Cytool for Mac ↗
Cytool is a command-line interface that is integrated into the Cortex XDR agent that enables you to query and manage both basic and advanced functions of the agent. Unless stated otherwise, changes you make using Cytool take effect when the agent receives the next heartbeat communication (every five minutes) from Cortex XDR.
On Mac endpoints, access Cytool as a super user using a terminal. Cytool is located in the /Library/Application Support/PaloAltoNetworks/Traps/bin directory on the endpoint.
The following table displays the Cytool options available on Mac endpoints. For the Cytool admin commands that require a password, the password is the same as is defined as the Uninstall password.
Note
Since Cortex XDR agent 7.6, the pmd process includes and replaces the trapsd process.
| Command Option | Description |
| cert_enforcement | Perform Certificate enforcement related operations. Usage: Where <operation> is one of the following:
|
| checkin | Initiate check-in to the server. Usage: To verify the checkin, view the check-in time on the Cortex XDR agent console. |
| connectivity_test | Perform a connectivity test to Cortex XDR servers. Usage: |
| dump | Enable or disable dump generation or restore policy settings. Traps-Mac:bin Traps$ sudo ./cytool dump enable Traps-Mac:bin Traps$ sudo ./cytool dump disable Traps-Mac:bin Traps$ sudo ./cytool dump restore |
| endpoint_tags | Use Endpoint Tags to identify groups of endpoints. Usage: where
Note Tags should be passed as one string separated by comas. For example:
|
| enum | Enumerate protected processes. Usage: For example: Traps-Mac:bin Traps$ sudo ./cytool enum
List of protected processes:
Process name Process ID User
Photos 2047 User1
Mail 2099 User2
Note If you change the action mode for protected processes in the Exploit Security Profile in Cortex XDR, you must restart the protected processes for the security policy to be enforced on the processes and its forked processes, and only then you will see them on this list. |
| -h --help | Traps-Mac:bin Traps$ sudo ./cytool Usage: cytool<options> cytool - Support tool Options: -h --help Display help information. enum List processes protected by Cortex XDR. startup query List startup status for Cortex XDR agent and daemons. startup <enable | disable> <process_name | all> Enable/Disable Cortex XDR agent and daemons after reboot. runtime query List runtime status for agent, daemons, and kernel extensions. runtime <start | stop> <process_name | all> Start/Stop Cortex XDR agent, daemons, and kernel extensions immediately. persist list Display persistent databases. persist export <db_name | db_path> Export databases in JSON format. persist import <db_name | db_path> <file_name> Import data into the database from the given JSON file. persist print <db_name | db_path> [csv] Print database to the command prompt. log <log_level> <process_name | all> Set log level for the desired process. log collect Generate support file archive. wakeup Wake up from OS incompatibility state. dump <enable | disable | restore> Enable/Disable dump generation or restore policy settings. checkin Update Cortex XDR from server. opswat <installed | running | protected | version> Check Cortex XDR Agent status and version. |
| import suex | Import pre-downloaded content or local support exceptions. Used for solving specific problems with a support representative. |
| isolate | Usage: Release endpoint from network isolation. |
| log |
Usage: where:
For example: Traps-Mac:bin Traps$ sudo ./cytool log set_level 2 all
Use the |
| opswat | Check the Cortex XDR agent status and version. Usage: where <parameter> is:
Traps-Mac:bin Traps$ sudo ./cytool opswat version 8.1.0.1042 Traps-Mac:bin Traps$ sudo ./cytool opswat installed Password: true Traps-Mac:bin Traps$ sudo ./cytool opswat running true Traps-Mac:bin Traps$ sudo ./cytool opswat protected true |
| persist | The Cortex XDR agent stores policy and security event information such as the list of trusted signers, local verdicts, and one-time actions in local databases on the endpoint. To troubleshoot policy issues and security events, you can use cytool persist operations to import, export, and view information stored in the local database. Usage: where <action>:
To view a list of all local databases, use the |
| queryall | The cytool queryall command displays a list of imported certificates, for troubleshooting purposes. |
| reconnect | Try reconnecting to the server if communication has been disabled, or force registration with a new Usage:
Note The |
| runtime | Stop or start product components. Usage: where:
For example: Traps-Mac:bin Traps$ sudo ./cytool runtime query
Name PID User Status Command
cortex xdr 1055 User1 Running /Library/Application Support/PaloAltoNetworks/Traps/bin/cortex xdr.app/Contents/MacOS/cortex xdr
authorized 927 _traps_panw Running /Library/Application Support/PaloAltoNetworks/Traps/bin/authorized
pmd 909 root Running /Library/Application Support/PaloAltoNetworks/Traps/bin/pmd
kproc-ctrl 159 root Loaded com.paloaltonetworks.driver.kproc-ctrl
Traps-Mac:bin Traps$ sudo ./cytool runtime stop all
Name PID User Status Command
authorized N/A N/A STOPPED N/A
pmd N/A N/A STOPPED N/A
cortex xdr N/A N/A STOPPED N/A
kproc-ctrl N/A N/A Unloaded N/A
Traps-Mac:bin Traps$ sudo ./cytool runtime start all
Name PID User Status Command
system call failed for command='/usr/bin/su -l Traps -c "/bin/launchctl start cortex xdr.plist"', returned status code=768
authorized 1883 _traps_panw Running /Library/Application Support/PaloAltoNetworks/Traps/bin/authorized
pmd 1889 root Running /Library/Application Support/PaloAltoNetworks/Traps/bin/pmd
cortex xdr N/A N/A FAILED TO START N/A
kproc-ctrl 160 root Loaded com.paloaltonetworks.driver.kproc-ctrl
|
| security_modules | Query, enable, disable or return to policy the Cortex XDR agent anti-tampering protection. Usage: Where:
Example: To disable the Cortex XDR agent anti-tampering protection:
|
| startup | Enable, disable, or query the startup state of Cortex XDR agent components. Usage: where:
For example: Traps-Mac:bin Traps$ sudo ./cytool startup disable cortex xdr pmd
Process name Startup status
cortex xdr Disabled
authorized Enabled
pmd Disabled
kproc-ctrl Loaded
Traps-Mac:bin Traps$ sudo ./cytool startup enable all
Process name Startup status
cortex xdr Enabled
authorized Enabled
pmd Enabled
kproc-ctrl Loaded
|
| wakeup | Wake up the endpoint from an OS incompatibility state.
|