Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below and we will reply as soon as possible.

  • Create a Support Ticket
  • Partner Portal
  • CYRISMA MSP Dashboard
  • Home
  • General Questions and Troubleshooting

Why Does Endpoint Protection Like ThreatLocker Block the CYRISMA Agent Installation?

When attempting to install the CYRISMA Agent using a PowerShell script, endpoint protection software, such as ThreatLocker, may block the installation. This is often due to security policies or restrictions configured on the endpoint protection software that prevent the downloading or execution of certain files.

Written by Liam Downward

Updated at December 26th, 2024

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below and we will reply as soon as possible.

  • User Manual
    Overall Risk Dashboard Agent Status Report Builder Data Scan Vulnerability Scan Secure Baseline Compliance Mitigation Dark Web MSP Interface Instance Admin
  • Self Onboarding Guide
  • Agents
  • The Cyber Risk Assessment Process
  • PSA Integrations
  • General Questions and Troubleshooting
    Agent Troubleshooting Scanning Troubleshooting
  • The Cyber Risk Assessment Process (Video Tutorials)
  • Sales and Prospecting Articles
  • CYRISMA Partner Portal Access
  • Glossary
  • API Documents
  • CYRISMA Change Log
  • Support Ticket SLA
  • Billing Questions
+ More

Table of Contents

Symptoms Why This Happens How to Troubleshoot Recommended Fix Preventing Future Issues Conclusion

Symptoms

  • The PowerShell script fails with the error:
    "The underlying connection was closed: An unexpected error occurred on a send."
  • The script is unable to download the CYRISMA Agent from the URL (e.g., https://dl.cyrisma.com/...).
  • The download works successfully when accessing the URL directly via a browser.
  • Endpoint protection logs (e.g., ThreatLocker) show the script or executable being blocked.

Why This Happens

Endpoint protection software like ThreatLocker may block PowerShell scripts or downloads due to:

  1. Security Policies: Configurations that flag downloads initiated by PowerShell as potentially unsafe.
  2. Application Control: Restricting unapproved or unknown executables (e.g., Cyrisma_Setup.exe).
  3. Script Restrictions: Monitoring or blocking script-based operations to reduce the risk of malicious activity.
  4. Network Restrictions: Network filtering rules applied by endpoint protection to control how and when files are downloaded.

How to Troubleshoot

Verify Endpoint Protection Logs:

  • Check ThreatLocker or other endpoint protection logs for blocked actions related to PowerShell or the CYRISMA download URL.

Test Download in a Browser:

  • Open the URL (e.g., https://dl.cyrisma.com/...) in a browser.
  • If the file downloads successfully, the issue is likely with the endpoint protection blocking PowerShell-specific operations.

Temporarily Disable Endpoint Protection (If Permitted):

  • Disable ThreatLocker or similar software temporarily to verify whether it is the cause of the block.
  • Re-run the PowerShell script to confirm.

Add Exceptions in Endpoint Protection:

  • Allow the PowerShell process and the https://dl.cyrisma.com domain in ThreatLocker or similar tools.
  • Add the CYRISMA Agent executable (e.g., Cyrisma_Setup.exe) as an approved application.

Confirm Permissions:

  • Ensure the script is running with sufficient permissions (e.g., as Administrator) and that the machine has internet access.

Recommended Fix

To allow the PowerShell script to function correctly, follow these steps for ThreatLocker:

Add the Download URL to Allowed List:

  • Open ThreatLocker settings.
  • Navigate to the policy or rule section for downloads.
  • Add https://dl.cyrisma.com to the list of allowed domains.

Allow PowerShell Scripts:

  • Approve the PowerShell process (powershell.exe) in ThreatLocker policies.
  • Allow scripts specifically from trusted sources like CYRISMA.

Approve the CYRISMA Setup File:

  • Add Cyrisma_Setup.exe as an approved application in ThreatLocker.

Re-run the Script:

  • After applying the changes, re-run the PowerShell script to complete the installation.

Preventing Future Issues

  • Document Exceptions: Maintain a list of required exceptions (e.g., URLs, processes, executables) within your endpoint protection software to streamline future deployments.
  • Test in a Controlled Environment: Before large-scale deployment, test the installation process in an environment with endpoint protection enabled to identify potential blocks.
  • Stay Updated: Ensure your endpoint protection policies and configurations are aligned with trusted tools like CYRISMA to avoid unnecessary restrictions.

Conclusion

Endpoint protection software like ThreatLocker can block the CYRISMA Agent installation due to restrictive policies. By identifying and addressing these restrictions, the installation can proceed successfully. If the issue persists, contact CYRISMA Support for further assistance.

endpoint security blockage threatlocker powershell install script endpoint protection

Was this article helpful?

Yes
No
Give feedback about this article

Related Articles

  • Troubleshooting Agent Installation Problems
  • Why Can't I Provision Agents?
  • Troubleshooting CYRISMA Agent Provisioning Failures: Checking the "Server" Service

Partners
pax8
CDW
Stellar Cyber
RedSky Alliance

Request A Demo
Platform
  • Platform Overview
  • Resellers
  • Managed Service Providers
  • Request A Demo
  • Platform Overview
  • Resellers
  • Managed Service Providers
  • Request A Demo
Resources
  • Case Studies
  • White Papers
  • Videos
  • Blog
  • Press Release
  • Events
  • Case Studies
  • White Papers
  • Videos
  • Blog
  • Press Release
  • Events
Contact Us
Address: 510 Clinton Square, Rochester, New York, USA, 14604

Email: info@cyrisma.com

Phone: 1-585-620-2496

Easiest To Do Business With Summer 2023
Category Leader Channel Program
Capterra
Software Advice

Terms of Use          Privacy Policy

Copyright © 2024 – Data Spotlite, Inc All rights reserved.
Expand