## Summary - Adds a new FAQ entry to `docs/Get started/FAQ.md` explaining that EDR products (e.g., SentinelOne, CrowdStrike) may occasionally flag the fleetd agent (orbit) after updates - Describes the osquery v5.23.0 change that performs temporary keychain file copies to prevent corruption when querying the `certificates` table, which can trigger EDR heuristic alerts - Notes that Fleet is working with EDR vendors to resolve false-positive classifications and advises customers can safely allowlist the orbit binary --- Built for [Mike McNeil](https://fleetdm.slack.com/archives/C062D0THVV1/p1778015225672909?thread_ts=1778005844.853449&cid=C062D0THVV1) by [Kilo for Slack](https://kilo.ai/slack) --------- Co-authored-by: kiloconnect[bot] <240665456+kiloconnect[bot]@users.noreply.github.com> Co-authored-by: Rachael Shaw <r@rachael.wtf>
Fleet documentation
Welcome to the documentation for Fleet, the lightweight management platform for laptops and servers.
You can also read the Fleet docs over at https://fleetdm.com/docs.
Using Fleet
Resources for using the Fleet UI, fleetctl CLI, and Fleet REST API.
Deploying
Resources for installing Fleet's infrastructure dependencies, configuring Fleet, deploying osquery to hosts, and viewing example deployment scenarios.
Contributing
If you're interested in interacting with the Fleet source code, you'll find information on modifying and building the code here.
If you have any questions, please don't hesitate to File a GitHub issue or join us on Slack. You can find us in the #fleet channel.