDunMonitor|AliYunDunUpdate)$'}
    # Check the service status. The Status column should show "Running".
    Get-Service | Where-Object {$_.Name -match 'Aegis|AliYunDun'}
    

    Sample output in normal state:

    Handles  NPM(K)    PM(K)      WS(K)     CPU(s)     Id  SI ProcessName
    -------  ------    -----      -----     ------     --  -- -----------
        380      26    15948      19656     615.75   6072   0 AliYunDun
        599      31    47576      37356     968.73   2488   0 AliYunDunMonitor
        257      14     8072      11336     232.03   2904   0 AliYunDunUpdate
    Status   Name               DisplayName
    ------   ----               -----------
    Running  Alibaba Securit... Alibaba Security Aegis Detect Service
    Running  Alibaba Securit... Alibaba Security Aegis Update Service