Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Data exfiltration, also known as data theft, data exportation, or data extrusion, is the unauthorized transfer of data from a device or network. It can occur as part of an automated attack or can be performed manually. The illegitimate transfer of data often looks very similar to legitimate transfers, making it difficult to detect.
Data exfiltration can occur in various ways and through multiple attack methods. Here are some of the most commonly used techniques:
Social Engineering and Phishing Attacks: These attacks trick victims into downloading malware and giving up their account credentials.
Outbound Emails: Cyber criminals employees or intruders use email to exfiltrate any data that sits on organizations’ outbound email systems.
Downloads to Insecure Devices: Data is transferred by users from secure, trusted systems to an insecure device. From there, the attacker can infiltrate the device and exfiltrate the data.
Uploads to Cloud Storage: Data can be exfiltrated from cloud storage when data is uploaded to insecure or misconfigured resources.
Nightfall provides a highly revolutionised solution to data exfiltration. Nightfall AI's exfiltration prevention capabilities easily integrate with existing tools, thus catering to security teams and companies across industries. Nightfall's exfiltration solution is much more than just a tool; it proactively protects against data breaches, providing tangible benefits for organizations striving to secure their sensitive information.
Data exfiltration, also known as data theft, data exportation, or data extrusion, is the unauthorized transfer of data from a device or network. It can occur as part of an automated attack or can be performed manually. The illegitimate transfer of data often looks very similar to legitimate transfers, making it difficult to detect.
Data exfiltration can occur in various ways and through multiple attack methods. Here are some of the most commonly used techniques:
Social Engineering and Phishing Attacks: These attacks trick victims into downloading malware and giving up their account credentials.
Outbound Emails: Cyber criminals employees or intruders use email to exfiltrate any data that sits on organizations’ outbound email systems.
Downloads to Insecure Devices: Data is transferred by users from secure, trusted systems to an insecure device. From there, the attacker can infiltrate the device and exfiltrate the data.
Nightfall provides a highly revolutionised solution to data exfiltration. Nightfall AI's exfiltration prevention capabilities easily integrate with existing tools, thus catering to security teams and companies across industries. Nightfall's exfiltration solution is much more than just a tool; it proactively protects against data breaches, providing tangible benefits for organizations striving to secure their sensitive information.

App Intelligence

Forensic Search
Exfiltration policies allow you to monitor download events across your Google Drive environment. Through real-time download monitoring, you can identify insider risk and anomalous behaviour before it escalates to large scale security incidents. You can monitor download activity for specific users or user groups, specific drives containing valuable sensitive assets, or downloads of any files containing sensitive data types as discovered and classified by Nightfall's ML/AI based detectors.
You can set up your policies to monitor only, to educate users in real-time about your download and data governance policies, or to automatically suspend user access to the Google Workspace to enforce zero tolerance policies.
The detailed steps to configure the Google Drive Exfiltration policy is explained in the following documents.
In this stage, you select the Integration for which the policy is created. In this case, Google Drive integration must be selected.
Click Policies from the left menu.
Click + New Policy.
Select Exfiltration.
Select Endpoint.
In this option, you can either choose to monitor uploads done to every cloud sync app or select specific cloud sync apps to which the uploads must be monitored.
Select the Cloud Syncing option.
Select one of the following options.
Any Storage Apps: If you select this option, Nightfall monitors the uploads done to every cloud sync storage application.
Specific Storage App(s): If you select this option, you must additionally select the storage apps. Nightfall monitors the uploads done to the selected storage apps.
Once you select a cloud storage application from the drop-down menu, the selected option is displayed on the screen and grayed out from the drop-down menu. You can use the drop-down menu to select additional cloud storage apps.
Intercepts documents sent to the print queue before they reach a physical or virtual printer. Nightfall evaluates the document at the OS print subsystem level (CUPS on macOS).
Domain collections are not used for this trigger. Monitoring scope is configured by printer selection directly on the policy.
Platform note: Printer monitoring is supported on macOS only. Windows support is not yet available.
Scope options
All printers connected to the endpoint.
Specific printers by name or type
Common use cases
Prevent printing of customer records, payroll data, or legal documents on unmanaged or shared printers.
Block printing to fax-to-email or cloud print services running on the endpoint.
Policy recommendations
Always include virtual printers in scope.
Scope block actions to all printers except approved print server destinations in environments with dedicated secure print rooms.
Deploy alongside Removable Media policies for full physical exfiltration coverage.
Note: Native "Save to PDF" or "Print to PDF" bypasses the print monitoring and blocking capability. However, if the PDF is subsequently exfiltrated, Nightfall does monitor and block this.
Learn about the advanced setting options present in the Nightfall exfiltration policy for MAC devices.
The advanced settings pages allows you to configure notifications for Nightfall admins and end-users. Additionally, you can also configure automated actions. The various configurations available in the advanced settings pages are described in the following sections.
In this final stage, you assign a name to the policy, verify your configurations, and create the policy.
Enter a name for the policy.
(Optional) Enter a description for the policy.
Click Next.
Verify if all the policy configurations are set up as per your requirements.
(Optional) Click back or click on any specific stage to modify any of the policy configurations.
Click Submit.
In this stage, you select the Integration for which the policy is created. In this case, Google Drive integration must be selected.
Click Policies from the left menu.
Click + New Policy.
Select Exfiltration.
Select the Google Drive integration.
In this final stage, you assign a name to the policy, verify your configurations, and create the policy.
Enter a name for the policy.
(Optional) Enter a description for the policy.
Click Next.
Verify if all the policy configurations are set up as per your requirements.
(Optional) Click back or click on any specific stage to modify any of the policy configurations.
Click Submit.
Nightfall supports exfiltration prevention in endpoint devices. The exfiltration prevention in endpoint devices prevents your organization's employees from exfiltrating data out of your organization. This feature is available for devices running on the macOS and Windows OS.
To monitor each device for exfiltration, you must first install the Nightfall agent on the devices that require monitoring. You can install the Nightfall agent either manually on each device. Alternatively, you can also use an MDM to install the agent. Once you install the Nightfall agent, you must create policies to start the monitoring. Nightfall monitors the devices as per the policy rules set.
You can learn about how to install the Nightfall AI agent for macOS/Windows OS and the process to create policies from the following links.
This explains the other methods of deployment available for the Nightfall AI extension, separate from the Nightfall AI Agent.
The Nightfall AI extension is commonly installed using MDM in one of two ways:
macOS: Deployed with the Nightfall profile
Windows: Deployed with the MSI
Some, however, utilize other methods of deployment. This section provides options available for those specific use-cases.
Ensure that you have configured domain collections before using the browser uploads option.
To monitor browser uploads:
Select the Browser uploads to option.
Select one of the following options.
Any Domain: If you select this option, Nightfall monitors your uploads done to any domain on the Internet.
Domain in: If you select this option, you must additionally also select the domain collections created in the section. Nightfall monitors the uploads done to all the domains that belong to the selected domain collections.
Once you select a domain collection, it is displayed on the screen and greyed out from the drop-down menu. You can use the drop-down menu to select additional domain collections.
Domain Not in: If you select this option, you must additionally also select the domain collections created in the section. Nightfall does not monitor the uploads done to all the domains that belong to the selected domain collections.
Once you select a domain collection from the drop-down menu, it is displayed on the screen and grayed out from the drop-down menu. You can use the drop-down menu to select additional domain collections.
Learn how to configure admin alerts in Nightfall exfiltration policies.
This stage allows you to select the notifications channels. If Nightfall detects sensitive data in any of the selected upload channels, the notifications are sent to the recipients configured in this section.
This section allows you to send notifications to Nightfall users. The various alert methods are as follows. You must first turn on the toggle switch to use an alert method.
The steps to configure alert channels for policy-level integration are the same as in the case of integration-level alerts. You can refer to this document for steps.
Exfiltration policies allow you to monitor download events across your Salesforce environment. Through real-time download monitoring, you can identify insider risk and anomalous behaviour before it escalates to large scale security incidents. The following are supported and monitored by Nightfall for exfiltration activities,
Attachments & Files
Reports
Records & Objects
Download of any of the above information containers is an exfiltration activity for Nightfall, and if such activities breach a threshold set in one of the exfiltration policies in Nightfall, then Nightfall will flag it an exfiltration event. You can configure which users should receive notifications and what automatic actions must be taken when an exfiltration event is detected.
The detailed steps to configure the Salesforce Exfiltration policy is explained in the following documents.
In this stage, you select the Integration for which the policy is created. In this case, Salesforce integration must be selected.
Click Policies from the left menu.
Click + New Policy.
Select Exfiltration.
Select the Salesforce integration.
Learn about Nyx. Nightfall's AI-powered Copilot.
Nyx is Nightfall’s AI-powered DLP Copilot, designed to help you quickly investigate and understand exfiltration risks. She can surface patterns, summarize user activity, and suggest next steps — all through a simple natural-language conversation.
Click the Comet Icon: In the upper right corner of your Nightfall dashboard, click the comet icon to open Nyx.
Start Conversing: Type your question in plain English — no special syntax required.
The trigger section further enhances the unwanted noise reduction capabilities. With the trigger section, you can
Set what download behavior can be termed as an exfiltration event.
Exclude downloads by trusted apps from being termed as exfiltration events.
In the trigger section, you can set the download behavior, the download frequency to be precise, must be termed as an exfiltration event.
To configure the Trigger section:
Mac with the Nightfall endpoint agent already installed
Permission to install apps from the Mac App Store
1. Install from the Mac App Store. Open this link (the app is not searchable by name in the App Store):
Click through to the Mac App Store and install Nightfall DLP for Browsers.
2. Open Safari extension settings
Below is a step-by-step guide to deploy the Nightfall Endpoint DLP agent for macOS using PDQ's SimpleMDM.
Enroll devices in PDQ SimpleMDM
Create a Device Group with the respective macOS machines assigned to it
Download and unpack Nightfall's install package from the console:
Nightfall for Windows OS allows you to detect exfiltration events on your Windows OS devices. The Nightfall exfiltration feature can monitor any files being uploaded through supported cloud storage apps or browsers on Windows OS devices.
To use Nightfall for macOS, you must install the Nightfall AI agent. This agent monitors your Windows OS device continuously. You can install the agent either manually or through a Mobile device management (MDM) tool. You can request the Nightfall deployment bundle which contains the data required for your MDM deployment.
Nightfall supports the following agent installation methods for Windows:
Learn how to install the Nightfall agent on Microsoft Windows OS using the Rippling MDM.
You have the Device Administrator role in Rippling.
Target Windows devices have been onboarded into Rippling MDM.
On your Nightfall console, navigate to and click the Download Package button on the top right corner of the page. Click Download Package for Windows. A
Below is a step-by-step guide to deploy the Nightfall Endpoint DLP agent for Windows using Workspace ONE UEM.
Confirm that the Windows devices are enrolled and managed through Workspace ONE.
Confirm that a device group has been set up for deployment.
From UEM, navigate to Groups & Settings > Groups > Assignment Groups > click "+ Add Smart Group" and follow the prompts
In this option, you can choose to monitor the copy/paste actions performed by end-users. If end-users copy some data and paste it to unsanctioned locations.
Apart from text data, Nightfall can also detect non-text clipboard content, including images and screenshots. Clipboard Paste trigger uses the optical character recognition (OCR) technology in combination with Nightfall to prevent the exfiltration of sensitive data present in visuals like copied screenshots, scanned documents, or copied images from web browsers.
Use cases
A typical example of this trigger can be a scenario in which an end-user copies an API key and pastes it in a prompt in ChatGPT/Deepseek or any other Gen AI apps while attempting to generate a piece of code.
An employee attempting to capture a screenshot of dashboards, reports, or customer data from sensitive SaaS apps into unsanctioned destinations.
Intercepts data movement - file transfers, uploads, and paste events - within desktop applications. Nightfall monitors at the application layer, capturing events before they reach the network.
Supported applications
Learn how to configure end user notifications in Nightfall exfiltration policies.
This section allows you to configure notifications to be sent to the end user whose actions triggered the violation.
Enter a custom message to be sent to the end user. This message is sent in an Email or a Slack message. You can modify the default message provided by Nightfall and draft your own. The total character length allowed is 1000 characters. You can also add hyperlinks in the custom message. The syntax is <link | text >. For example, to hyperlink https://www.nightfall.ai with the text Nightfall website, you must write < | Nightfall website>.
You can either select Email, Slack, or both as an automated notification method. You must turn the toggle switch to use this option. Based on the options selected, end-users receive notifications in their Email or Slack, based on the option(s) enabled.
End-User Remediation (also known as Human Firewall) allows you to configure remediation measures that end-users can take when an exfiltration event is triggered due to their actions. You must turn on the toggle switch to use this option. When you configure end-user remediation, the user whose actions triggered the exfiltration event receives a notification from Nightfall. This notification provides details of the user's actions that caused the exfiltration along with your custom message. End-users can take appropriate actions.
Nightfall supports the following remediation actions for end-users.
Nightfall Exfiltration for Salesforce helps you to keep tab of the exfiltration activities in your Salesforce orgs. Nightfall leverages Salesforce Shield Real Time Event Monitoring for exfiltration activities across your Salesforce orgs and identifies activities which are in violation to configured policies.
Download of attachments, files, reports and bulk download of objects are all exfiltration event recognised by Nightfall. You can configure policies to set appropriate thresholds for such events and identify them as unwarranted that may require scrutiny. You may configure the policy to alert the stakeholders who need to be notified and choose one of the available actions to be invoked automatically. You may also choose not to configure automated actions but only act after evaluating the specific exfiltration events.
Nightfall exfiltration leverages Salesforce Shield's Event Monitoring to identify exfiltration events. Salesforce Shield provides multiple security tools to safeguard your Salesforce orgs. Nightfall depends on in Salesforce Shield which is available as an independent module within . You must enable the following Event Monitoring settings for all the Salesforce orgs that you wish to monitor,
Generate event log files - Generate an event log file when events occur in your org.
At this time the Nightfall AI Endpoint Agent does not support the ARM processor architecture. However, ARM compatibility is being prioritized in a future release.
If you manage Chrome extensions via Google Workspace Admin Console
See these steps first. Otherwise, the Nightfall extension may not connect properly.
Not sure if this applies to you? If your IT team uses Google Workspace (Google Admin Console) to manage which Chrome extensions are force-installed on employee machines, this applies to you.
Both of the following must be in place before AI Agent Security can function:
Nightfall endpoint agent v1.2.12.11+ installed and running on the endpoint. The hooks call the binary by name, so without the agent the hooks resolve to nothing.
MDM configuration profile v3+ deployed via your MDM provider (Jamf, Mosyle, Kandji, etc.)
MDM scope selected - the device group / Blueprint / Smart Group / assignment that will receive the deployment.
Claude Code is reasonably current on managed devices.
You have the three pieces from this package: the payload (payloads/nightfall-hooks.json) and the scripts for your platform (scripts/macos/ or scripts/windows/).
If the MDM profile has not been deployed, the agent will show a missing permissions error and you will not see any local or remote MCP servers across installed devices.









If the event monitoring module is not setup in Salesforce, event monitoring is displayed as "disabled" on the Scope page as shown in the following image.





“What are my most common exfiltration patterns?”
“Summarize Bob’s activity over the last 7 days.”
“What are my most frequent upload domains? Put results in a table.”
"Write an email to Bob's supervisor for me."
Nyx can process up to 100 exfiltration events at a time.
Available for endpoint customers only. Support for other event types coming soon.
Your feedback will directly shape Nyx’s future! After trying her out, let us know what works well and what could be improved.
Get a Nyx demo
Open Safari
Menu bar: Safari > Safari Extensions...
Or: Safari > Settings > Extensions
3. Enable the extension
Select Nightfall DLP for Browsers in the sidebar
Check the box to enable it
Approve any macOS authorization prompt
4. Set permissions
Turn on Allow in Private Browsing
Click Always Allow on Every Website...
In the confirmation dialog, click Always Allow on Every Website
Extension is enabled under Safari > Settings > Extensions
Private browsing and “every website” permissions are granted
Device shows online in the Nightfall console under Endpoint
Outlook, Apple Mail
AI assistants
ChatGPT, Claude, Microsoft Copilot
Scope options
All supported applications.
Specific applications selected from the list above.
Event types monitored
File attachments and transfers
Uploads within app interfaces
Paste events into app input fields
Domain collections are not used for this trigger. There is no session detection for desktop app events - monitoring applies to all account types within the monitored application.
Messaging
Slack, WhatsApp, iMessage, Signal, Telegram, Discord, Microsoft Teams
Enable Lightning Logger Events - Enable collection of Lightning Logger Events in custom components.
Enable the following events for storage and streaming
Bulk API Result Event - Track when a user downloads the results of a Bulk API request
File Event - Track file activity. For example, track when a user downloads or previews a file
Report Event - Track when a user accesses or exports data with reports
SessionHijacking Event - Track when an unauthorised user gains ownership of a Salesforce user’s session with a stolen session identifier
You can learn more about Salesforce Shield here and once enabled, advance to the next steps with Installing Nightfall DLP for Salesforce
If you have already onboarded your Salesforce org to Nightfall platform, please ensure you have the latest Nightfall DLP package deployed in your Salesforce org. Follow the steps mentioned in Upgrading Nightfall DLP to upgrade it to the latest version.
The installation procedure remains the same as in case of Salesforce DLP for sensitive data. The links to the installation and upgradation documents are as follows.
You must perform the above actions only on those Salesforce orgs in which the Salesforce Shield Event monitoring module is enabled.
Set the minimum number of downloads threshold that must be considered as an exfiltration event.
Set the required time period (frequency). If the minimum download threshold (set in the previous step) is reached or exceeded, within the set time period, an exfiltration event is generated.
In the following image, the configurations are set such that if an asset is downloaded 2 or more times within 10 minutes, an exfiltration event is triggered.
Depending on your environment, a significant number of downloads may be attributed to applications (i.e. backup apps). You may choose to ignore such download events to reduce the noise and focus your monitoring on unexpected application and user download events.
The Exclude apps section allows you to exclude specific applications from being monitored by your policy.
To configure the Exclude apps section, select the applications to exclude from the drop-down menu. Once saved, Nightfall will not alert on download events attributed to the excluded applications.
You must set the action frequency carefully. For example, consider that you set the download condition as 5 or more files, within 1 hour. In this case, if a user downloads four assets, every 1 hour, the policy does not trigger a violation, since the condition is not met.
Integrations > Manage (Endpoint Windows) > Download Package > click "Download Package"
From within SimpleMDM, navigate to Scripts > click “Scripts” > click “Create Script”
Name: Nightfall Pre-Installation Script
Click “Choose File”
Select the “mdm_pre_installation_script.sh” from the mdm_scripts folder that was downloaded from the Nightfall Console.
Create a job.
Navigate to Scripts > click “Job” > click “Create Job”
Name: Deploy Nightfall Pre-Install Script
Script: Select the “Nightfall Pre-Installation Script”
Navigate to Configs > click “Profiles” > click “Create Profile”
Select “Custom Configuration Profile”
Name: Nightfall Profile
Uncheck “Install via Declarative Management”
In testing there were issues with profile deployment unless this was unchecked.
Mobileconfig: Click “Choose File”
From the mac_bundle folder, navigate to “profiles” > select “NightfallAI_Profile_with_Browser_Extensions.mobileconfig”
OS: Only select “macOS”
Navigate to the “Groups” tab
Click “Assign Group”
Select the group > click “Assign”
Navigate back to “Profile” tab > click “Save”
Navigate to Apps & Media > click “Catalog” > click “Add App” > select “Custom App”
From the mac_bundle folder, locate the “nightfall-ai-agent-signed.pkg” > click “Open”
Click the “Groups” tab > click “Assign Groups”
Install Method: MDM
Install Type: Auto
Groups: (select group)
Click “Assign”
Click “Done”
PDQ SimpleMDM does not have the ability to run a job to deploy in a specific order. Due to this, follow the steps below explicitly so as to make sure the agent has the appropriate permissions during install.
.msiNavigate to: https://app.rippling.com/hardware/software
Click Upload Software on the right of the pane and provide the following details.
Name: “Nightfall Endpoint DLP Agent <version>”
<version> is the version of the package your received from Nightfall.
Operating System: “Windows”
Category: “My Uploads” (Default)
Description: “Nightfall Endpoint DLP Agent”.
Upload Icon: use the .png icon file provided.
Upload Installer File: Drop or select the downloaded NightfallAgent.msi file.
Under Silent arguments add /qn /norestart API_KEY="" COMPANY_ID="" INSTALL_NF_DRIVER="1" where the content of API_KEY and COMPANY_ID are the values provided to you by Nightfall. Note that these values must be enclosed in " double quote characters.
Click Submit.
You will receive an email from Rippling with the subject: “Your recently uploaded custom software is processing”
After a period of time (typically less than 1 hour) You will receive an email from Rippling: “Your recently uploaded custom software has been processed successfully!”
You may now proceed to step 2. to deploy the agent.
Click Add on the newly created Software Item in the Rippling Software Catalog.
Click Finished Selecting.
Search or scroll to the newly added item matching the name you used in the previous step.
Download "NightfallAgent.msi" from the Nightfall console:
Log into Nightfall > Integrations > Manage (Endpoint Windows) > click "Download Package" > click "Download Package for Windows"
Unpack the file.
Additionally, take note of the install command for Windows machines. This will need to be copied later.
This step deploys both the agent and the extension via the same MSI file.
Log into Workspace ONE UEM
Navigate to Resources > Native Apps > click "Add" > select "Application File"
Click "Upload" > click "Choose File" > select "NightfallAgent.msi" > click "Save"
Click "Continue"
Under Details tab > Supported Processor Architecture > Select "64-bit"
Navigate to the Deployment Options tab > Locate "Install Command"
Paste the command from the Nightfall console into "Install Command".
Click "Save & Assign"
Set a Name for the Distribution.
Choose an Assignment Group. NOTE: Use the group that was created from the Prerequisites section.
Decide if the App Delivery Method should be Auto or On Demand. For a manual trigger use On Demand.
Click "Create" > click "Save" > click "Publish"
To enable the Clipboard Paste trigger:
Select the Paste To option.
Select one of the following options.
Any Domain: If you select this option, Nightfall monitors your paste actions performed on any domain on the Internet.
Domain in: If you select this option, you must additionally also select the domain collections created in the section. Nightfall monitors the uploads done to all the domains that belong to the selected domain collections. The process of domain selection remains the same as demonstrated in the case of the section.
Domain Not in: If you select this option, you must additionally also select the domain collections created in the section. Nightfall does not monitor the uploads done to all the domains that belong to the selected domain collections.
Once you select a domain collection from the drop-down menu, it is displayed on the screen and grayed out from the drop-down menu. You can use the drop-down menu to select additional domain collections.
Provide Business Justification: This option allows end-users to add a descriptive note on the file transfer or exfiltration event. Basically, users can provide a business justification giving you more context into the file transfer or a business justification. The user input is delivered directly to the console for review, saving you time and helping you assess the risk of the data transfer based on the additional user input.
When an end-user decides to provide a business justification, the following screen is displayed.
Based on the user response, the Exfiltration Event is updated.
The other options available to be configured in this section are:
When a Violation is Reported as False Positive (justified): You can use this option to set actions to be taken when input has been provided by the end-user. You can automatically ignore violations for which the user has provided input.
Remind Every (until Violation expires): You can use this option to adjust the frequency at which Nightfall should remind the user to provide context into their data transfer. You can choose to remind the end user every 24, 48, or 72 hours.
This stage allows you to select automated notification channels or actions if a policy violation occurs.
This section allows you to send notifications to Nightfall users. The various alert methods are as follows. You must first turn on the toggle switch to use an alert method.
The steps to configure alert channels for policy-level integration are the same as in the case of integration-level alerts. You can refer to this document for steps.
Automated actions allow you to configure automated remediation actions when an exfiltration attempt is detected by Nightfall policy. Nightfall supports the following automated actions for Google Drive. You can choose to implement the automated action immediately after detecting a download attempt or after some time.
Suspend Account: This action suspends the user's account who tried to download files and triggered the exfiltration event.
To enable the automated action, you must turn on the respective toggle switch.
You must now select when exactly after detecting the event, the action must be triggered. if you select the Immediately option, the automated action is triggered immediately after the download attempt is made.
If you select the After option, you must select the time gap after which the automated action must be implemented.
This section allows you to configure notifications to be sent to the end user whose actions triggered the violation.
Enter a custom message to be sent to the end user. This message is sent in an Email. You can modify the default message provided by Nightfall and draft your message. The total character length allowed is 1000 characters. You can also add hyperlinks in the custom message. The syntax is <link | text >. For example, to hyperlink with the text Nightfall website, you must write <www.nightfall.ai|Nightfall website>.
The automation settings allow you to send notifications to end users. You can select one or both the notification methods. You must first turn on the toggle switch to use the automation option. The automation notification channels are as follows
Email: This option sends an Email to the user who attempted the download.
Slack: This option sends a Slack message to the user who attempted the download.
End-user remediation (also known as Human Firewall) allows you to configure remediation measures that end users can take, when a violation is detected on by their download attempt. You must turn on the toggle switch to use this option. End-users receive the remediation actions in an Email as an action item. The various available remediation actions for end-users are as follows.
Report as False Positive with Business Justification: This option allows end users to report false positive alerts and provide a business justification as to why the alert is considered to be false positive.
When end-users report alerts as false positive, you can choose the resolution method to be either Automatic or manual.
If end-users do not take any remediation action, you can set the frequency at which they must receive the notifications to take action.
Nightfall for macOS allows you to detect exfiltration events on your macOS devices. The Nightfall exfiltration feature can monitor any files being uploaded through supported cloud storage apps or browsers on macOS devices.
To use Nightfall on macOS, you’ll need to install the Nightfall AI agent. You can install it manually for testing or evaluation purposes, or automate the install through MDM.
Apple requires the use of MDM profiles for applications like Nightfall AI to obtain the necessary permissions to function properly. While you can grant these permissions manually, there is no supported or scriptable alternative to an MDM solution for seamless, unattended deployment at scale.
If managing Chrome extensions via Google Workspace Admin Console
See these first. Otherwise, the Nightfall extension may not connect properly.
Not sure if this applies to you? If your IT team uses Google Workspace (Google Admin Console) to manage which Chrome extensions are force-installed on employee machines, this applies to you.
Nightfall supports the following agent installation methods for macOS:
You can install the Nightfall AI macOS agent in stealth/hidden mode. Installing the agent in stealth mode allows you to hide visible UI elements once the Nightfall agent is installed. When you install the agent in silent mode, the Nightfall status bar icon. Additionally, the Nightfall application will not be visible in the Applications folder when viewed in Finder.
Covert Monitoring: If an organization suspects an employee of exfiltrating sensitive data, they can install the agent in stealth mode to monitor the employee's asset without the employee's knowledge.
Ensuring Bias-Free Compliance: An organization wishes to confirm if their employees are adhering to HIPAA/PCI compliances; they can install the agent in stealth mode without giving any indication to their employees (which can prompt a change in their behavior).
Prevent User Distractions: Organizations that do not wish to distract their users about the agent presence and monitoring can depoy in stealth mode.
In the mdm_pre_installation_script.shfile, find the hide_status_iconflag.
Set the flag to true. By default, the flag is set to false.
Nightfall employs the automatic endpoint update functionality. With this feature, Nightfall can deliver the majority of endpoint agent bug fixes and feature updates directly to endpoints.
Features:
Stay Secure: Receive the latest security patches and updates promptly, reducing the risk of vulnerabilities being exploited.
Remain Compatible: Keep your deployment compatible with the latest operating system updates and other software changes.
Receive New Features: You get access to new features and improvements to exfiltration monitoring without manual intervention.
Learn how to install the Nightfall agent on Microsoft Windows OS manually.
This document outlines the steps to manually deploy the Nightfall AI Agent on a Windows device.
Ensure that Windows endpoint has been enabled on your Nightfall tenant.
Download the Nightfall AI Agent NightfallAgent.msi file from Nightfall.
Download NightfallAgent.msi from to a local folder on the target machine
Integrations -> Endpoint Windows -> Manage -> Download Package -> Download Package For Windows
Navigate to > Exfiltration > Endpoint - (optional)
Copy downloaded NightfallAgent.msi to a folder on a target machine.
Run the Installer:
Launch CMD as an Administrator
b. Navigate to the folder where NightfallAgent.msi is downloaded to.
i. cd C:\\users\\<username>\\Downloads\\ update the above accordingly.
c. Copy the installation command from .
i. Note : this includes the necessary command line parameters for the agent to communicate with Nightfall
ii. Integrations -> Endpoint Windows -> Manage -> Download Package -> 'To install, run the command as admin.
d. Paste the msiexec installation command copied from the above step to cmd and press Enter key.
e. Installation should start in silent mode.
Verify Installation
Once installation is complete, check if the agent is running:
Open Task Manager (Ctrl + Shift + Esc).
b. Confirm the Nightfall agent is configured to your Nightfall tenant
i. On the windows machine:
1. Double-click the Nightfall agent icon in the status bar.
2. The displayed UUID should match your Nightfall tenant UUID located under
ii. On the Nightfall console:
1. The newly configured device should be listed under
The Nightfall AI Agent should now be successfully installed, running on your Windows machine, and connected to your Nightfall tenant. If you run into any issues, please contact Nightfall AI support.
A trigger defines the exfiltration medium - the specific channel or application through which data moves off a managed device. Each trigger represents a distinct interception point: a file upload in a browser, a sync client writing to disk, a document sent to the print queue, a file sent with AirDrop. Nightfall intercepts the event at that point, inspects the content against your detection rules if applicable, and applies the configured action.
You configure one trigger per policy. Each trigger is independently scoped - a browser upload policy and a thick app policy can cover the same domains without conflicting.
A domain collection is a named, reusable set of domains used to scope trigger monitoring. Collections appear in two roles:
Source collection - identifies domains associated with corporate account sessions or originating domains. Used to answer: did this data originate from a corporate account? Example: your company's Google Workspace domain (yourcompany.com on Google Drive).
Destination collection - identifies domains associated with personal account sessions or destination domains. Used to answer: did this data go to a personal account? Example: gmail.com, dropbox.com, chatgpt.com accessed with a personal login.
Collections are created and managed separately from policies, then referenced when configuring data lineage and session detection on the Browser Upload and Clipboard Paste triggers. Not all domains in a collection support session detection - the policy UI shows coverage at configuration time (e.g., "3 of 12 domains across 2 collections support session detection"). Domains without session detection support are always monitored for all account types regardless of which collection they belong to.
You do not need to configure collections for Cloud Syncing, Removable Media, Printer, Thick App (desktop app), Git Push, CLI Transfer, AirDrop, or Bluetooth. Those triggers use application lists, tool lists, or no destination list.
Once you zero in on the policy to the required devices and originating domains, you must now define the trigger actions that can be termed as exfiltration events. Nightfall provides you with multiple types of triggers that you can set as exfiltration events.
Browser Uploads: If an asset is uploaded through a web browser or desktop app to any online destination (for example, a file attached to a ChatGPT prompt or uploaded to a personal Google Drive via the browser), you can define such events as file upload exfiltration events.
Cloud Syncing: If an asset is synced to a cloud storage application running on the endpoint (for example, a file written to a local Dropbox or OneDrive folder and automatically uploaded to the cloud), you can define such events as cloud sync exfiltration events.
Clipboard Paste: If data is copied from a source application and pasted into an external destination (for example, customer records copied from an internal tool and pasted into a personal email), you can define such events as clipboard paste exfiltration events.
Git Push: If source code is pushed from a managed endpoint to a non-approved remote repository (for example, a developer pushing proprietary code to a personal GitHub account), you can define such events as git push exfiltration events. This feature is designed to prevent accidental or intentional source-code exfiltration. Detection is based on source and destination metadata.
Removable Media: If an asset is transferred to a removable storage device connected to the endpoint (for example, a file copied to a USB flash drive or an external hard drive), you can define such events as external media transfer exfiltration events.
Printer: If a document is sent to the print queue on the endpoint (for example, a confidential report printed to a shared office printer or exported as a PDF using a virtual printer), you can define such events as print exfiltration events.
Desktop App: If data is transferred, uploaded, or pasted within a desktop application (for example, a file attached in WhatsApp or sensitive content pasted into a ChatGPT desktop app), you can define such events as exfiltration events.
CLI Transfer: If a file is uploaded or downloaded by a selected command-line tool on the endpoint (for example, scp of an export to a home machine, or curl / aws s3 of a secrets file), you can define that as a CLI Transfer exfiltration event. You choose the tools on the policy. This is not Git Push.
AirDrop: If a file is sent through Apple AirDrop from a managed Mac (for example, a spreadsheet sent to a personal iPhone), you can define that as an AirDrop exfiltration event. There is no recipient picker. Data Source and Data Destination do not apply.
Bluetooth: If a file is sent over Bluetooth from a managed endpoint (for example, a document sent to a personal phone), you can define that as a Bluetooth file-transfer exfiltration event. This is not pairing or audio. Nearby device details appear on the event, not as policy filters.
The steps to use the above triggers are elaborated in the following sections.
Learn more about how automated actions work in a Nightfall exfiltration policy.
This section describes the various actions that Nightfall takes automatically when an exfiltration attempt is detected. This automated action is triggered when the condition set in the section is violated.
The automated actions supported by Nightfall are described as follows.
This action automatically blocks the process of file transfer thus preventing an exfiltration attempt. You can use this action to prevent the upload of files with sensitive data, to web browsers or cloud storage apps. You must enable the toggle switch to activate the automated action.
You can configure the section and the section such that you can leverage this feature to:
Block transfer based on file origin: Block the upload of files downloaded from highly sensitive SaaS applications.
Block transfer based on destination: Allow uploads only to sanctioned destinations.
Combine origin and destination: Create powerful DLP policies that factor in both where files came from and where they are headed.
Some use cases scenarios in which you can use the automatic Block action, are as follows.
Employees access confidential reports from an internal data repository and attempt to upload them to personal iCloud or unsanctioned personal email service.
Solution
Configure the filters in the section to scope the policy to include domains to be monitored (for instance your organization *.drive.google.com or *.force.com). Now, any file(s) downloaded from the configured domain(s) are monitored. Configure the section to trigger an exfiltration action when an attempt is made to upload the downloaded file to an unsanctioned destination (for instance to personal iCloud or a non corporate sanctioned domain). Finally, enable the Block automated action.
In this scenario, if a user downloads a file from an organization's Google Drive or Salesforce and attempts to upload it to their personal iCloud, the action is blocked and user gets the following error message.
Also, other similar scenarios could be
A health department which prevents employees from uploading customer health data, downloaded from organization's domain, to employees' personal Google Drive, OneDrive, or any supported cloud storage app.
An employee working on code repository of an organization, attempting to upload a file to developer forums, LLM services, or generative AI apps like ChatGPT.
An organization allows employees to store work documents only in corporate-managed OneDrive or Google Drive but wants to prevent uploads to personal accounts.
Solution
Configure the filters in the section to scope the policy to include domains to be monitored (for instance your organization Google Drive or OneDrive). Now, any file(s) downloaded from the configured domain(s) are monitored. Configure the section to monitor only unsanctioned domains. Finally, enable the Block automated action. Now any attempt to upload a file to sanctioned domains is allowed.
This action captures a session recording before and after an endpoint exfiltration event and stores it in the destination you select. Use it to review what happened around the event.
To enable recordings, store them in your own bucket, and play them back from an event, see .
The Scope section determines which areas of Nightfall needs to be monitored by Nightfall for Exfiltration. You can choose one or all of the following data types to be monitored.
Attachments & Files
Reports
Records & Objects
After you make the required selection, you can also add filters to monitor specific Salesforce users or Salesforce profiles.
Nightfall can detect download actions done only from the Salesforce lightning version. Any download action done on the Salesforce Classic version cannot be detected by Nightfall.
In the Data Types section, you must select the Salesforce data types to be monitored. By default, all the three data types are selected. You can choose to either retain all the three data types or clear any of the data types.
The Filters section allows you to add additional filters, on top of the selected data types, to narrow down the monitoring scope. Nightfall provides the following two types of filters.
You can choose specific Salesforce users whose activities need to be monitored or excluded from being monitored. Nightfall populates the list of all your users from Salesforce. You need to select either the users whose activities need to be monitored or the users whose activities need to be excluded from monitoring.
To add Users filter, click Add Filter and select Internal Users.
To monitor specific users, select the Monitor specific option. To exclude specific users from being monitored, select the Monitor all, except option.
Nightfall populates the list of Salesforce users in the Search users field. You can select the all the required users.
You can choose specific Salesforce profiles whose activities need to be monitored or excluded from being monitored. Nightfall populates the list of all your Salesforce profiles. You need to select either the profiles whose activities need to be monitored or the profiles whose activities need to be excluded from monitoring.
To monitor specific Salesforce profiles, select the Monitor specific option. To exclude specific Salesforce profiles from being monitored, select the Monitor all, except option.
Nightfall populates the list of Salesforce profiles in the Search profiles field. You can select the all the required users.
Contoso Ltd. uses Salesforce to host their applications. They have three users Steve, Rick, and Matt in their Salesforce org. These users are not Contoso employees. They are employees of Acme corp. which is a prospective customer of Contoso Ltd. Steve, Rick, and Matt are evaluating Constoso's app so that they can check if it meets Acme corp's requirements. Contoso has created a Salesforce profile called Prospective customers and added these three users to this profile
Contoso Ltd. uses Nightfall Salesforce exfiltration and wishes to check if any files with sensitive data is downloaded by any of these three users. They create a Salesforce exfiltration policy to monitor all the data types. They can choose one of the following filter.
They can use the filter and add these three users.
They can select the filter and add the Prospective customers profile to it. So, in future if any other prospective customers added, they are also automatically monitored.
In this final stage, you assign a name to the policy, verify your configurations, and create the policy.
Enter a name for the policy.
(Optional) Enter a description for the policy.
Click Next.
Verify if all the policy configurations are set up as per your requirements.
(Optional) Click back or click on any specific stage to modify any of the policy configurations.
Click Submit.
This document explains the steps to install the Nightfall for Google Drive.
To install the Nightfall DLP for Google Drive integration, you must have the following:
A Google Workspace account, preferably a service account.
An admin user account of your organization's Google Workspace account (or any other Google Workspace account) on which you wish to install the integration.
To install Nightfall for Google Drive:
This walkthrough adds the Nightfall Profile Chrome ExtensionSettings to an existing custom macOS profile.
When a company has deployed another profile that controls the Chrome browser ExtensionSettings and it clashes with Nightfall's Profile, the administrator can add the Nightfall ExtensionSettings within the currently present profile to allow the Nightfall extension to connect.
Simply add this code block to the custom, common MDM profile within the <array> brackets:
An example of it is found below:
Below is a step-by-step guide to deploy the Nightfall Endpoint DLP agent for macOS using Mosyle MDM.
Before you begin, ensure you have:
Mosyle Business or Mosyle Manager with admin access
Nightfall API Key and Company ID - available at app.nightfall.ai/endpoint under Agent Configuration
Below is a step-by-step guide to deploy the Nightfall Endpoint agent for macOS using Workspace ONE UEM.
Confirm that the macOS devices are enrolled and managed through your MDM.
Confirm that a device group has been set up for deployment.
From UEM, navigate to Groups & Settings > Groups > Assignment Groups > click "+ Add Smart Group" and follow the prompts
Nightfall monitors the following signals during a Git push operation:
The endpoint where the push originates
The user performing the push
The Git protocol (HTTPS / SSH)
AirDrop watches files sent through Apple AirDrop on a managed Mac. Nightfall records the transfer as an AirDrop / AirDrop Transfer event and can monitor or block it when the file matches the policy.
This is a file-transfer trigger. It is not the same as Removable Media (USB) or Bluetooth. The wizard label is AirDrop.
Domain collections are not used. Data Source and Data Destination are shown as disabled placeholders: Not applicable for AirDrop action. There is no recipient or nearby-device picker. The policy applies to AirDrop file transfers on devices in the policy scope.
If you do not see AirDrop in the For dropdown, ask your Nightfall account team to enable it.
What you configure
Bluetooth watches file transfers over Bluetooth on a managed endpoint. Nightfall records the transfer as a Bluetooth / Bluetooth Transfer event and can monitor or block it when the file matches the policy.
This is not all Bluetooth activity. Pairing, audio, keyboards, and mice are not this trigger. The wizard label is Bluetooth.
Domain collections are not used. Data Source and Data Destination are disabled placeholders: Not applicable for Bluetooth action. There is no device-type picker on the policy. The policy applies to Bluetooth file transfers on devices in the policy scope. Device type and name show up on the event, not as policy filters.
If you do not see Bluetooth in the For dropdown, ask your Nightfall account team to enable it.
What you configure
All AI agent violations appear in the unified Incidents > Exfiltration Prevention view - there is no separate incident queue. This page explains how to identify, review, and respond to AI agent incidents.
Navigate to Incidents > Exfiltration Prevention. AI agent incidents are identified by the "AI Prompt" event type label in the incident list.
The Trigger section in Salesforce policies allows you to define the frequency of action that must be considered as an exfiltration event. In case of Salesforce policies, the download frequency is the trigger.
The download frequency can be defined as the number of downloads over a period to time. This allows you to set custom thresholds in terms of number of downloads over a specific period of time and can be useful to identify anomalous download patterns for specific locations, users or content type. This can be set in combination to other scoping capabilities.
In the Actions section, you can define the download action that must be considered as a potential exfiltration attempt by Nightfall. Nightfall allows you to set the frequency of downloads as the action.
To configure Actions:
Click the minimum number of files that must be the download threshold.
As employees adopt AI coding assistants like Claude Code, Cursor, and GitHub Copilot, those assistants increasingly reach beyond the editor, connecting to external tools and data sources through the Model Context Protocol (MCP), running shell commands, and reading from your codebase and filesystem. Each of these actions is a potential path for sensitive data to leave your environment, often invisibly to traditional DLP. Nightfall's AI Agent Governance gives security teams visibility into what AI agents are doing and the ability to apply data protection policies to that activity in real time.
This section covers three surfaces in the Nightfall console under AI Governance:
MCP Server Visibility (Inventory, Collections, Users & Devices, Settings): what is already running on endpoints
Nightfall uses two complementary mechanisms to protect AI agent activity:
Hooks intercept AI agent actions before they execute. When a developer submits a prompt, calls a tool, or runs a shell command, Nightfall scans the content against your policies and can block the action if a violation is detected.
Supported agents: Claude Code, Cursor, VS Code
Enforcement: Block or Monitor
OpenTelemetry (OTel) captures a complete telemetry stream of AI agent activity after actions complete. This provides full session audit trails including cost tracking, model information, and tool activity.
Run Options: Select “Run ASAP”
Click “Create”
Stealth mode installation hides the agent only from UI. Employees can find Nightfall if they navigate to the Application folder via Terminal.




























When
Relative time (e.g., "2 hours ago")
Actor
Machine name and device ID
Policy
Policy name that triggered the violation
Status
Active, Blocked, Ignored, Resolved or Acknowledged
Column
Content
Event Label
"AI Agent Hooks" label for Hooks and AI Agent Telemetry for OTEL
Click Edit
Select all employees or specific target devices.
Click Save.
Script: mdm_pre_installation_script.sh
Profile: NightfallAI_Profile_with_Browser_Extensions.mobileconfig
Agent: nightfall-ai-agent-signed.pkg
A target device group scoped to the macOS devices you want to monitor
(Optional) If the ability to upload a .PKG to Mosyle is not available, make sure the .PKG file is stored/hosted somewhere.
Log in to app.nightfall.ai and navigate to Settings → MDM Profile.
Select Mosyle from the list of supported MDM providers.
Follow the OAuth prompts to grant Nightfall read-only access to your Mosyle device inventory and user identity data. This allows Nightfall to map usernames to devices automatically.
Unpack the zip file provided and locate the mdm_pre_installation_script.sh file in the mdm_scripts folder.
On Mosyle, navigate to Management → Custom Commands.
Paste the content of mdm_pre_installation_script.sh into the script editor.
Target the command to desired devices group
Click Save.
Run immediately.
Unpack the zip file provided and locate the NightfallAI_Profile.mobileconfig file in the Profiles folder.
Navigate to Management → Configuration Profiles.
Click the Upload button and upload NightfallAI_Profile.mobileconfig.
Configure the settings for your configuration profile.
In the Scope tab, add the target devices or device groups to which this profile should be deployed.
Click Save.
Once assigned, the profile will be automatically deployed to target machines.
On Mosyle, navigate to Management → Install PKG → CDN.
Upload the nightfall-ai-agent-signed.pkg.
This creates a unique CDN reference, e.g.: %MosyleCDNFile:d4d8f767-3f99-4747-8041-253ea90c462d%
The Nightfall Agent updates automatically.
The Nightfall Profile will need updated from Mosyle if a new one is released.
The Nightfall Extension updates automatically.
Unpack the zip file provided and locate the mdm_nightfall_ai_agent_uninstall.sh file in the mdm_scripts folder.
On Mosyle, navigate to Management → Custom Commands.
Paste the content of mdm_nightfall_ai_agent_uninstall.sh into the script editor.
Choose the device scope to deploy the command to.
Click Save.
Run immediately.
Auditability and Control: hooks, OpenTelemetry, and AI agent security policies
The Model Context Protocol lets AI assistants connect to external servers that provide tools and data, for example a GitHub server, a database connector, or an internal knowledge base. Because these connections can move data in and out of the assistant, knowing which servers are in use is the foundation of governing them.
Nightfall automatically discovers and reports MCP activity across your monitored endpoints:
Connected servers and clients - Nightfall detects the MCP servers each AI client connects to and surfaces these as connection events in the AI Governance dashboard.
Configuration discovery - MCP server configurations are discovered from the agent's settings on the endpoint, including assistants installed through managed channels such as the Microsoft Store.
Accurate client attribution - Each event is attributed to the specific assistant that generated it (for example, Claude Code or Claude Desktop).
Note: Some AI clients label MCP tool activity differently, and a few do not include the server name in the activity they report. Where the server can be identified, you can scope policies to specific servers; where it cannot, that activity is governed under your broader "all servers" policies.
MCP Gateway is a separate tab next to Inventory. Clients such as Cursor, Claude Code, Windsurf, and VS Code connect to one Nightfall endpoint. Admins enable servers from a catalog or by URL. Users bring their own OAuth or PAT. Every tool call is written to the gateway Audit log.
The gateway tab is enabled per organization. If you do not see it, contact your Nightfall account team.
Beyond seeing which servers are connected, Nightfall can inspect and act on what AI agents actually do: the prompts, tool calls, and responses flowing through them.
Hooks - lifecycle hooks that fire as the agent works. Nightfall uses them to inspect activity and enforce policy.
OpenTelemetry (OTel) - structured agent telemetry that feeds the same dashboards and detection policies you use across Nightfall.
Supported agents: Claude Cowork
Enforcement: Monitor only (no real-time blocking)
Additional data: Token usage, cost per prompt, model name, API errors
Before AI Agent Security can function on your endpoints, ensure the following requirements are met:
Version 1.2.12.11 or later is required.
The agent must be installed and running on each endpoint where AI agents are used.
At least one AI Agent Security policy must be active in your Nightfall console. SecOps or IT administrators must install hooks using an MDM script or the IDE console for Cursor, Claude Code or VS Code.
Setup & Installation - Verify your deployment and understand how hooks are installed
Hooks vs. Open Telemetry - Compare the two enforcement mechanisms
Policy management - Step-by-step policy creation guide
Policy incidents - How to review and respond to AI agent violations
MCP server collections - Discover and manage MCP servers across your fleet
<dict>
<key>ExtensionSettings</key>
<dict>
<key>jgmgecncmjklkabkejnjfgfkglapfgek</key>
<dict>
<key>installation_mode</key>
<string>force_installed</string>
<key>update_url</key>
<string>https://clients2.google.com/service/update2/crx</string>
</dict>
</dict>
<key>PayloadDisplayName</key>
<string>Google Chrome - Nightfall Extension</string>
<key>PayloadIdentifier</key>
<string>com.google.Chrome.8370900F-6579-4703-8FEF-1DE3DD384618</string>
<key>PayloadType</key>
<string>com.google.Chrome</string>
<key>PayloadUUID</key>
<string>8370900F-6579-4703-8FEF-1DE3DD384618</string>
<key>PayloadVersion</key>
<integer>1</integer>
</dict>
<dict>
<key>ExtensionSettings</key>
<dict>
<key>jgmgecncmjklkabkejnjfgfkglapfgek</key>
<dict>
<key>installation_mode</key>
<string>force_installed</string>
<key>update_url</key>
<string>https://clients2.google.com/service/update2/crx</string>
</dict>
</dict>
<key>PayloadDisplayName</key>
<string>Google Chrome Beta - Nightfall Extension</string>
<key>PayloadIdentifier</key>
<string>com.google.Chrome.beta.A6E44352-4604-4968-8F35-F74BA0FE5C48</string>
<key>PayloadType</key>
<string>com.google.Chrome.beta</string>
<key>PayloadUUID</key>
<string>A6E44352-4604-4968-8F35-F74BA0FE5C48</string>
<key>PayloadVersion</key>
<integer>1</integer>
</dict><?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>PayloadContent</key>
<array>
...
...
<dict>
<key>ExtensionSettings</key>
<dict>
<key>jgmgecncmjklkabkejnjfgfkglapfgek</key>
<dict>
<key>installation_mode</key>
<string>force_installed</string>
<key>update_url</key>
<string>https://clients2.google.com/service/update2/crx</string>
</dict>
</dict>
<key>PayloadDisplayName</key>
<string>Google Chrome - Nightfall Extension</string>
<key>PayloadIdentifier</key>
<string>com.google.Chrome.8370900F-6579-4703-8FEF-1DE3DD384618</string>
<key>PayloadType</key>
<string>com.google.Chrome</string>
<key>PayloadUUID</key>
<string>8370900F-6579-4703-8FEF-1DE3DD384618</string>
<key>PayloadVersion</key>
<integer>1</integer>
</dict>
<dict>
<key>ExtensionSettings</key>
<dict>
<key>jgmgecncmjklkabkejnjfgfkglapfgek</key>
<dict>
<key>installation_mode</key>
<string>force_installed</string>
<key>update_url</key>
<string>https://clients2.google.com/service/update2/crx</string>
</dict>
</dict>
<key>PayloadDisplayName</key>
<string>Google Chrome Beta - Nightfall Extension</string>
<key>PayloadIdentifier</key>
<string>com.google.Chrome.beta.A6E44352-4604-4968-8F35-F74BA0FE5C48</string>
<key>PayloadType</key>
<string>com.google.Chrome.beta</string>
<key>PayloadUUID</key>
<string>A6E44352-4604-4968-8F35-F74BA0FE5C48</string>
<key>PayloadVersion</key>
<integer>1</integer>
</dict>
...
...
</array>
</dict>
</plist>Log in to Nightfall.
Click Google Drive under the MY INTEGRATIONS section (click Show more if you are unable to view Google Drive)
Click Begin Setup.
The access permission page is displayed as follows. Copy the client ID and Scopes ID generated.
Login to your Google Workspace with an admin account.
Click the menu icon.
Select Admin.
In the Admin console left pane, expand Security and then expand Access and data control.
Click API controls.
Click MANAGE DOMAIN WIDE DELEGATION under Domain wide delegation.
Click Add New.
Paste the Client ID copied from the Nightfall app, in the Client ID field.
Paste the Scopes ID copied from the Nightfall app, under OAuth Scope field. Use comma to add multiple scope IDs.
Click AUTHORIZE.
Return to the Nightfall app and click Next Step.
Click Connect.
Once the installation is completed, you can view the details of your Google Drive in the Nightfall app.
Download "mac_bundle.zip" from the Nightfall console:
Log into Nightfall > Integrations > Manage (Endpoint macOS) > click "Download Package" > click "Download Package for macOS"
Unpack the file.
This step deploys one script - the pre_installation_script. The "pre installation script" ensures the machine is in a clean state for the Nightfall install and wipes any preexisting Nightfall installations.
From UEM, navigate to Resources > Scripting > Scripts > click "Add" > select "macOS"
Add the Nightfall Pre-Installation Script:
Name the script "Nightfall Pre-Installation Script" and add a description.
Confirm the language is "Bash".
Click "Upload" > navigate to "mac_bundle" > "mdm_scripts" > and select the mdm_pre_installation_script.sh > click "Open" > click "Next"
Click "Save".
Assign the Pre-Installation Script to the smart group.
From the Scripts page > select the "Nightfall Pre-Installation Script" > click "Assign"
Click "New Assignment" at the top-left.
Name the assignment and select a smart group. NOTE: This should be the same group as the previous script step.
This step deploys the mobileconfig profile to push the browser extension and to give permissions to the agent. Always make sure this step takes place before Step 3 - deploying the PKG.
From Workspace ONE UEM, navigate to Resources > Profiles & Baselines > Profiles
Click the "Add" dropdown > select "Upload Profile" > Select platform: "Apple macOS"
Select "Device Profile" (if desired)
Click "Upload" > "Choose File" > navigate to mac_bundle > profiles
Select the mobileconfig entitled, NightfallAI_Profile_with_Browser_Extensions.mobileconfig
NOTE: If the "with_browser_extensions" file is not selected it will not deploy the Nightfall extension within the browser and key functionality of Nightfall could be lost.
Click "Save" > click "Continue".
Under "Smart Groups", assign target devices by adding the group previously created from the Prerequisite steps. NOTE: All other settings are optional and depend upon your organization's preference.
Click "Save and Publish"
Review to confirm that the device assignment is correct.
Click "Publish"
Once published, the profile will be automatically deployed to target machines.
This step deploys the PKG, which pushes out the agent to the targeted devices.
From UEM, navigate to Resources > Apps > Native Apps
Click "Add" dropdown > select "Application File"
Click "Upload" > tick "Local File" > Click "Choose File" > select nightfall-ai-agent-signed.pkg > click "Open" > click "Save" > click "Continue"
Select the preferred Deployment Type as "Full Software Management"
Download and run the Workspace One Admin Assistant and follow the steps to generate a .plist for the Nightfall PKG.
Click "Upload" > click "Choose File" > navigate to the plist file > click "Open" > click "Save"
Click "Continue" > navigate to the "Images" tab > drag over the Nightfall icon generated
Click "Save & Assign"
Name the Distribution and add a description.
Choose the same "Assignment Group" as in Step 2.
Adjust the "App Delivery Method" accordingly > click "Create"
Click "Save"
Review the devices being deployed to, and if correct click "Publish".
Nightfall upgrades the agents automatically when the latest version is available from the console. To push a newer version from Workspace One UEM out-of-band simply perform Step 3 again by uploading a new package.
The steps below will immediately push to the Assignment Group what is being published at that time. To deploy everything at once and in a specific flow, use the Freestyle Orchestrator feature.
This guide does not cover the Freestyle Orchestrator Workflow.
The repository name and configured remotes
A Git Push Monitoring policy evaluates where code is being pushed, not what is being pushed. If the destination does not match your approved Git domains, Nightfall generates an exfiltration event.
Supported Git Destinations
Git Push Monitoring supports:
GitHub Cloud
GitLab Cloud
Bitbucket
Any Git server accessible via HTTPS or SSH
Policy Configuration
Step 1: Define Approved Git Destinations
Customers define approved Git hosting locations using Domain Collections.
Examples:
github.com/my‑company‑org/*
gitlab.company.com/*
bitbucket.org/company/*
These domains represent where source code is allowed to be pushed.
Step 2: Configure Git Push Monitoring Policy
Policy Type: Endpoint Exfiltration Action: Git Push
Destination Condition Options:
Any domain
Domain in approved list
Domain not in approved list (recommended)
Recommended Configuration:
This configuration alerts when developers push code outside approved repositories.
Example Use Cases
Prevent Personal GitHub Usage
Approved: github.com/company‑org/*
Detected: github.com/john‑doe/test‑repo
Monitor Scratch or Temporary Repositories
Even if the repository is newly created or unnamed, Nightfall detects the push if the destination domain is not approved.
Enforce Corporate GitHub & GitLab Usage
Ensure all production code stays within:
Corporate GitHub organizations
Internal GitLab instances
Event Details
When a Git push violates policy, Nightfall generates an event with metadata‑only context.
Event Summary Fields
Field
Description
Event Type
Git Push
Repository
Repository name
Actor
Example Scenarios
The following scenarios illustrate the support matrix for this capability.
Push to Approved Repository
Git operation succeeds
No alert generated
Push to Non‑Approved Repository
Git operation succeeds (no blocking)
Exfiltration event generated
HTTPS and SSH Both Supported
Detection works for both authentication methods
Multiple Remotes Supported
Events reflect the actual remote used for the push
Unmanaged Devices
No detection occurs without an endpoint agent
Git Push Monitoring provides organizations with a simple and effective control to:
Detect source code exfiltration
Enforce approved Git destinations
Gain visibility into developer Git activity
Managed Endpoint with Nightfall agent
└── git push
├── Action: Git Push
├── Source: Managed device
└── Destination:
├── Approved domain → Allowed
└── Non‑approved domain → Exfiltration Event generatedAction: Git Push
For: Domain not in <Approved Git Domains>Leave Data Source and Data Destination as shown. They are not configurable for this trigger. Switching to AirDrop clears any asset-origin filters that were set on another trigger.
Content scanning and detection rules apply.
You can Monitor or Block.
End-user notification, when enabled, uses the title Assets transferred via AirDrop. Destination on that notice is empty because the product does not store an AirDrop recipient.
Platform note
AirDrop is a macOS capability. The policy wizard does not currently lock the OS checkboxes to Mac only. Put macOS in the policy scope. Windows devices will not produce AirDrop events.
What shows up on an event
Event type: AirDrop file transfer (list views may say Airdrop File Transfer; Forensic Search shortens the action to AirDrop).
File name, file hash, file size, start time.
No recipient device list (unlike Bluetooth).
Common use cases
Stop a laptop from AirDropping a payroll sheet to a personal phone in a cafe.
Log AirDrop of design files from a studio Mac to an unmanaged iPad.
Cover the wireless hop that Removable Media and Browser Upload miss.
Policy recommendations
Pair with To removable media and Bluetooth if you care about every off-device copy that never hits a browser.
Use content detection if you only want to fire on sensitive files. You can also run a lineage-only policy if your tenant supports that pattern on other file-transfer triggers.
Do not expect to allowlist a specific friend's iPhone. That control is not in the wizard.
How this differs from nearby triggers
USB / external disk
To removable media
Bluetooth file send, with device names
Bluetooth
scp / curl
Can I limit AirDrop to certain people or devices?
No. The AirDrop scope has no recipient filter. The policy applies to matching transfers on in-scope endpoints.
Why are Data Source and Data Destination greyed out?
AirDrop does not take those filters. The placeholders say they are not applicable.
Does this cover AirPlay, Continuity, or iCloud?
No. This trigger is AirDrop file transfer only.
Will a Windows policy do anything?
You will not get AirDrop events from Windows. Scope the policy to macOS.
Can I block AirDrop?
Yes. Enable the block action on the policy. Monitor-only still writes an event.
Where do I see the file that was sent?
On the event: file name, size, hash, and start time, plus the usual user and device context.
Leave Data Source and Data Destination as shown. Switching to Bluetooth clears any asset-origin filters that were set on another trigger.
Content scanning and detection rules apply.
You can Monitor or Block.
End-user notification, when enabled, uses the title Assets transferred via Bluetooth. Destination is the comma-separated device names from the transfer, when Nightfall has them.
What shows up on an event
Event type: Bluetooth file transfer (list views may say Bluetooth File Transfer; Forensic Search shortens the action to Bluetooth).
File name, file hash, file size, start time.
Bluetooth Devices on the event (when the feature is on): device name, type, vendor, MAC address, product id and name.
Device types you may see: Phone, Computer, Audio, HID, Wearable, Other.
Common use cases
Catch a file sent from a laptop to a personal phone over Bluetooth.
Investigate which nearby device received a transfer (name, type, MAC).
Cover the path that is not USB and not AirDrop.
Policy recommendations
Pair with AirDrop on Mac fleets and To removable media for physical drives.
Use the event device list for investigation. You cannot allowlist a MAC address in the trigger today.
HID or Audio in the device list on an event does not mean the policy watches keyboards or headsets. It means a file transfer involved a device Nightfall classified that way.
How this differs from nearby triggers
AirDrop to an iPhone
AirDrop
USB stick
To removable media
scp to another host
Does this monitor every Bluetooth connection?
No. Only file transfers. Pairing and audio are out of scope.
Can I allow corporate Bluetooth devices and block everything else?
Not in the policy wizard. There is no include/exclude list for Bluetooth devices. Removable Media has vendor and serial filters; Bluetooth does not.
Why are Data Source and Data Destination greyed out?
Bluetooth file transfer does not take those filters.
What device details will I see?
When present: name, type (Phone, Computer, Audio, HID, Wearable, Other), vendor, MAC, product id, product name. Search the devices list on the event.
Can I block the transfer?
Yes. Enable the block action. Monitor-only still writes an event.
Is this the same as AirDrop?
No. AirDrop is Apple's peer transfer. Bluetooth is Bluetooth file send, and the event can list the other device.
Set the time period within which the minimum no. of downloads must be considered as exfiltration event.
In the following case, an exfiltration event is created if, there are 2 or more downloads within a minute.

You must set the action frequency carefully. For example, consider that you set the action condition as 5 or more files, within 1 hour as shown in the following image. In this case, if a user downloads four assets, every 1 hour, the policy does not trigger a violation, since the Action condition does not match. So, a user can keep downloading four files every hour and get away with it.
Currently, this action is supported only for MAC devices.
Nightfall for Google Drive allows you to configure alerts at the policy level and also at the integration level. Alerts can be sent in Google drive by using the following alert channels.
Slack
Webhook
Jira Tickets
When you configure alert settings at the integration level, the alert settings apply to all the policies, created for the Google Drive integration. However, when you configure alert settings specifically for a policy, which is created in the Google Drive integration, the alert settings are applicable only for that specific policy.
This document explains how to configure alerts at the integration level. To learn about how to configure alerts at the policy level, read .
To use Slack as an alert platform, you must first perform the required Slack configurations. You can refer to to learn more about how to configure Slack as an Alert platform.
To use Webhook as an alert platform, you must first perform the required Webhook configurations. You can refer to to learn more about how to configure Webhook as an Alert platform.
To use JIRA as an alert platform, you must have the DLP for the JIRA app installed from the . You can read more about the DLP for JIRA integration .
You can configure alerts at the integration level once you have installed the Nightfall for Google Drive integration.
To configure alerts at the integration level:
Navigate to the Google Drive integration
Scroll down to the Alerting section.
You can configure one or multiple alert channels.
To configure Slack as an alert channel, click + Slack channel.
In the Slack alert channel field, enter the name of the Slack channel in which you wish to receive the alerts.
Click Save.
A confirmation pop-up box is displayed to confirm if the Slack channel (entered in the second step) must be used only for Google Drive integration or all the Nightfall integrations.
Select No, only integration level to use the Slack channel only for Google Drive, or select Yes, please to use the selected Slack channel for all the Nightfall integrations.
Click + Email.
Enter the Email ID of the recipient who should receive the notifications.
Click Save.
A confirmation pop-up box is displayed to confirm if the Email ID (entered in the second step) must be used only for Google Drive integration or all the Nightfall integrations.
Select No, only integration level to use the Slack channel only for Google Drive, or select Yes, please to use the selected Slack channel for all the Nightfall integrations.
Click + Webhook.
Enter the Webhook URL.
Click Test. If the test result is not successful, check the Webhook URL.
(Optional) Click Add Header to add headers.
Click + Jira Ticket.
Select a JIRA project from the Jira Project drop-down menu.
Select an issue type from the Issue Type drop-down menu.
(Optional) Add comments to be added in the JIRA ticket.
A confirmation pop-up box is displayed to confirm if the JIRA settings configured for the Google Drive integration must be applied to all the other Nightfall integrations too.
Select No, only integration level to use the configurations only for Google Drive, or select Yes, please to use the selected JIRA configurations for all the Nightfall integrations.
When a Violation occurs, Nightfall sends a notification to the end-user whose actions triggered the violation. While notifying the end-user, Nightfall also sends a text message. You can draft the text message to be sent to the end-user. This message applies to all the policies. Click Save changes once done.
This document explains what admins and end-users can do once a policy is violated.
When end-users violate a policy, the Nightfall admin is notified about the incident. The notification channel used to notify the Nightfall admin depends on the settings configured in the Admin Alerting section. If you have not enabled any notification channels in the Admin alerting section, Nightfall admins are not notified.
If you have enabled the email notification in the Admin alerts section, Nightfall admins receive an email. The email is as shown in the following image.
The Email consists of the following data.
Event: The event that caused the violation. For Google Drive, the event is always a download of assets.
Actor: The Email ID of the user who downloaded the file.
When: The date and time when the email was downloaded.
Where: The name of the file that was downloaded.
Policies Violated: The name of the policy that was violated.
Violation Dashboard: The link to the Events screen to view the violation in detail.
Actions: The list of actions that the Nightfall admin can take.
Also, a Slack message is sent if you have enabled the Slack alerts for the Nightfall admin. The Slack message looks as shown in the following image.
End-users receive notifications and remediation actions if the Nightfall admin has enabled these settings. The notifications are based on the settings configured in the section. The end-user remediation actions are based on the settings configured in the section.
If you have configured the Email notification for end-users and enabled the end-user remediation, end-users can take remediation actions from the Email itself.
If you have configured Slack notifications for end-user and enabled end-user remediation, end-users can view the Slack message.
Nightfall admins can manage violations from within the Nightfall console. The Events page in Nightfall lists all the violations under the Exfiltration tab. End-users can get a detailed view of each exfiltration Event triggered.
To view violations in Nightfall navigate to the Exfiltration Prevention page from the left menu.
The Exfiltration Events page lists all the exfiltration events. To view events with specific statuses, you can click the respective tabs.
To view the past events, click the Time filter and select the required time period. By default, the time period displays Events for the Last 7 Days.
The Event list view consists of the following columns.
You can click an event to view the details. The detail view window consists of the following tabs.
Summary: The Summary tab displays highlights of the event like the name of the downloaded asset, the name of the violated policy, the email ID of the user who violated the policy, and so on.
Asset: The asset window displays the details of the asset and the history of the asset. You can also choose to view historic asset data. If there are multiple assets in a single violation, you can choose which asset's details must be displayed.
Actor: The actor tab displays the details and history of the user who downloaded the asset. You can choose to view historical data of the user. You can also add which can serve as metadata for the violation.
The events list view displays an ellipsis menu at the extreme right corner. Admins can click this menu to take appropriate action on an exfiltration event.
The various available actions are explained as follows.
Acknowledge: This action can be taken when you just wish to acknowledge that you have viewed the violation.
Notify Email: This action sends an email notification to the end-user who caused the violation.
Notify Slack: This action sends a Slack notification to the end-user who caused the violation.
Suspend Account: This action suspends the account of the user who caused the violation.
Once the action is implemented, the status of the event changes respectively. By default, an event can have one of the following two statuses.
Active: The event has been generated but no action has been taken.
Input Requested: A notification has been sent to the end-user requesting their response.
A step-by-step guide to deploy the Nightfall endpoint agent and the AI-coding-assistant hooks (Claude Code, Cursor, VS Code + GitHub Copilot) to Windows devices using SCCM/MECM.
Client: SCCM Current Branch; SCCM client installed and healthy on target devices; a reachable Distribution Point (DP).
Operating System: Windows 10(22H2 and above)/11 x64 targets (ARM not supported).
Package: From the Endpoint page → navigate to Download package button →
Download NightfallAgent.msi
Copy API Key and Company ID
The agent self-updates (every few hours) — SCCM’s job is a one-time install; don’t manage the version in SCCM (hence the version-agnostic detection in §3).
Claude Code shows a one-time security-consent dialog the first time it loads managed hooks — communicate this to developers. (On some 2.1.x builds /hooks may show “0” even when hooks are active — verify via the Nightfall console or claude --debug, not that count.)
Always "Run as Administrator".
Put the installers on a UNC share the site server and DP can read.
⚠️ Share permissions matter. SCCM’s distribution service reads the source as the site server’s computer account, not your user. Grant Read to
Domain Computers(or the site server’s machine account) on both the share and NTFS — otherwise Distribute Content fails with “cannot access … Win32 error 5 (Access Denied).”
Within SCCM, navigate to: Software Library → Application Management → Applications → Create Application → Manually specify → add a Script Installer deployment type.
Content location: \\<fileserver>\NightfallDeploy\Agent
Installation program:
Install behavior: Install for system · Whether or not a user is logged on · Hidden
Detection method — use a
Then Distribute Content → your DP
Deploy the app Required to your target device collection.
Create one Script Installer application per IDE (VS Code needs two — see below).
Common settings: Install for system · Whether or not a user is logged on · Hidden · Required.
Content location: \\<fileserver>\NightfallDeploy\ClaudeCode
Installation program:
Detection — File System: C:\Program Files\ClaudeCode\managed-settings.d\nightfall-hooks.json exists
Content location: \\<fileserver>\NightfallDeploy\Cursor
Installation program:
Detection — custom PowerShell (Cursor’s hooks.json is shared with other vendors, so existence isn’t enough):
App 1 — hook file:
Content: \\<fileserver>\NightfallDeploy\VSCode
Install:
Detection — File System: C:\ProgramData\Copilot\hooks\nightfall.json exists
App 2 — enterprise policy (Copilot ignores hook files at paths not registered in policy):
Content: \\<fileserver>\NightfallDeploy\VSCode
Install: powershell.exe -NoProfile -ExecutionPolicy Bypass -File .\scripts\windows\install-policy.ps1
Detection — Registry: HKLM\SOFTWARE\Policies\Microsoft\VSCode value chat.hookFilesLocations
On a target device:
Run Machine Policy Retrieval
Navigate to Application Deployment Evaluation (Control Panel → Configuration Manager → Actions), then check:
Confirm the device and per-IDE hook status appear healthy on the Devices page in the Nightfall console.
Nightfall for macOS and Nightfall for Windows OS allow you to configure alerts at the policy level and also at the integration level.
You can navigate to the alerts page by executing the following steps:
Click Integrations in the left pane.
Click Manage for either Endpoint macOS or Endpoint Windows widget.
The Exfiltration policies for MAC and Windows OS allow you to monitor if there are any uploads via browser or cloud storage apps. You can configure the domains in Internet that needs to be monitored and also the cloud storage apps which need to be monitored.
When there are any uploads to the configured domain or cloud storage apps, the Nightfall AI agent notifies this action. You can configure the notification channels through which you wish to receive notifications when there is an attempt to upload files/folders.
Once you have completed the installation of the Nightfall agent, you must ensure that the connection is live. If the Nightfall agent cannot connect to the macOS or the Windows OS device for more than 6 hours, the connection is lost. When the connection is live, a Connected message is displayed. If the connection is lost, a Disconnected message is displayed under the Agent Status column.
When a macOS or Windows OS device is disconnected, you can remove the device from the monitored list (Devices tab). To remove a disconnected device from the monitored list, click the delete icon for the respective device.
Clicking the delete icon displays a warning pop-up window as shown in the following image. Click
Nightfall’s removable media controls allow you to monitor or block sensitive data exfiltration to external storage devices such as USB drives and external HDD/SSD. Policies are evaluated at the endpoint and can be scoped with device type, vendor, and serial number filters for precise enforcement.
Out of the box, Nightfall supports ~1,200 removable media vendors, enabling immediate coverage without manual vendor onboarding.
Nightfall detects and can block the following removable media categories:
USB storage devices (thumb drives, external HDD/SSD)
These are internally represented as removable media types and can be included or excluded in the policy configuration.
How Removable Media Policies Work
A removable media policy is evaluated using three layers of filters:
CLI Transfer watches file movement started by selected command-line tools on a managed endpoint. The agent intercepts the process (for example scp or curl) when it uploads or downloads a file. You pick the tools on the policy. Nightfall does not treat every shell command as this trigger.
This is not Git Push. git push is a separate trigger (Git Push to). CLI Transfer is for the tools listed below.
Domain collections are not used as a destination list for this trigger. You do not pick domains or apps. You pick CLI tools. Data Source (asset origin) is still available, the same as on Browser Upload.
If you do not see CLI Transfer in the For dropdown, ask your Nightfall account team to enable it.
What you configure
This stage allows you to select automated notification channels or actions if a policy violation occurs.
This section allows you to send notifications to Nightfall users. The various alert methods are as follows. You must first turn on the toggle switch to use an alert method.
The steps to configure alert channels for policy-level integration are the same as in the case of integration-level alerts. You can refer to the document.
Automated actions allow you to configure automated remediation actions when an exfiltration attempt is detected by Nightfall policy. Nightfall supports the following automated actions for Salesforce. You can choose to implement the automated action immediately after detecting a download attempt or after some time.
To enable the automated action, you must turn on the respective toggle switch.
This action logs out the user from the Salesforce account. They cannot login until a Salesforce admin revokes the freeze on the account.
You must now select when exactly after detecting the event, the action must be triggered. if you select the Immediately option, the automated action is triggered immediately after the download attempt is made.
Claude Cowork can't run Nightfall hooks, so it's monitored through Anthropic's built-in OpenTelemetry (OTel) integration instead. You configure it once from the Anthropic admin console — not per device or per user — and it captures prompts, tool calls, file access, and session metadata across every Team / Enterprise seat.
OTel is monitor-only: it reports on activity after it happens and cannot block. For how it compares to hooks, see Hooks vs. OpenTelemetry.
1. Copy your OTLP values from Nightfall
In the Nightfall console, open AI Agent Security → AI Agent Security Setup and select the OpenTelemetry tab. Nightfall generates three values scoped to your organization — use Copy all values to grab them together:
User performing the push
Device
Endpoint hostname
Destination URL
Git remote URL
Git Remotes
origin, personal, etc.
Risk
Critical, High, Medium, Low
CLI Transfer
Browser attach
Browser uploads to
CLI Transfer
All Bluetooth pairing
Not available as a trigger














OTLP Endpoint
An HTTPS URL for your environment, e.g. https://<your-nightfall-otel-host>/es/otel/…
OTLP Protocol
http/json
OTLP Headers
X-Nightfall-Company-Identifier=<company-id>,Authorization=Bearer <token>
Copy each value exactly as shown — the endpoint host and the headers are specific to your organization and environment.
2. Paste them into the Anthropic console
Sign in to console.anthropic.com as an organization owner. (You can use Open Anthropic console on the OpenTelemetry tab to jump straight there.)
Open Organization Settings → Cowork → Observability.
Paste the endpoint, protocol, and headers you copied from Nightfall.
Save.
3. Verify the connection
Back on the OpenTelemetry tab in Nightfall, the collector status card starts as "OTEL collector not yet connected · Not configured." Once Cowork sends its first telemetry — usually after the next Cowork session — the status flips to connected, and Claude Cowork appears as an active client on the Devices page.
What Cowork OTel captures
Across every Team / Enterprise seat, with no per-device install:
Prompts and session metadata
Tool calls and file access
Model name, token usage, and cost
API errors and retries
Capturing full prompt text and tool input/output (rather than metadata only) depends on Anthropic's OTel logging options being enabled for your organization — see Hooks vs. OpenTelemetry and Anthropic's Cowork monitoring docs.
The OTLP Headers value contains a bearer token that authenticates your organization's telemetry. Treat it like a secret — copy it directly from the console into Anthropic, and don't paste it into tickets, chat, or screenshots.
Deployment runs in System context (SCCM default).
\\<fileserver>\NightfallDeploy\
├── Agent\NightfallAgent.msi
├── ClaudeCode\ (payloads\ + scripts\windows\ from the Claude Code package)
├── Cursor\ (payloads\ + scripts\windows\ from the Cursor package)
└── VSCode\ (payloads\ + scripts\windows\ from the VS Code package)msiexec /i "NightfallAgent.msi" API_KEY="<YOUR_API_KEY>" COMPANY_ID="<YOUR_COMPANY_ID>" INSTALL_NF_DRIVER="1" /qnpowershell.exe -NoProfile -ExecutionPolicy Bypass -Command "New-Item -ItemType Directory -Force 'C:\Nightfall\Hooks\claude-code' | Out-Null; Copy-Item -Force '.\payloads\nightfall-hooks.json' 'C:\Nightfall\Hooks\claude-code\'; & '.\scripts\windows\install.ps1'"powershell.exe -NoProfile -ExecutionPolicy Bypass -Command "New-Item -ItemType Directory -Force 'C:\Nightfall\Hooks\cursor' | Out-Null; Copy-Item -Force '.\payloads\hooks.json' 'C:\Nightfall\Hooks\cursor\'; & '.\scripts\windows\install.ps1'"$f = 'C:\ProgramData\Cursor\hooks.json'
if ((Test-Path $f) -and (Select-String -Path $f -Pattern 'nightfall-hook-relay --source cursor' -Quiet)) { Write-Output 'Installed' }powershell.exe -NoProfile -ExecutionPolicy Bypass -Command "New-Item -ItemType Directory -Force 'C:\Nightfall\Hooks\vscode' | Out-Null; Copy-Item -Force '.\payloads\nightfall.json' 'C:\Nightfall\Hooks\vscode\'; & '.\scripts\windows\install.ps1'"Get-Service NightfallAgent # Running
where.exe nightfall-hook-relay # relay on PATH
Test-Path 'C:\Program Files\ClaudeCode\managed-settings.d\nightfall-hooks.json'
Test-Path 'C:\ProgramData\Cursor\hooks.json'
Test-Path 'C:\ProgramData\Copilot\hooks\nightfall.json'
Get-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\VSCode' -Name 'chat.hookFilesLocations' -EA SilentlyContinueif ((Test-Path 'HKLM:\SOFTWARE\NightfallAI\NightfallAgent') -and (Get-Service 'NightfallAgent' -ErrorAction SilentlyContinue)) {
Write-Output 'Installed'
}Click "Next"
Select "Run Once Immediately" > Click "Add"
Click "Save and Publish"
Click Save.
Click Save changes.











Actor
The email ID of the user who downloaded the asset. In some cases, you can also find the name of an app in brackets. This indicates that the app present in your Google Workspace downloaded the asset on behalf of the user. You can find more info in this .
Policy
The name of the policy violated by the event.
Status
THe current status of the event.
Ignore: This action ignored the violation. You can take this action when an event is false positive.
Copy Link: This action is only available on the Asset detail view. You can copy the direct link to the Event with this action.
Event type and asset(s)
The nature of the event (asset download) and the name of the asset that is either downloaded or uploaded.
Location
The location of the asset (Google Drive in this case)
When





Number of days/months since the event occured.
Alerts can be sent in macOS and windows OS policies by using the following alert channels.
Slack
Webhook
Jira Tickets
When you configure alert settings at the integration level, the alert settings apply to all the policies, created for the macOS/Windows OS integration. However, when you configure alert settings specifically for a policy, which is created in the macOS/Windows OS integration, the alert settings are applicable only for that specific policy.
This document explains how to configure alerts at the integration level. To learn about how to configure alerts at the policy level, read this document.
To use Slack as an alert platform, you must first perform the required Slack configurations. You can refer to this document to learn more about how to configure Slack as an Alert platform.
To use Webhook as an alert platform, you must first perform the required Webhook configurations. You can refer to this document to learn more about how to configure Webhook as an Alert platform.
To use JIRA as an alert platform, you must have the DLP for the JIRA app installed from the Atlassian Marketplace. You can read more about the DLP for JIRA integration here.
You can configure alerts at the integration level once you have installed the Nightfall for macOS/ Nightfall for Windows OS integration.
To configure alerts at the integration level:
Navigate to the macOS integration
Scroll down to the Alerting section.
You can configure one or multiple alert channels.
To configure Slack as an alert channel, click + Slack channel.
In the Slack alert channel field, enter the name of the Slack channel in which you wish to receive the alerts.
Click Save.
A confirmation pop-up box is displayed to confirm if the Slack channel (entered in the second step) must be used only for macOS integration or all the Nightfall integrations.
Select No, only integration level to use the Slack channel only for macOS, or select Yes, please to use the selected Slack channel for all the Nightfall integrations.
Click + Email.
Enter the Email ID of the recipient who should receive the notifications.
Click Save.
A confirmation pop-up box is displayed to confirm if the Email ID (entered in the second step) must be used only for macOS integration or all the Nightfall integrations.
Select No, only integration level to use the Slack channel only for macOS, or select Yes, please to use the selected email address for all the Nightfall integrations.
Click + Webhook.
Enter the Webhook URL.
Click Test. If the test result is not successful, check the Webhook URL.
(Optional) Click Add Header to add headers.
Click Save.
Click + Jira Ticket.
Select a JIRA project from the Jira Project drop-down menu.
Select an issue type from the Issue Type drop-down menu.
(Optional) Add comments to be added in the JIRA ticket.
Click Save changes.
A confirmation pop-up box is displayed to confirm if the JIRA settings configured for the macOS integration must be applied to all the other Nightfall integrations too.
Select No, only integration level to use the configurations only for macOS, or select Yes, please to use the selected JIRA configurations for all the Nightfall integrations.
When a Violation occurs, Nightfall sends a notification to the end-user whose actions triggered the violation. While notifying the end-user, Nightfall also sends a text message. You can draft the text message to be sent to the end-user. This message applies to all the policies. Click Save changes once done.
If a removed device reconnects, it is automatically added to the monitored list. To permanently prevent the monitoring of a device, you must de-provision the device through MDM (uninstall the Nightfall Agents and remove it from future targeting).
This feature declutters your monitoring list and ensures that only active devices that are being monitored are displayed.
You can leverage this feature efficiently with loaner laptops. When a former employee returns a device, the connection is lost and the status is displayed as disconnected. Security teams can be concerned about the device displaying the Disconnected status for a prolonged period and can initiate an investigation. Instead, you can use this feature and remove the device from the monitored list. When the device is reassigned to another employee, it connects back automatically, and the monitoring resumes.
Similarly, you can use this feature for seasonal and dormant devices; remove them once they are not in use. They will connect back automatically once they are in use again.
Collections help you refine your monitoring to reduce noise from sanctioned upload destinations as well as closely monitor exfiltration of files originating from high-value SaaS applications accessed through the browser. You can also define specific domain collections to closely monitor upload activity to specific categories of upload destinations. For instance, to track files uploaded to social media, you can create a domain collection called social media and add domains like Facebook, Instagram, Twitter, and so on. Similarly, you create a collection for known and sanctioned upload destinations that are safe to upload to so you can ignore them from your monitoring policies or monitor the upload of items originating from such domains. While creating a policy, you can directly add the collection to be monitored. All the domains in the collection will be monitored.
You can create a domain by either manually entering all the domain URLs manually or by uploading a comma-delimited list of domains in a text file.
To group domains:
Log in to the Nightfall app.
Navigate to Integrations from the left menu.
Click Manage on the macOS/Windows OS integration.
Click the Domains tab.
Click + New Collection.
You can either add the domains manually or upload a text file containing the list of domains. The following section has two tabs. The first explains the process of manually adding domains, and the second tab explains adding domains by uploading a file.
Click + Add Domain.
Enter a name for the Collection in the Collection Name field (Social Media in the following image)
Enter a domain and hit the enter key (facebook.com in the following image).
(Optional) Click + Add Domain to add multiple domains to the collection.
(Optional) Click the delete icon to delete a domain.
Click Save Changes.
Enter a name for the Collection in the Collection Name field.
Click Upload.
Browse and upload the text file containing the list of domains.
Once you upload the file, the list of domains present in the file are displayed as follows.
The detailed steps to configure the MAC OS/Windows OS device exfiltration policy are explained in the following documents.


Origin - Where the content originated from
Destination Removable Media Filters - Which removable devices the rule applies to
Content Detection - Whether sensitive data is present
Endpoint Device - Which devices are included or excluded in the policy
If all conditions match, the configured enforcement (Monitor or Block) is applied.
Policy configuration:
Step 1 - To apply a policy to removable devices:
Set Action to “To removable media”
This ensures the rule only evaluates file transfers where data is being written to an external device.
Step 2 - Removable media filters
Removable media filters allow you to precisely control which removable devices are included in enforcement.
Device Type
Monitor all – Applies to all removable media types
Specific types – Limit enforcement to selected media types (USB, HDD/SSD)
Once a removable media action and device match, Nightfall evaluates the content being transferred:
Sensitive data types (PII, credentials, secrets, etc.), file classifiers or any other applicable detectors in the configured detection rules
If sensitive content is detected, enforcement is applied. Each policy can be configured to:
Monitor – Log the event for visibility and auditing
Block – Prevent the transfer to removable media
Both modes can be enabled simultaneously to provide audit visibility even when blocking.
Common Configuration Examples
Example 1: Block All USB Devices
Action: To removable media
Device Type: USB
Vendor: Monitor all
Serial Number: Monitor all
Enforcement: Block
Example 2: Allow Only Approved Vendors
Action: To removable media
Vendor: Specific vendor(s)
Enforcement: Block
Example 3: Allow Only Specific Devices
Action: To removable media
Serial Number: Specific serial numbers
Enforcement: Block
Example 4: Exclude Corporate USB Drives
Action: To removable media
Vendor: All vendors
Serial Number: All serial numbers except
For exfiltration events involving removable media, Nightfall surfaces additional asset-level metadata to help security teams understand where data was written and which physical device was involved.
In the Asset details panel, you can expect the following removable media–specific fields:
Medium – Indicates the destination medium as Removable Media
Mount Path – The local mount location of the device on the endpoint (for example, /Volumes/My USB Device on macOS)
Volume Label – The human-readable label assigned to the removable device
Media Type – The category of removable media (for example, USB, HDD/SSD)
Vendor ID – The hardware vendor identifier reported by the operating system
Serial Number – The device’s unique serial number, when available
These fields are available only for removable media events and enable precise investigations, device allowlisting, and policy tuning.
All other event information - including user identity, endpoint details, timestamps, policy action, file preview, activity log and risk context, manual actions - is consistent with other Endpoint Exfiltration events and is available in the Summary and Device tabs.
In the policy wizard, set For to CLI Transfer.
Under CLI Tools, select at least one tool. Next stays disabled until you do.
Optional: set Data Source / asset origin if you only care about files that came from certain apps or domains.
Content scanning and detection rules apply. You can Monitor or Block. Block copy in the product: This will block file transfers that match this policy.
End-user notification and screen replay follow the same endpoint rules as other triggers, when those options are on for your tenant.
CLI tools you can select
scp
Copy files over SSH
curl
HTTP(S) upload or download
wget
sftp and ssh are not available in the CLI Tools picker.
Windows notes for wget and rsync
These two cannot be enforced on Windows:
rsync has no native Windows binary the agent can intercept.
PowerShell wget is an alias for in-process Invoke-WebRequest, so the agent never sees a process-create event.
Behavior in the picker:
Windows-only policy: wget and rsync are disabled. Tooltip: {tool} cannot be enforced on Windows endpoints, so it is unavailable for Windows-only policies. If an older policy still had them saved, Nightfall strips them on edit.
macOS and Windows together: wget and rsync stay selectable, with an amber warning. Tooltip: {tool} applies to macOS endpoints only. It cannot be enforced on the Windows endpoints in this policy's scope.
macOS only: all six tools are available.
scp, curl, aws s3, and npm have no Windows restriction in the wizard.
What shows up on an event
Events are labeled CLI Transfer. The agent records both file upload and file download through the selected tools.
Typical fields: tool, command, remote host, remote path, parent process, execution source, file name, local path, size, and hash when available.
Execution source values you may see:
User Terminal
AI Agent Subprocess
Other
Common use cases
Stop engineers from scp or rsync of customer exports to a home machine.
Catch curl or aws s3 of a secrets file to an unmanaged bucket.
Watch npm publish from a laptop that is not supposed to ship internal packages.
Pair with Git Push if you care about both git push and raw file copy over SSH.
Policy recommendations
Start with scp, curl, and aws s3. Add wget/rsync only if you have macOS in scope.
Do not rely on CLI Transfer for git push. Use Git Push to.
If you also run AI agents that shell out to curl, look at Execution Source AI Agent Subprocess on the event.
How this differs from nearby triggers
git push to a personal remote
Git Push to
File copied to a USB stick
To removable media
File attached in Chrome
Which tools does CLI Transfer cover?
Only the tools you check: scp, curl, wget, rsync, aws s3, npm. Other binaries are out of scope, even if they move files.
Why are wget and rsync greyed out?
The policy is Windows-only. Those tools cannot be enforced on Windows. Use a macOS (or mixed) OS scope, or drop those two tools.
Why is there an amber warning on wget or rsync?
The policy includes Windows and macOS. Those tools still apply on Mac. They will not apply on the Windows devices in the same policy.
Why can't I click Next?
You have not selected a CLI tool. Select at least one.
Does this monitor every command in Terminal?
No. Only the selected tools, when they transfer a file.
Is this the same as Git Push?
No. Git Push evaluates git remotes and is monitor-only. CLI Transfer evaluates scp/curl/and the rest, and can block.
Can I limit destinations (only certain hosts)?
Not in this trigger. There is no domain or host allowlist on CLI Transfer. Scope by OS, users, devices, optional asset origin, and tool list.
Does Block actually stop the transfer?
Yes, when you enable the block action on this trigger. The confirm text is about blocking file transfers that match the policy.
Do I need a browser extension?
No. This is endpoint-agent interception of the CLI process.
If you select the After option, you must select the time gap after which the automated action must be implemented.
This action revokes the permissions of the user. The user can now only view data across al Salesforce pages. They cannot download any data. This action assigns the user Salesforce's minimum access profile. You can learn more about this profile from this Salesforce document.
You must now select when exactly after detecting the event, the action must be triggered. if you select the Immediately option, the automated action is triggered immediately after the download attempt is made.
If you select the After option, you must select the time gap after which the automated action must be implemented.
This section allows you to configure notifications to be sent to the end user whose actions triggered the violation.
Enter a custom message to be sent to the end user. This message is sent in an Email. You can modify the default message provided by Nightfall and draft your message. The total character length allowed is 1000 characters. You can also add hyperlinks in the custom message. The syntax is <link | text >. For example, to hyperlink www.nightfall.ai with the text Nightfall website, you must write <www.nightfall.ai|Nightfall website>.
The automation settings allow you to send notifications to end users. You can select one or both the notification methods. You must first turn on the toggle switch to use the automation option. The automation notification channels are as follows
Email: This option sends an Email to the user who attempted the download.
Slack: This option sends a Slack message to the user who attempted the download.
End-user remediation (also known as Human Firewall) allows you to configure remediation measures that end users can take, when a violation is detected on by their download attempt. You must turn on the toggle switch to use this option. End-users receive the remediation actions in an Email as an action item. The various available remediation actions for end-users are as follows.
Report as False Positive with Business Justification: This option allows end users to report false positive alerts and provide a business justification as to why the alert is considered to be false positive.
When end-users report alerts as false positive, you can choose the resolution method to be either Automatic or manual.
If end-users do not take any remediation action, you can set the frequency at which they must receive the notifications to take action.

This document explains the process of installing the Nightfall agent manually.
Ensure that you have root level access to the target macOS device.
On your Nightfall console, navigate to https://app.nightfall.ai/endpoint and click the Download Package button on the top right corner of the page. Click Download Package for macOS and unpack the contents of the downloaded file.
Create a default policy for web browser uploads and cloud storage application sync.
Locate the mdm_pre_installation_script.sh in the payload downloaded from Nightfall.
Open a Terminal window.
Run the mdm_pre_installation_script.shscript on your local machine as a root user, by executing the following command.
Double click the provided nightfall-ai-agent_<version>.pkg.
Click Continue.
Click Install.
Click Use Password to enter your device password and start the installation process.
Once the installation is completed, you get a completion message as shown in the following image.
Click Close.
At the top right corner of your screen, you can view the Nightfall AI agent icon which looks as follows.
When you click this icon, you can view the details of the agent.
These system permissions and handled automatically through MDM profiles. For manual install, enabling these permissions manually is required.
To monitor your MAC device, you must grant access to the hard disk. This section explains the process of granting disk access.
Navigate to System Settings > Privacy & Security > Full Disk Access.
If Nightfall is listed, make sure to toggle the permission to ON
[Optional] Should Nightfall not be listed in the primary list
Click the + icon at the bottom of the list (you may be prompted to enter your macOS password)
Select NightfallAIAgent (under Applications) and click Open.
Click Quit & Reopen.
On the Full Disk Access page, ensure that the toggle switch is turned on for the NightfallAIAgent. This ensures that the full disk access is granted.
For clipboard monitoring, you must grant the Nightfall agent accessibility permissions. This section explains the process.
Navigate to System Settings > Privacy & Security > Accessibility.
If Nightfall is listed, make sure to toggle the permission to ON
[Optional] If Nightfall is not listed in the primary list
Click the + icon at the bottom of the list (you may be prompted to enter your macOS password)
b. Select NightfallAIAgent (under Applications) and click Open.
c. On the Accessibility settings page, ensure that the toggle switch is turned on for the NightfallAIAgent. This ensures that the full disk access is granted.
To ensure changes are picked up by the agent:
Open Activity Monitor > Search of Nightfall > you should see two Nightfall processes running
If you do not see two Nightfall processes, make sure to expand your view to all processes
Select both process and click Quit, the agent will restart instantly.
Apart from the disk access and accessibility permissions, you must also grant permission to the Nightfall AI agent to monitor browser uploads. This section explains the process.
To grant access to browser uploads:
Open a browser instance and upload a test file to any destination.
When prompted, grant the Nightfall AI agent permissions.
Nightfall delivers broad browser coverage with full data exfiltration protection across modern AI browsers and traditional browsers. Customers can confidently deploy Nightfall across supported environments without compromising on security or feature depth.
AI Browsers
Perplexity Comet (macOS only)
ChatGPT Atlas (macOS only)
Chromium-Based Browsers
Google Chrome
Microsoft Edge
Arc
Brave
Other Browsers
Firefox
Operating System Support
macOS - The following browsers are supported on macOS:
Chrome
Edge
Firefox
To uninstall the Nightfall AI agent, locate the uninstallation script provided as part of the deployment bundle. You must execute the following command on your MAC device, as a root user.
This guide provides instructions for deploying the Nightfall AI Endpoint Agent to macOS devices via JumpCloud MDM using the mdm_jumpcloud_deploy.sh script.
The script is an all-in-one solution that handles config provisioning, installation, and ongoing health monitoring. When scheduled as a recurring JumpCloud command, it ensures the agent stays installed and running without manual intervention.
Before you begin, ensure you have:
JumpCloud admin access with macOS devices enrolled
A JumpCloud device group scoped to the macOS devices you want to monitor
Deployment assets:
Configuration Profile: NightfallAI_Profile_with_Browser_Extensions.mobileconfig
Deployment script: mdm_jumpcloud_deploy.sh
Installer package: nightfall-ai-agent-signed.pkg
Note: The Nightfall agent will only install correctly if the required
.mobileconfigprofile has been deployed beforehand.
Log in to app.nightfall.ai and navigate to Settings > MDM Profile.
Select JumpCloud from the list of supported MDM providers.
Complete the OAuth flow to grant Nightfall read-only access to your JumpCloud device and user directory. This maps JumpCloud user identities to devices in the Nightfall console automatically.
In JumpCloud Admin Portal, navigate to Device Management → Policy Management.
Create a new MDM Custom Configuration Profile.
Click the + button → select Mac tab → select MDM Custom Configuration Profile > click Configure
In JumpCloud Admin Console, navigate to Device Management → Commands → + Command → Command.
Type: Mac
Paste the contents of mac_bundle folder → mdm_scripts folder →mdm_jumpcloud_deploy.sh as the command body.
Save and run by pressing Run Now.
JumpCloud console: Check Commands → Results for the command's exit code and output after execution.
Verify the agent is running:
Open Activity Monitor → CPU and search for "Nightfall". Two processes should be running — one as root (daemon) and one as the logged-in user (agent).
To remove the Nightfall agent from devices, run mdm_nightfall_ai_agent_uninstall.sh as a one-time JumpCloud command:
Create a new Command in JumpCloud.
Paste the contents of mdm_nightfall_ai_agent_uninstall.sh as the command body.
Assign to the target devices and run.
This document explains the process of installing Nightfall AI agent using the Rippling MDM.
Please note there are two parts to this process:
Deploy the "mobileconfig" that pushes the profile and permissions.
Step 1 - Create & Deploy Profiles
Deploy the agent via the .PKG and scripts.
Step 2.1 -
Step 2.2 - Deploy the Nightfall Endpoint DLP Agent
Confirm the following:
The macOS devices are onboarded.
Download the package from the console:
On your Nightfall console, navigate to
Click Download Package for macOS
After confirming, move to "Step 1" as shown below.
In this step, you will create a custom profile for each of the profiles provided in your Nightfall endpoint payload.
Locate NightfallAI_Profile_with_Browser_Extensions.mobileconfig in the downloaded Nightfall Endpoint payload package.
Navigate to and click Upload.
The below describes the steps to upgrade endpoints with a new version of the agent:
Search or scroll to the old version of the Nightfall Endpoint DLP Agent and click “Edit”.
a. Remove all devices from the installation list and click “Save”.
Follow the to configure the new software package for the new version
Follow to deploy the new version.
The Nightfall Endpoint DLP Agent will now deploy to all selected target endpoints. Installation may take up to 48 hours and is dependent on the endpoint devices being turned on and connected.
Learn how to install the Nightfall Agent for Windows using Intune as a Line-of-Business (LOB) app.
The Microsoft Intune installation consists of the following steps:
Connect Microsoft Intune to Nightfall (API-based MDM Onboarding)
Deploy the Nightfall Agent via Intune
You are a Systems Administrator in Nightfall
You must have access to Microsoft Intune with the necessary admin privileges. An Intune administrator account with permission to approve OAuth access
Get the .msi package and command arguments form
Download the .msi installer file for the Nightfall Agent.
Note the API Key and Company ID in the command line provided by Nightfall.
This step enables automated mapping of user profiles to devices without requiring manual scripts.
API-based MDM onboarding allows Nightfall to automatically map the user email attribute to specific devices by syncing device inventory from your Microsoft Intune tenant using OAuth-based authentication.
Log in to the Nightfall Console at
Navigate to Settings - MDM Profile
Click Add MDM
Select Microsoft Intune from the list of supported MDM providers
Once authentication is complete, Nightfall will automatically connect to your Intune tenant and begin syncing device data.
Important: This API-based connection enables Nightfall to automatically map user email addresses to devices. You do not need to deploy any additional scripts for user-to-device mapping when using this method.
Nightfall requests the following Microsoft Graph API permissions:
DeviceManagementManagedDevices.Read.All - Read managed device information
User.Read.All - Read user profiles
Organization.Read.All - Read basic organization details
These are read-only permissions. Nightfall does not modify device settings or configurations.
Once connected, Nightfall will periodically sync device inventory from Microsoft Intune. You can now proceed to deploy the Nightfall agent to your devices following the steps below.
Log into the Intune Admin Center
Navigate to .
Go to: Home > Apps > All Apps > Add
Do I still need to install a Nightfall agent on devices after API-based onboarding?
Yes. API-based MDM onboarding enables Nightfall to map user email addresses to devices automatically. You still need to deploy the Nightfall agent to the devices using the steps above.
What permissions does Nightfall need in Microsoft Intune?
Nightfall requires least privilege read-only access to device inventory and user information via Microsoft Graph API. It does not modify device settings or configurations. The user email to device attribution is automatically managed with API-based MDM onboarding and no manual scripts are needed.
Is OAuth-based authentication secure?
Yes. Nightfall uses Microsoft's OAuth 2.0 authentication flow with encrypted connections. Credentials are securely stored and refreshed automatically.
What happens if OAuth permissions are revoked?
If OAuth permissions are revoked:
Device syncing will stop. New devices added or removed will not be reflected in Nightfall during that time.
Nightfall will surface an error in the console.
You can re-authenticate without reconfiguring policies by reconnecting from Settings → MDM Profile.
Can I disconnect or change my MDM connection later?
Yes. Contact Nightfall Support to disconnect or update your MDM connection from Settings → MDM Profile.
What device types are supported with Intune?
Microsoft Intune supports both Windows and macOS devices. Nightfall will sync inventory for both device types when connected via API-based onboarding.
Who should I contact if onboarding fails?
If you encounter issues:
Verify you have admin permissions in Microsoft Intune
Check the error message in the Nightfall console
Ensure you approved all requested OAuth permissions
Contact Nightfall Support for assistance
When Personal accounts only or Corporate accounts only is enabled, Nightfall uses the browser session to decide whether an event is in-scope. On supported domains, that usually means: the Nightfall browser extension reads the signed-in email, and Nightfall compares the email domain against your Corporate Domains collection.
Sometimes the session cannot be determined. Common causes:
The user is not signed in
The browser is in incognito / private mode
The Nightfall browser extension is missing, disabled, or disconnected
The site is loading and no logged-in identity is available yet
Unknown session behavior controls what the policy does in that case. It only applies to supported domains (hover the violet Supported domains pill to see the list). Domains that do not support session detection continue to be monitored for all account types, regardless of this setting.
This control appears under the session-check toggle on the policy Trigger step.
Use this when the policy should fire only on uploads, pastes, or git pushes into a personal account.
Use this when the policy should fire only on data that originated in a corporate account. The default is inverted: skipping unknown sessions means treating them as not corporate.
Recommended default: skip the incident when the session cannot be determined. This is the setting shown as Treat as corporate - skip incident on personal-account destination policies. It reduces false positives when Nightfall cannot read the signed-in user, while still enforcing the policy whenever the session is known to be personal.
The toggle copy in the console is:
Only tracks data sent to personal account sessions for Supported domains. Remaining domains monitored for all account types.
That means:
Supported domain + known personal session → personal-account policy can create an incident
Supported domain + known corporate session → personal-account policy skips
Supported domain + unknown session → follows the radio option above
Unsupported domain → session check is not applied; the event is evaluated like any other destination/source match
Unsupported domains are not skipped just because unknown-session behavior is set to skip. They are monitored for all account types.
An Endpoint Exfiltration policy with Browser uploads to, Paste to (browser), or Git Push to
At least one selected collection that includes session-detection-supported domains
Nightfall browser extension installed, enabled, and connected on the device
Nightfall Agent macOS v1.2.13+ or
After saving the policy:
Confirm the session toggle is On and the expected radio option is selected
Hover Supported domains and confirm the destinations you care about are listed
On a test device, sign into a personal account on a supported domain and confirm an incident is created
Sign into a corporate account on the same domain and confirm the personal-account policy does
If the destination is a supported domain and the session could not be determined, the default (Treat as corporate - skip incident) intentionally does not create an incident. Check whether the user was signed in, whether the extension was connected, and whether the browser was in incognito.
That is expected. Unknown-session behavior only applies to supported domains. Remaining domains in the collection are monitored for all account types.
On a Personal accounts only policy, yes for supported domains: unknown and corporate sessions are out of scope. The file may still match a different policy that does not use session detection.
The policy is configured to Create incident - mark account as unknown. Nightfall created the incident because the session could not be resolved, not because it confirmed a personal or corporate account.
The extension typically cannot read the signed-in user in private windows. Those events are unknown-session events and follow this setting.
This document explains what admins can do when a macOS policy is violated.
Nightfall admins can manage violations from within the Nightfall console. The Events page in Nightfall lists all the violations under the Exfiltration tab. End-users can get a detailed view of each exfiltration violation recorded.
To view violations in Nightfall
Navigate to Exfiltration Prevention from the left menu.
Steps 2-6 help you filter the events to only view the alerts generated by macOS.
Click Filter.
Click + Add Filter.
Select Integration.
Select the macOS check box.
Click Apply.
Select Integration.
Select the macOS check box.
Select Integration.
Select the macOS check box.
Click Apply.
You can click an event to view the details. The detail view window consists of the following tabs.
The Summary tab consists of the following details.
Assets: The name of the uploaded asset(s) that was exfiltrated.
Policy: The name of the policy violated.
Device ID: The device ID of the device from which the asset was uploaded.
Machine Name: The physical name of the device from which the asset was uploaded.
App Name: The name of the cloud storage app to which the asset containing sensitive data was uploaded. This field is applicable only for uploads done to cloud storage apps.
Account Type: The nature of the cloud storage app to which the asset was uploaded. The account type is generally either a personal account or a business account. This field is applicable only for uploads done to cloud storage apps.
Account type: Personal → when a personal session is detected
The Summary tab for a Browser upload action is as follows.
The Summary tab for a Cloud storage app event is as follows.
The Summary tab for a Clipboard Paste action is as follows.
The Summary tab also displays a log of activities that occurred on the event. The Summary tab also displays a log of activities that occurred on the event. The first log entry is always the asset creation date. The subsequent logs display the actions applied to the event. You can also add comments on the Summary tab. The comments added by you can be viewed by other users as well.
This tab displays the details of the asset that was uploaded to a domain or cloud storage app. The asset tab also displays a number in brackets. This number indicates the number of assets that were uploaded as part of the event.
In the following image, there are two assets that were uploaded, and these four uploads together triggered the event. In such cases when there are multiple assets involved, you can use the drop-down menu to switch between assets and view the asset details.
The Assets tab displays the following details for the Browser upload action and the Cloud Storage app action.
Name: The name of the asset uploaded.
Where: The location of the asset in the device.
Medium: The medium used to upload the asset. This can be a browser or cloud storage app.
Size: The size of the asset.
The Assets tab also contains the Asset History section. This section displays the source or origin from where the asset was downloaded. Additionally, it also displays the destinations to which the asset was uploaded. If the source and destination details are not available, this section does not display any information. Users can use the time filter to view historic data. By default, the asset history is displayed for the last 7 days. You can click the Last 7 Days drop-down menu to view historic asset details.
The assets tab for the copy/paste action displays the following information.
Content Origin: The site from which the data was copied. If Nightfall cannot find the origin, this field displays Local Machine (Unknown origin).
Content Destination: The location where the copied information was pasted.
Time of Copy: The date and time when the data was copied.
Time of Paste
If the copy/pasted content contains sensitive data, the asset tab displays the sensitive data and also the text surrounding the sensitive data. The sensitive data is highlighted so that it can be recognized easily.
The asset history section displays the timeline and the number of times data was copied and pasted.
The device tab displays the details of the device used to upload the asset. You can view the following details on this tab.
Device ID: The device ID of the device from which the asset was uploaded.
Device Name: The name of the device from which the asset was uploaded.
Connection Status: The current status of the device. This can either be Connected or Disconnected. If the device is not in contact with the Nightfall agent for more than 6 hours, the connection status changes to disconnected.
You can perform the following actions on all three tabs. These actions are present at the bottom.
Copy Event Link: This action copies the link of the event to the clipboard.
Acknowledge: This action modifies the status of the event to Acknowledged.
Notify Slack: This action sends a Slack notification about the event to the recipient configured in the section.
Notify Email: This action sends an email notification about the event to the recipient configured in the
Nightfall Exfiltration prevention for Salesforce allows you to configure alerts at the policy level and also at the integration level. Alerts can be sent in Salesforce by using the following alert channels.
Slack
Webhook
Jira Tickets
When you configure alert settings at the integration level, the alert settings apply to all the policies, created for the Salesforce integration. However, when you configure alert settings specifically for a policy, which is created in the Salesforce integration, the alert settings are applicable only for that specific policy.
This document explains how to configure alerts at the integration level. To learn about how to configure alerts at the policy level, read .
To use Slack as an alert platform, you must first perform the required Slack configurations. You can refer to to learn more about how to configure Slack as an Alert platform.
To use Webhook as an alert platform, you must first perform the required Webhook configurations. You can refer to to learn more about how to configure Webhook as an Alert platform.
To use JIRA as an alert platform, you must have the DLP for the JIRA app installed from the . You can read more about the DLP for JIRA integration .
You can configure alerts at the integration level once you have installed the Nightfall for Salesforce integration.
To configure alerts at the integration level:
Navigate to the Salesforce integration
Scroll down to the Alerting section.
You can configure one or multiple alert channels.
To configure Slack as an alert channel, click + Slack channel.
In the Slack alert channel field, enter the name of the Slack channel in which you wish to receive the alerts.
Click Save.
A confirmation pop-up box is displayed to confirm if the Slack channel (entered in the second step) must be used only for Salesforce integration or all the Nightfall integrations.
Select No, only integration level to use the Slack channel only for Salesforce, or select Yes, please to use the selected Slack channel for all the Nightfall integrations.
Click + Email.
Enter the Email ID of the recipient who should receive the notifications.
Click Save.
A confirmation pop-up box is displayed to confirm if the Email ID (entered in the second step) must be used only for Salesforce integration or all the Nightfall integrations.
Select No, only integration level to use the Slack channel only for Salesforce, or select Yes, please to use the selected Slack channel for all the Nightfall integrations.
Click + Webhook.
Enter the Webhook URL.
Click Test. If the test result is not successful, check the Webhook URL.
(Optional) Click Add Header to add headers.
Click + Jira Ticket.
Select a JIRA project from the Jira Project drop-down menu.
Select an issue type from the Issue Type drop-down menu.
(Optional) Add comments to be added in the JIRA ticket.
A confirmation pop-up box is displayed to confirm if the JIRA settings configured for the Salesforce integration must be applied to all the other Nightfall integrations too.
Select No, only integration level to use the configurations only for Salesforce, or select Yes, please to use the selected JIRA configurations for all the Nightfall integrations.
When a Violation occurs, Nightfall sends a notification to the end-user whose actions triggered the violation. While notifying the end-user, Nightfall also sends a text message. You can draft the text message to be sent to the end-user. This message applies to all the policies. Click Save changes once done.
Managing Violations in Nightfall
Nightfall admins can manage violations from within the Nightfall console. The Events page in Nightfall lists all the violations under the Exfiltration tab. End-users can get a detailed view of each exfiltration violation recorded.
To view violations in Nightfall
Navigate to Exfiltration Prevention from the left menu.
Steps 2-6 help you filter the events to only view the alerts generated by Windows OS.
Click Filter.
Click + Add Filter.
Select Integration.
Select the Windows check box.
Click Apply.
You can click an event to view the details. The detail view window consists of the following tabs.
The Summary tab consists of the following details.
Assets: The name of the uploaded asset(s) that was exfiltrated.
Policy: The name of the policy violated.
Device ID: The device ID of the device from which the file upload was performed.
Machine Name: The physical name of the device from which the file upload was performed.
The Summary tab also displays a log of activities that occured on the Event. The first log entry is always the asset creation date. The subsequent logs display the actions applied on the event. You can also add comments on the Summary tab. The comments added by you can be viewed by other users as well.
This tab displays the details of the asset (with sensitive data) that was uploaded to a domain or cloud storage app. The asset tab also displays a number in brackets. This number indicates the number of assets that were uploaded as part of the event.
In the following image, there were two assets which were uploaded, and these four uploads together triggered the event. In such cases when there are multiple assets involved, you can use the drop-down menu to switch between assets and view the asset details.
The Assets tab displays the following details.
Name: The name of the asset uploaded.
Where: The location of the asset in the device.
Medium: The medium used to upload the asset.
User: The username of the device owner.
The Assets tab also contains the Asset History section. This section displays the source or origin from where the asset was downloaded. Additionally, it also displays the destinations to which the asset was uploaded. If the source and destination details are not available, this section does not display any information. Users can use the time filter to view historic data.
The device tab displays the details of the device used to upload the asset. You can view the following details on this tab.
Device ID: The device ID of the device from which the asset was uploaded.
Device Name: The name of the device from which the asset was uploaded.
Connection Status: The current status of the device. This can either be Connected or Disconnected. If the device is not in contact with the Nightfall agent for more than 6 hours, the connection status changes to disconnected.
This document explains what admins and end-users can do once a policy is violated.
When end-users violate a policy, the Nightfall admin is notified about the incident. The notification channel used to notify the Nightfall admin depends on the settings configured in the Admin Alerting section. If you have not enabled any notification channels in the Admin alerting section, Nightfall admins are not notified.
If you have enabled the email notification in the Admin alerts section, Nightfall admins receive an email. The email is as shown in the following image.
The Email consists of the following data.
Event: The event that caused the violation. For Salesforce, the event is always download of assets.
Who: The Email ID of the user who downloaded the file.
When: The date and time when the email was downloaded.
What: The name of the file that was downloaded.
Policies Violated: The name of the policy that was violated.
Violation Dashboard: The link to the Events screen to view the violation in detail.
Actions: The list of actions that the Nightfall admin can take.
Also, a Slack message is sent if you have enabled the Slack alerts for the Nightfall admin.
End-users receive notifications and remediation actions if the Nightfall admin has enabled these settings. The notifications are based on the settings configured in the section. The end-user remediation actions are based on the settings configured in the section.
If you have configured the Email notification for end-users and enabled the end-user remediation, end-users can take remediation actions from the Email itself. The end-user Email is shown in the following image.
If you have configured Slack notifications for end-user and enabled end-user remediation, end-users also get a message in the respective Slack channel configured.
To manage violations in the Nightfall console:
Click Events from the left menu.
Click the Exfiltration tab.
The Exfiltration Events page lists all the exfiltration events. To view events specific to the Salesforce integration:
Click Filters and select + Add Filter.
Select Integration in the Select a filter field.
Select the Salesforce check box in the Select an option field.
Click Apply.
Now, only the Salesforce events are displayed.
To view events with specific statuses, you can click the respective tabs.
To view historic events, click the Time filter and select the required time period.
You can click an event to view the details. The detail view window is as follows.
The detail view window consists of the following tabs.
Summary: The Summary tab displays highlights of the event like the name of the downloaded asset, the name of the violated policy, and the email ID of the user who violated the policy.
Asset: The asset tab displays the details of the asset. You can view details like name of the downloaded asset, size of the downloaded asset, exfiltration action (download), owner's Salesforce ID and IP address. If there are multiple assets in a single violation, you can choose which asset's details must be displayed.
Actor: The actor tab displays the email ID of the Salesforce user who downloaded the asset. You can add notes on this tab which is displayed in the Admin notes section.
The events list view displays an ellipsis menu at the extreme right corner. Admins can click this menu to take appropriate action on an exfiltration event.
The various available actions are explained as follows.
Acknowledge: This action can be taken when you just wish to acknowledge that you have viewed the violation.
Notify Email: This action sends an email notification to the end-user who caused the violation.
Notify Slack: This action sends a Slack notification to the end-user who caused the violation.
Ignore: This action ignored the violation. You can take this action when an event is false positive.
Once the action is implemented, the status of the event changes respectively. By default, an event can have one of the following two statuses.
Active: The event has been generated but no action has been taken.
Input Requested: A notification has been sent to the end-user requesting their response.
When there is a high volume of exfiltration (basically download) in your organization, the scoping capability enables you to reduce the noise from low risk events so that you can zero in on genuine exfiltration events and resolve them.
Exfiltration (Download monitoring) can be scoped to:
Location: All or a specific set of drives
This allows you create flexible policies to monitor all or specific high-risk locations. This is a required scope for all policies.
If an organization is utilizing Google Workspace to deploy extensions to Chrome, two options are provided to deploy the Nightfall extension and avoid conflicts on the machine.
Nightfall typically deploys the extension through common install methods, such as:
macOS: macOS Profile
Windows: MSI and registry key entries
However, some administrators utilize Google Workspace for extension deployment to Chrome. Here are two methods to deploy the Nightfall extension successfully using Google Workspace:
This guide is written for employees - developers, engineers, data scientists, and other end-users - who have been invited to connect their AI tools to the Nightfall MCP Gateway.
Model Context Protocol (MCP) is an open standard developed by Anthropic that allows AI assistants (such as Cursor, Claude, and VS Code) to securely interact with external tools, issue trackers, databases, and APIs. Instead of manually copying and pasting context into chat prompts, MCP allows your AI assistant to query data (like reading pull requests, inspecting Jira/Linear tickets, or searching internal documentation) on your behalf.
The Nightfall MCP Gateway is a centralized, secure bridge between your AI clients and approved enterprise tools (such as GitHub, Linear, Notion, and internal APIs). Instead of having every developer generate personal API keys, configure separate local .json files, and manage individual tokens, the Gateway provides a single setup URL that securely routes and authenticates all approved tool calls through your organization's Single Sign-On (SSO).
Your security team provisioned this gateway to empower you with AI tools while eliminating friction and security risks:
All device types except – Exclude specific device types from enforcement
If no specific type is selected, all removable media types are included by default.
Vendor filtering
Nightfall supports ~1,200 removable media vendors out of the box.
You can configure vendor behavior as follows:
Monitor all vendors (default)
Specific vendor(s) – Apply the rule only to selected vendors
All vendors except – Exclude specific vendors from enforcement
Vendor matching is based on device metadata reported by the operating system.
Example use cases:
Allow corporate-approved encrypted USB vendors
Block unknown or consumer-grade USB brands
Device Serial Number Filtering
Serial number filters provide the most granular level of control.
Options:
Monitor all (default)
Specific serial numbers – Apply enforcement only to listed devices
All serial numbers except – Exclude specific devices from enforcement
Serial numbers are matched exactly as reported by the endpoint OS.
Example use cases:
Allow a small set of approved devices
Exempt forensic or IT-issued USB drives
Filter precedence and evaluation logic
When multiple device filters are configured, Nightfall evaluates them together using the following rules:
Include rules are evaluated first
Exclude rules override include rules
If no include filters are specified, the rule defaults to include all
Practical Implications
If you select Specific vendors, only those vendors are eligible
If you then exclude a serial number, that device will never trigger the policy
If both vendor and serial filters are empty, all removable media is in scope
Corporate-approved devices are excluded from enforcement.
HTTP(S) download (macOS only; see Windows notes)
rsync
Sync files to a remote host (macOS only; see Windows notes)
aws s3
AWS CLI S3 copy / sync
npm
Package publish / fetch that moves files through npm
Browser uploads to
File sent with AirDrop
AirDrop
File sent over Bluetooth
Bluetooth
Browser Name: The name of the browser from which the asset was uploaded.
Domain: The domain URL to which the asset containing sensitive data was uploaded. This field is applicable only for browser uploads. When you hover over a domain that is not added to any Collection, the list of Collections is displayed. You can choose to add the domain to an existing Collection or create a new collection and add the domain to the newly created collection. If you are already leveraging the domain collection as part of your monitoring policies, the new addition will be automatically picked up. For example, if the domain is added to a collection of sanctioned domains your policy is ignoring, future uploads to this destination will be ignored.
Upload Start Time: The start date and start time of the upload.
Upload End Time: The end date and end time of the upload.
Size: The size of the downloaded asset.
MAC Address: The physical MAC address of the device.
Last Connection: The date and time when the device was last connected.
Agent Version: The Nightfall agent version installed on the device.
OS Version: The Windows OS version used on the device.














Freeze User: This action freezes the user account and logs them out of Salesforce. Users cannot login until admin unfreezes their account.
Revoke User Permission: This permission revokes the user's download privileges. Users can only view data in Salesforce. This action assigns the Salesforce's Minimum access profile to the user. You can learn more about this profile from this Salesforce document.
Unfreeze User: Once you freeze a user, this action is active. You can unfreeze a freezed user with this action.

















Policy Name: (Name the new policy)
Mobile Configuration File: Click the upload file button
From mac_bundle → profiles → select NightfallAI_Profile_with_Browser_Extensions.mobileconfig
(Optional) On the Policy Groups tab, select any desired groups.
On the Device Groups tab, select the chosen group of devices to deploy too, or choose an individual test device from the Devices tab.
Click Save and confirm the devices receive the profile.
Command Name: (Name the command)
Run As: root
Event: (Recommend Run as Repeating → Day)
If scheduled as Run as Repeating, set the Days and Run at time.
Click + File → select mac_bundle folder → select nightfall-ai-agent-signed.pkg → click Open
Click the Save button
From the Device Groups tab, select the group (same group as Step 1).
3
Package file not found atPKG_PATH
4
Package installation failed
5
Required MDM configuration profile not installed
6
Health check completed with unresolved errors
In the Nightfall web console, navigate to Integrations → macOS → Manage.
Confirm the device is listed with Agent Status = Connected.
Asset
Purpose
NightfallAI_Profile_with_Browser_Extensions.mobileconfig
Pre-authorizes macOS permissions required by the Nightfall agent (Full Disk Access, System Events, Automation) and silently installs/enables the Nightfall browser extension. Prevents user prompts and tampering with security controls.
mdm_jumpcloud_deploy.sh
Creates the agent configuration file, installs the .pkg if the agent is missing, and verifies services are running on every scheduled execution.
nightfall-ai-agent-signed.pkg
Code
Meaning
0
Success (installed, repaired, or already healthy)
1
Not running as root
2
Note the file path shown after upload. If it differs from the default /tmp/nightfall-ai-agent-signed.pkg, update PKG_PATH in the script to match.
Signed installer package for the Nightfall AI Endpoint Agent.
Credentials not populated (script still contains placeholders)
Create incident - mark account as unknown
Creates an incident and tags the account type as Unknown
Visibility into session-detection failures without asserting personal vs. corporate
Create incident - mark account as unknown
Creates an incident and tags the account type as Unknown
Visibility into session-detection failures on the source side
Audit trail of session-detection gaps (extension down, incognito)
Personal or Corporate accounts only
Create incident - mark account as unknown
Track data that left a corporate session, any destination
Corporate accounts only
Treat as personal - skip incident (default)
Repeat in incognito (or with the extension disabled) and confirm the unknown-session option behaves as configured
On an unsupported domain in the same collection, confirm the event is still monitored (all account types)
Option
What Nightfall does
When to use it
Treat as corporate - skip incident (recommended default)
Treats the unknown session as corporate. A personal-account-only policy does not create an incident.
Production policies where you want to avoid false positives from extension gaps, incognito, or unsigned-in tabs
Treat as personal - create incident
Treats the unknown session as personal and creates an incident
Option
What Nightfall does
When to use it
Treat as personal - skip incident (recommended default)
Treats the unknown session as personal. A corporate-account-only policy does not create an incident.
Production source-scoped policies where you want to avoid false positives
Treat as corporate - create incident
Treats the unknown session as corporate and creates an incident
Policy goal
Session toggle
Unknown-session setting
Block uploads to personal Drive / Gmail / ChatGPT with low noise
Personal accounts only
Treat as corporate - skip incident
Departing-user or watchlist: do not miss personal-account egress
Personal accounts only
High-risk or departing-user policies where missing a personal-account transfer is worse than extra noise
Fail-closed source policies (for example, departing-user watchlists)
Treat as personal - create incident, or mark as unknown
No Plaintext API Tokens on Laptops: Personal API keys and long-lived tokens no longer need to be generated or stored in local configuration files.
Streamlined Onboarding: You get immediate access to all approved development tools with a single URL and one-click SSO login.
Safe Guardrails: Destructive operations (such as deleting repositories or dropping database tables) are blocked at the gateway, enabling safe, high-speed read and query capabilities.
Nightfall AI is your organization's enterprise AI security and data security partner. Nightfall provides the zero-trust token brokering, granular permission scoping, and audit infrastructure powering the MCP Gateway.
The MCP Gateway supports any client, IDE, or agent framework that supports standard Streamable HTTP / Server-Sent Events (SSE) and OAuth MCP connections, including:
Cursor IDE (Composer, Chat & Agent)
Claude Desktop & Claude Code CLI
VS Code (via MCP extensions)
Windsurf IDE (Cascade)
JetBrains IDEs (via MCP plugins)
Claude.ai / ChatGPT Custom Connectors (Enterprise / Team workspaces)
Custom AI Scripts & Autonomous Agents (LangChain, LlamaIndex, AutoGen, custom Python/Node agents)
Setup takes less than 60 seconds:
Click the activation link in your invite email and log in via your company SSO.
Copy your unique Tenant MCP Endpoint URL from the Setup tab.
Paste the URL into your AI client's MCP configuration settings.
No. The gateway brokers credentials centrally. For OAuth-supported tools (like GitHub or Linear), you simply click Connect in the gateway once to authenticate via SSO. You never have to generate, copy, paste, or rotate personal access tokens.
No. Stored tokens and OAuth secrets are encrypted at rest and injected directly into upstream tool calls. Administrators can see connection status (e.g., Connected or Token Expired), but they cannot view secrets, passwords, or personal keys.
No. Nightfall does not train AI models on your code, prompts, or tool data. The gateway functions strictly as an enterprise proxy. Tool calls and payloads are logged solely for your organization's security audit trail (with strict data retention limits).
No. The gateway uses high-throughput, low-latency streaming HTTP connections. Tool discovery and invocations typically execute with sub-millisecond proxy overhead, ensuring your AI assistant responds instantaneously.
If a specific backend server encounters downtime, the gateway immediately surfaces the vendor's error message and short-circuits repeated failing calls. All other enabled tools and servers continue operating without disruption.
Yes. On the Enabled Servers page in your Gateway dashboard, you can toggle Enabled for me on individual tools. If there are certain tools you prefer not to load into your assistant's context window, disabling them removes them exclusively from your client.
Check SSO Authorization: Ensure you have completed the one-time browser consent (Approve) when connecting your client to the gateway.
Verify Upstream Connection: If using a server like GitHub, verify that your account shows Connected under the Enabled Servers tab in the Gateway dashboard.
Check Client URL: Confirm that the endpoint URL in your client configuration matches the exact URL provided in your Setup tab.
Reach out to your internal IT/Security team or post in your company's dedicated help channel
For platform documentation and support, visit help.nightfall.ai or contact support@nightfall.ai.
Arc
Brave
Vivaldi
Perplexity Comet
ChatGPT Atlas
Windows - The following browsers are supported on Windows:
Chrome
Edge
Firefox
Arc
Brave
Vivaldi
Not supported on Windows:
ChatGPT Atlas (not available on Windows)
Perplexity Comet (Windows version does not allow installation of browser extensions)
At this stage, your manual installation is complete. Your machines should start showing up on you Nightfall AI management console under https://app.nightfall.ai/endpoint



















An example of Webhook request is as follows.
This is part of alert event consumption and can be ignored.











{
"service": "nightfall",
"test": true,
"timestamp": "2024-03-07T23:18:39Z"
}sudo ./mdm_pre_installation_script.shmdm_nightfall_ai_agent_uninstall.sh{
"service": "nightfall",
"test": true,
"timestamp": "2024-03-07T23:18:39Z"
}(Optional) To add more Domains to the Collection, you can either click + Add Domain and enter the domain manually, or click Upload txt and upload another text file containing domains.
(Optional) Click the delete icon to remove a domain from the Collection.
Click Save Changes.






Unpack the contents of the downloaded file.
(Optional) In the downloaded folder, locate the README.md under /Profiles to learn about the various MDM profiles available.
Upload and save provided config profile.
Policy name: “Nightfall AI Agent Profile”
Policy description: “Nightfall AI Agent profile”
Platform: “macOS”
Drop or select NightfallAI_Profile_with_Browser_Extensions.mobileconfig.
Click Save & continue.
Navigate to https://app.rippling.com/it/hardware/configurations?section=everything-else. Click the three-dot context menu located on the far right of the new profile. Deploy from
Select all employees or specific target devices.
Click Save to deploy the software.
Navigate to: https://app.rippling.com/hardware/software
Click Upload Software on the right of the page.
Name: “Nightfall Endpoint DLP Agent <version>”
<version> is the version of the package your received from Nightfall.
Operating System: “macOS”
Category: “My Uploads” (Default)
Description: “Nightfall Endpoint DLP Agent”.
Upload Installer File: drop or select the provided nightfall-ai-agent-signed.pkg file.
Install-check script: provided in your package as mdm_pre_install_check_script.sh
Pre-install script: provided in your package as mdm_pre_installation_script.sh
Click Submit.
Click Add on the newly created Software Item.
Click Finished Selecting.
Search or scroll to the newly added Software Item matching the name you used in "Step 2.1".
Click Edit. NOTE: If the Software Item was just recently created it may take a few minutes to leave from the "Pending" status.
Select all employees or specific target devices.
Click Save.
The Nightfall Endpoint DLP Agent will now deploy to all selected target devices. This may take up to 72 hours and is dependent on the endpoint devices being turned on, connected, and pre-requisite profiles deployed.
mdm_pre_installation_script.sh
The script is used by MDMs to ensure that a macOS machine is in a clean state before installing the Nightfall Agent. It wipes any existing Nightfall installation and prepares a clean environment for a new install, including:
Loading API keys
Rebuilding folders
Resetting launch daemons
NightfallAI_Profile_with_Browser_Extension.mobileconfig
This profile is designed to pre-authorize and enable what the Nightfall Endpoint Agent requires on a macOS machine without needing user prompts.
Silently installs/enables the Nightfall browser extension
Allows the extension to run without prompts
Authorizes required permissions (content inspection, file uploads, scanning)
Grants macOS Privacy Permissions required by Nightfall:
Full Disk Access (FDA)
System Events/Automation Permissions
Application Control Permissions
Configures the payloads for browser + system integration
Prevents users from tampering with the security controls
IMPORTANT: Both Steps 1 and 2 require defining the devices to deploy to. This means that the "mobileconfig" profile requires the devices to be selected to assign to, and the agent requires selecting the devices to assign to as well. Ideally, both lists should match.
Click Microsoft Intune Login
You will be redirected to Microsoft's login page
Authenticate with your Microsoft admin account
Review and approve the requested permissions:
Read device information
Read user profiles
Access basic organization information
Click Accept to grant permissions
Under App type, choose: Line-of-business app
Add App Package
In the App package file section, click Select app package file.
Upload the NightfallAgent.msi file.
Configure App Information
Fill in the Name, Description, and other fields as desired.
Click Next.
Specify Install Command Line
In the Command-line arguments field, enter:
API_KEY=your_api_key_here COMPANY_ID=your_company_id_here INSTALL_NF_DRIVER=1
⚠️ Important:
- Do NOT include msiexec /i NightfallAgent.msi — This is handled automatically.
- Do NOT wrap the values in double quotes.
- Make sure to include INSTALL_NF_DRIVER=1.
- If INSTALL_NF_DRIVER=1 is not included you may receive a Driver Error.
✅ Correct Example: API_KEY=ufapuhaefaw COMPANY_ID=qohuifpqrwfAssign the App
Assign the app to the appropriate device groups or users.
Click Next and complete the wizard.
IMPORTANT: Add the preferred group under "Available for enrolled devices"
Monitor Deployment
Go to Monitor > App Install Status to confirm successful deployment.
Verify Installation on a target/test machine
Once installation shows as successfull by Intune, check if the agent is running:
Open Task Manager (Ctrl + Shift + Esc).
Look for the Nightfall Agent & NightfallUI processes under the Processes tab.
Confirm the Nightfall agent is configured to your Nightfall tenant
On the windows machine:
Double-click the Nightfall agent icon in the status bar.
The displayed UUID should match your Nightfall tenant UUID located under
Browser Name: The name of the browser from which the asset was uploaded. This field is applicable only for those events that were triggered by the browser upload action.
Domain: The domain URL to which the asset containing sensitive data was uploaded. This field is applicable only for browser uploads. When you hover over a domain that is not added to any Collection, you can choose to add it to an existing Collection or create a new one. If you are already leveraging the domain collection as part of your monitoring policies, the new addition will be automatically picked up. For example, if the domain is added to a collection of sanctioned domains your policy is ignoring, future uploads to this destination will be ignored.
Empty → when session differentiation is not applicable or unavailable
Upload Start Time: The start date and start time of the upload.
Upload End Time: The end date and end time of the upload.
MAC Address: The physical MAC address of the device.
Last Connection: The date and time when the device was last connected.
Agent Version: The Nightfall agent version installed on the device.
OS Version: The MAC OS version used on the device.
Resolve: This action resolves the event and modifies the status to resolved.
Ignore: This action ignores the event and modifies the status to ignored.














Click Save.
Click Save changes.











This allows you to create custom policies for specific high-risk individuals or user groups. As such, you can create policies to monitor download activity by a disgruntled employee or departing employees. This can be set in combination to other scoping capabilities.
Permissions: Public, Organization or Restricted
This allows you to tailor your policies to drives or files with specific access restrictions. This can be set in combination to other scoping capabilities.
Detection rules: Any or a specific set of sensitive data protection detection rules
You can reuse any of detection rules you've already created or create new ones. This helps focus your detection on files which have associated sensitive data violations identified by your sensitive data scanning product. This can be set in combination to other scoping capabilities.
The Scope stage consists of two main sections.
Drive Selection: This section allows you to include various files and drives for monitoring. In this section, you can select the different types of drives to be monitored.
Add Filters: This section allows you to scrutinize your policy scope at more granular levels. While the Drive selection section allows you to select the whole drive to be monitored, this section provides you more granular level filters. You can select specific files within the selected drives for monitoring.
The Drive Selection section allows you to select various drives for monitoring. You can select either User Drives or Shared Drives to be monitored by Nightfall for exfiltration.
This section allows you to select various drives in your Google Drive to be monitored. There are two options in this section. You can either choose to scan the User drives, Shared drives, or both.
User Drives: The User Drives is the personal drive of the user. The files in this drive are visible only to the owner of the file and other users to whom the owner has granted access. User Drive is commonly known as My Drive in Google Drive. To monitor a User Drive, you must select the User drives check box as shown in the following image.
Shared Drives: Shared drives are common storage locations accessed by all the users in your Workspace. To select this option, you must select the Shared drives check box.
The following image displays the scenarios when you select the Shared Drives check box.
If you select the All Drives, except for option, you must also select the shared drives which must be excluded from monitoring.
Similarly, if you select the Specific Drive(s) option, you must also select the specific shared drives which must be monitored.
The filters section provides you the flexibility to include and exclude users at a granular level.
For instance, in the previous section, irrespective of whether you selected Shared Drive, User Drive, or specific User Drives, you ended up selecting one or a set of Drives for monitoring.
Once you select the Drives to monitor, in this section, you can overlay additional filters to further scope your monitoring. Nightfall provides the following additional filters:
Specific User(s): Choose this option to monitor one or a specific set of internal users. Once you choose this option, Nightfall populates the list of users from the synced IdPs in Directory Sync. You must select the required users.
All Users, except for: Choose this option to exclude specific individuals from your monitoring policy. Once you choose this option, Nightfall populates the list of users from the synced IdPs in Directory Sync. You must select the required users.
Specific User(s): Choose this option to monitor one or a specific set of external users. Once you choose this option, you must manually enter the email ID(s) of the external users and hit the enter key.
All Users, except for: Choose this option to exclude specific external users, from being monitored. Once you choose this option, you must manually enter the email ID(s) of the external users and hit the enter key.
Specific Group(s): Choose this option to monitor one specific or a set of internal groups. Once you choose this option, Nightfall populates the list of internal groups from the synced IdPs in Directory Sync. You must select at least one group.
All Groups, except for: Choose this option to exclude one specific, or a set of, internal groups from being monitored. Once you choose this option, Nightfall populates the list of internal groups from the synced IdPs in Directory Sync. You must select the required users.
Specific Group(s): Choose this option if you have external user groups defined in your IdP and would like to monitor one specific or a set of external groups. Once you choose this option, you must select at least one external user group to monitor then hit the enter key.
All Groups, except for: Choose this option if you have external user groups defined in your IdP and would like to exclude one or more external groups from being monitored. Once you choose this option, you must select at least one external user group to monitor then hit the enter key.
Before understanding the Permission filters, we must understand Google's General Access feature.
The general access feature in Google Workspace consists of three types of access, which are as follows.
Restricted: Files with this permission can only be accessed by users who have been granted access.
Target Audience: Files with this permission can be accessed by the users of the selected target audience group. There is a default target audience that gets created when the Google workspace is provisioned. This target audience has the same name as provisioned in the Google Workspace and includes all members of the organization. You can refer to this Google document to learn more about the target audiences.
Anyone with the Link: Files with this permission can be accessed by any user who has the file link.
Nightfall also provides inclusion and exclusion of files in policy scope that resembles the General Access sharing principle in Google Workspace. The Nightfall General Access permission options are as follows.
Restricted: Choose this option to scope monitoring to files with restricted access.
Shared with target audiences: Choose this option to scope monitoring to files shared with target audiences within your Google Workspace environment.
Anyone with the link: Choose this option to scope monitoring to files shared with anyone with a link.
The Nightfall Detection Rules consist of a single or multiple detectors. You can use this filter to either include all the detection rules or include only specific detection rules. Note that upon a download event, Nightfall will check if the downloaded file has been previously scanned, and results matched at least one of the selected detection rules (i.e. The file is not rescanned upon download).
All: If you select this option, all the detection rules are included.
Specific Detection Rule(s): If you select this option, you must also select the required detection rules. Nightfall scans your files only for the selected detection rules.
A Label is a metadata that you can create to help users organize, find, and apply policy to files in Google Drive. To learn more about Google Drive Labels, refer to this Google document.
You can choose one of the following options.
Specific Label(s): You must choose this option to monitor only those files that contain the selected Labels. Once you choose this option, you must select the Labels. Nightfall only monitors those files that have the selected labels.
All Labels, except for: You must choose this option to exclude the monitoring of files that contain the selected Labels. Once you choose this option, you must select the Labels. Nightfall does not monitor the files that contain the selected labels.
IMPORTANT
If you choose to monitor the User drives, all the User drives in your Google domain are selected for monitoring. You do not have the option to choose specific User drives for monitoring.
IMPORTANT
If you choose to monitor the Shared Drives, you can select whether to monitor all the Shared drives or only specific shared drives. Nightfall provides the following options.
If you select the All Drives option, all the Shared drives in your Google Workspace are selected for monitoring.
Note
If you have not configured the feature, the users list is populated from the . As a result, you can see the Google Drive icon before the user name. However, if you have set up Directory sync, the users list is fetched from the IdP used for the configuration. In the above image, the users list is populated from the Microsoft Azure IdP and hence you can see the Azure icon before the users’ names.
Before utilizing filters for Labels, you must as per instructions and create labels in your Google Drive.
Policy Precedence (Preferred)
Within Google Workspace, set the Policy Precedence as Machine Cloud.
This is the preferred method of installing Nightfall, due to the control of the app deployment being handled and secured by Google Workspace cloud as opposed to the individual machine.
This option will include the following changes:
Changing Policy Precedence to Machine Cloud.
Adding the Nightfall DLP for Browsers app to Google Workspace.
Adjusting the Nightfall extension to Force Install.
Enabling the extension when in Incognito mode.
From within the Google Workspace Admin console, adjust the Policy Precedence.
Click on Chrome Browser > Settings > Select the OU
Navigate down to Setting sources
Confirm Policy precedence is set to Machine Cloud first.
If yes, leave it as-is.
If not, adjust it to Machine Cloud.
Click into the Policy precedence setting.
Click on the "Configuration" flow under Inheritance. It may look like this:
From within the Google Workspace Admin console, add the Nightfall DLP extension to Force Install so it automatically deploys.
Navigate to Devices > Chrome > Apps & Extensions
Select the appropriate OU.
Identify the Nightfall DLP for Browsers app
Within Google Workspace, set the Policy MergeList to merge policies from both sources - Cloud and Machine.
This is a last resort method to use if you do not want to adjust the Policy Precedence, and instead accept policies from both Google Workspace and direct from the machine (e.g., MDM Profile).
From within the Google Workspace Admin console, navigate to Devices > Chrome > Settings.
Under Setting sources, select Policy mergelist
Select the specific Organizational Unit for your deployment scope.
Under Configuration, specify individually the two policies, ExtensionInstallForceList and ExtensionSettings (one per line).
Confirm the policy is applied in: chrome://policy
Check that the Source shows as Merged for the policies you want merged.
IMPORTANT: Nightfall does not know your environment. Each organization has to decide for themselves what method of deployment to utilize in their own environment.
IMPORTANT: This takes control away from Google Workspace and allows both Cloud and Machine policies of equal importance to coexist. It is recommended to use Option 1, instead of Option 2, in most scenarios.
This document explains the process of installing Nightfall AI agent using the Kandji MDM.
You are a Systems Administrator in Nightfall
You have administrator access to Kandji
The Kandji APN is set.
The target macOS devices are onboarded.
On your Nightfall console, navigate to and click the Download Package button on the top right corner of the page. Click Download Package for macOS and unpack the contents of the downloaded file.
This step enables automated mapping of user profiles to devices without requiring manual scripts.
API-based MDM onboarding allows Nightfall to automatically map the user email attribute to specific devices by syncing device inventory from your Iru (Kandji) instance.
To connect Iru (Kandji) to Nightfall, you'll need:
Iru (Kandji) Organization API URL (for example: yourcompany.api.kandji.io)
API Token with read access to device inventory
Log in to your Iru (Kandji) instance
Navigate to Settings > Access > API Token
Click Generate New Token
Configure the following:
Your Kandji Organization API URL follows this format: yourcompany.api.kandji.io
Where yourcompany is your organization's subdomain in Kandji.
You can find this in your Kandji admin panel:
Log in to Kandji
Look at your browser URL (e.g., https://yourcompany.kandji.io)
Your API URL is: yourcompany.api.kandji.io
Log in to the Nightfall Console at
Navigate to Settings → MDM Profile
Click Add MDM
Select Kandji from the list of supported MDM providers
Nightfall will validate the credentials and begin syncing device information automatically.
Important: This API-based connection enables Nightfall to automatically map user email addresses to devices. You do not need to deploy any additional scripts for user-to-device mapping when using this method.
Once connected, Nightfall will periodically sync device inventory from Kandji. You can now proceed to deploy the Nightfall agent to your devices following the steps below.
Navigate to
Click New Blueprint on the top right corner.
Click New Blueprint on the pop up menu.
Enter a name for the blueprint in the Blueprint name field.
In this section, we create a custom profile for each of the profiles provided in the Nightfall endpoint payload and assign them to the blueprint you have created in the previous section.
In the downloaded folder, locate the README.md under /Profiles to learn about the various MDM profiles available.
Choose the NightfallAI_Profile_with_Browser_Extensions.mobileconfig.
Navigate to .
a. Click Add new.
b. Select Custom Profile and click Add & Configure on the pop-up window.
c. Add Title, Select Blueprint, and finally drag and drop the .mobileconfig file.
d. Click Save.
In this section, we will create a custom app item for Nightfall Endpoint Agent.
Navigate to .
Click Add New.
Click Custom App
Click Add & Configure on the pop-up window.
a. Add Title, Select the Blueprint you previously created.
b. Select the Audit and enforce option.
c. Paste the content of mdm_kandji_audit_script into the Audit Script text box.
d. Choose the Installer Package option.
e. Add Preinstall Script & Upload the installer package.
I. Paste the content of mdm_pre_installation_script into the Pre-install Script text box.
II. Upload the installer package
i. Drag and drop or click to upload the provided nightfall-ai-agent_v*.*.*.pkg file
Save the change and wait for the changes to get deployed on the node machine.
Do I still need to install a Nightfall agent on devices after API-based onboarding?
Yes. API-based MDM onboarding enables Nightfall to map user email addresses to devices automatically. You still need to deploy the Nightfall agent to the devices using the steps above.
What permissions does Nightfall need in Kandji?
Nightfall requires least privilege access to device inventory. It does not modify device settings or configurations. The user email to device attribution is automatically managed with API-based MDM onboarding and no manual scripts are needed.
What happens if API credentials expire or are revoked?
If credentials expire or are revoked:
Device syncing will stop. New devices added or removed will not be reflected in Nightfall during that time.
Nightfall will surface an error in the console.
You can re-authenticate or update credentials without reconfiguring policies.
Can I disconnect or change my MDM connection later?
Yes. Contact Nightfall Support to disconnect or update your MDM connection from Settings → MDM Profile.
Who should I contact if onboarding fails?
If you encounter issues:
Verify API credentials and permissions in Kandji
Check the error message in the Nightfall console
Contact Nightfall Support for assistance
Instructions on how to install the Nightfall agent on Microsoft Windows using the JumpCloud MDM.
Before beginning the install, make sure you have the following:
A JumpCloud Admin / MDM environment ready, and the JumpCloud Agent already configured or in process of being configured for your Windows devices.
The Nightfall Windows Agent (MSI) and associated parameters (API_KEY / COMPANY_ID) as from the page → Download Packages.
When Nightfall detects a policy violation and blocks a data transfer, it can optionally prompt the user to provide a business justification before the action is logged. This gives employees a chance to explain their intent while ensuring security teams have full context.
Once a justification is submitted, it appears in the Nightfall console for security admin review, and admins can approve it if warranted.
When a blocked action triggers the justification workflow, a floating panel appears on screen from the Nightfall AI user agent.
Panel contents:
Header: Nightfall AI branding + timestamp of the event
On the Nightfall console:
The newly configured device should be listed under https://app.nightfall.ai/endpoint.

Name: Nightfall Integration
Permissions: Select Read for:
Device List
Device Details
User List
Click Generate Token
Copy the API Token - you'll need this in the next step and it will only be shown once
Enter the following information:
Kandji Organization API URL: Your Kandji API URL (e.g., yourcompany.api.kandji.io)
API Token: The API Token you created in Kandji
Click Connect
Enter a description for the blueprint in the Blueprint description field.
Click Create Blueprint.
mdm_pre_installation_script.sh
The script is used by MDMs to ensure that a macOS machine is in a clean state before installing the Nightfall Agent. It wipes any existing Nightfall installation and prepares a clean environment for a new install, including:
Loading API keys
Rebuilding folders
Resetting launch daemons
NightfallAI_Profile_with_Browser_Extension.mobileconfig
This profile is designed to pre-authorize and enable what the Nightfall Endpoint Agent requires on a macOS machine without needing user prompts.
Silently installs/enables the Nightfall browser extension
Allows the extension to run without prompts
Authorizes required permissions (content inspection, file uploads, scanning)
Grants macOS Privacy Permissions required by Nightfall:
Full Disk Access (FDA)
System Events/Automation Permissions
Application Control Permissions
Configures the payloads for browser + system integration
Prevents users from tampering with the security controls









If you select the All Drives, except for option, you can exclude some shared drives from being monitored.
If you select the Specific Shared Drives option, you get the option to choose specific Shared drives for monitoring.











{
"service": "nightfall",
"test": true,
"timestamp": "2024-03-07T23:18:39Z"
}Select Machine Cloud as the primary configuration.
Click Save
If the Nightfall DLP for Browsers app is not present, then install it from the Chrome Web Store.
Click the yellow circle with the + symbol at the bottom right.
Select "Chrome Web Store"
Name: Nightfall DLP for Browsers
ID: jgmgecncmjklkabkejnjfgfkglapfgek
Once the Nightfall DLP for Browsers app is visible, select it.
Change Allow install to Force install
Toggle on Extension is mandatory for Incognito
Click Save
Communication to end-users (if needed) and any documentation of maintenance windows or reboots.
Valid credentials / admin rights on target Windows devices (or ability via MDM / script to install silently).
Log in to app.nightfall.ai and navigate to Settings > MDM Profile.
Select JumpCloud from the list of supported MDM providers.
Complete the OAuth flow to grant Nightfall read-only access to your JumpCloud device and user directory. This maps JumpCloud user identities to devices in the Nightfall console automatically.
Use JumpCloud’s Commands/Policies feature to deploy the Nightfall Agent silently to the target Windows device group:
In JumpCloud Admin Portal: Device Management → Commands → Commands tab → click + Command (or use Policies if available)
Type: Windows
Check "Windows PowerShell"
Command: Copy/paste in the command shown below.
Replace the File Destination ($msi value) as needed or leave as-is.
Replace the API_KEY and COMPANY_ID with what is in the Nightfall console.
From the page > click Download Package > copy the API_KEY and COMPANY_ID from the Windows command.
Command Name: (e.g., “Install Nightfall Agent Windows”)
Under Files > click + File > upload the NightfallAgent.msi
Copy the File Destination where the MSI would be copied onto the enrolled devices by jumpcloud mdm.
Choose a Device Group
Navigate to the Device Groups tab.
Check the group to use for deployment.
Click "Save".
Click "Run Now".
After installation, verify that the Nightfall Agent is functioning correctly:
In JumpCloud, Device Management → Devices, check that the device remains active and that there are no policy conflicts or errors.
In the Nightfall Console → Integrations → Manage (macOS or Windows) → confirm the device is in the “Connected” state.
On the Windows machine, check Programs & Features to confirm “Nightfall Agent” appears.
In Services (services.msc), verify the Nightfall service is installed and running.
Confirm that the NightfallUI app is shown on the taskbar and that the Version, Company UUID, and Device ID are correct.
Conduct a simple test of exfiltration detection (per your internal policy) to ensure the agent is monitoring as expected.
Ensure that the MSI installation parameters (API_KEY, COMPANY_ID) are correct and correspond to your Nightfall account.
If installation fails silently, re-run the installation with log flags and check the install log file:
If devices have pending reboots or other software installations, consider staging installation to avoid conflicts.
Because you’re installing via JumpCloud, ensure the device’s JumpCloud Agent is up-to-date and reporting properly before deploying Nightfall.
For stealth or minimal-disruption deployment (if desired), schedule installs during off-hours and consider using silent /qn /norestart. The Nightfall Windows guide supports silent installs.
Document versioning of Nightfall Agent: if you need to upgrade later, consider how you’ll script uninstall + reinstall or patch. The MSI guide covers uninstall.
Monitor JumpCloud’s device compliance and policy execution logs to ensure the command executed successfully.
In JumpCloud Admin Portal: Device Management → Commands → + Command
Type: Windows
Check "Windows PowerShell"
Command: Copy/paste in the command shown below:
Command Name: (e.g., “Uninstall NightfallAI Agent Windows”)
Choose a Device Group
Navigate to the Device Groups tab.
Check the group to use for deployment.
Click "Save".
Run whenever needed.
Nightfall Windows Agent MSI Deployment Guide – Nightfall Help Center: Install Nightfall AI Agent for Windows OS
JumpCloud Windows Agent Installation Walk-through – JumpCloud Support: JumpCloud Agent Windows Installation Walkthrough
JumpCloud Commands / Remote Application Install guide: Install Applications Remotely via JumpCloud
$args = @(
'/i', ""$msi""
'API_KEY="<API_KEY>"'
'COMPANY_ID="<COMPANY_ID>"'
'INSTALL_NF_DRIVER=1'
'/qn'
'/L*V’,'C:\\Windows\\Temp\\NightfallAgent-install.log’
)Action Details section: Contextual information about what was blocked, including:
For browser uploads: Source browser + destination domain + file name
For cloud sync apps: App name
For clipboard paste: Destination domain or app
For removable media: File name + device label
For code pushes: Repository name
For print jobs: Printer name + destination
Business reason text field: Free-text input, up to 300 characters. Placeholder: "e.g: working on a project with a partner"
Buttons:
Submit for approval - enabled only when text is entered; submits justification to Nightfall
Cancel - dismisses the prompt without submitting
Note: Only one justification prompt is shown at a time. If the same policy triggers within 15 minutes, the prompt is suppressed to avoid repetition.
On Windows, the justification prompt appears as a toast notification in the bottom-right corner of the screen, above the system tray.
Window contents:
Header: Nightfall AI logo + app name + idle countdown timer ("Closes in: 15s")
Alert title and message: Configured by your security admin
Event Details box: Shows:
File: Name of the file involved (if applicable)
Destination: Where the data was being sent (domain or app)
Time: Timestamp of the event
View Assets link: (if configured) — links to the violation record in the Nightfall console
Business Justification field: Text input, up to 300 characters with live character counter (e.g., "0/300")
Info line: "Your justification will be logged for security review."
Buttons:
Cancel - dismisses without submitting
Submit & Proceed - enabled only when text is entered
Auto-dismiss behavior:
The window auto-closes after 15 seconds of idle (no mouse hover, no keyboard focus, no text typed)
The countdown pauses while the user is actively interacting with the window
The window hard-closes when the backend action expires (15 minutes from event time)
Once a user submits a justification:
Nightfall records the event as an exfiltration violation in the console
The justification text is attached to the violation record
The violation appears in the Violations view with activity: "Provided Business Justification"
If the policy is configured for block override with justification, an "Approve Business Justification" action becomes available to security admins
Security admins review submitted justifications in the Nightfall console under Violations.
Each violation with a submitted justification shows:
The event details (user, device, file, destination, timestamp)
The user's justification text (logged in the activity timeline)
The current violation state
Available actions, including Approve Business Justification (if block override is enabled)
Action
Description
Approve Business Justification
Grants a policy override for the specified device and policy, allowing the action to proceed
Bulk Annotate - Business Justification
Annotates the violation as having a valid business justification without granting a device override
Resolve
Note: "Approve Business Justification" is only available on endpoint exfiltration violations where the policy has Allow Block Override with Justification enabled.
Nightfall sends alert notifications to configured channels (Slack, email, webhook) when a violation with a justification is created. The notification includes:
Who triggered the violation (user + device)
What was blocked (file, destination, timestamp)
A link to the violation record in the console
The justification text in the activity log
From Slack, admins can open a "Provide Justification" modal to annotate directly from the alert message.
In the Nightfall console, navigate to Policies > [Your Policy] > Action Notification Settings.
For the BLOCK action, enable:
Enable notification: On
Notification type: Pop-up (or Banner)
Title: Custom alert title shown to the user (e.g., "Action Blocked by Nightfall")
Message: Custom message shown to the user (e.g., "Your action was blocked by a security policy. Please provide a business justification if this action is necessary.")
Allow Override with Justification: ✅ Enabled
If you want admins to be able to approve and unblock the action after reviewing the justification, also enable:
Allow Block Override with Justification on the policy's automated action settings
This surfaces the "Approve Business Justification" action in the Nightfall console.
Behavior
Detail
Prompt re-show interval
15 minutes per policy (per device)
Justification window (Windows)
Expires 15 minutes from event time
Auto-dismiss idle timeout (Windows)
The justification prompt fires for blocked events across all monitored channels:
Transfer Type
Details shown in prompt
Browser upload
Browser name + destination domain + file name
Cloud sync app upload
App name
Clipboard paste
Q: What happens if I cancel the justification prompt?
The blocked action is logged as a standard policy violation. No justification is recorded, and your action does not proceed.
Q: What happens if the window closes before I can type my justification?
On Windows, the prompt auto-dismisses after 15 seconds of idle. If this occurs, the violation is logged without a justification. You can reach out to your security team directly to explain the context.
Q: Will submitting a justification automatically allow my action?
Not automatically. The justification is submitted for admin review. If your admin has enabled block override approval, they can approve it from the console — which creates a policy exception for your device.
Q: Will I be prompted again for the same action?
If the same policy blocks you again within 15 minutes, the prompt will not reappear. After 15 minutes, the prompt may show again if the action is blocked.
Q: Where does my justification text go?
It is securely logged in the Nightfall platform, visible only to your security team. It is attached to the violation record for audit purposes.
User attempts transfer
↓
Policy detects violation → BLOCK action fires
↓
Justification prompt appears on-screen (Mac or Windows)
↓
User types justification and submits (or cancels / window expires)
↓
Justification recorded in Nightfall console as a violation event
↓
Security admin reviews → can Approve Business JustificationLearn the details available on the Nightfall Exfiltration Events page
The Nightfall Exfiltration page displays various details of the Exfiltration Events. An Exfiltration Event is automatically created in Nightfall when an Exfiltration policy is violated. The Event displays useful information like the integration on which the exfiltration occurred (Google Drive, Salesforce, macOS/Windows Endpoint), the name of the policy violated, the details of the asset responsible for the violation, and so on.
You can navigate to the Exfiltration Event page by clicking Exfiltration Prevention button from the left menu.
Once you land on the Exfiltration Events page, all the Exfiltration Events are listed. This view can be called as the Event list view. When you click an Event on the Event list view, the details of only the selected Event is displayed. We can call it the Event Detail view.
The Event list view contains a table which displays details of the Events. You can click here to learn more about the details displayed in the Event list view.
You can filter the data on the list view by date or by integrations. To filter the data by integrations, you must execute the following steps.
Navigate to Exfiltration Prevention from the left menu.Steps 2-6 help you filter the events to only view the alerts generated by Windows OS.
Click Filter.
Click + Add Filter.
Select Integration.
Select the check box required integration(s).
Click Apply.
You can also use the date filter to view historic Exfiltration events. To learn more about how to use the historic time filter, .
Nightfall provides a powerful search bar to search specific Exfiltration events. Nightfall provides you various search operators to perform your search. You must use the following syntax to search data.
For example, to search events that are in active state, you must use the State search operator with the following syntax.
The various Exfiltration search operators provided by Nightfall are as follows.
To learn more about how to search special characters, refer to . Nightfall allows you to share and download the Event data. The Share button creates a link to the current view with all the filters applied. When you click this link, the Events page opens with all the filters applied.
This document explains the process of installing the Nightfall AI agent using JAMF.
The JAMF installation consists of the following steps.
You are a Systems Administrator in Nightfall
You have administrator access to JAMF Pro
Target macOS devices are onboarded.
On your Nightfall console, navigate to and click the Download Package button on the top right corner of the page. Click Download Package for macOS and unpack the contents of the downloaded file.
This step enables automated mapping of user profiles to devices without requiring manual scripts.
API-based MDM onboarding allows Nightfall to automatically map the user email attribute to specific devices by syncing device inventory from your JAMF Pro instance.
To connect JAMF Pro to Nightfall, you'll need:
Jamf Pro URL (for example: https://yourcompany.jamfcloud.com)
Do I still need to install a Nightfall agent on devices after API-based onboarding?
Yes. API-based MDM onboarding enables Nightfall to map user email addresses to devices automatically. You still need to deploy the Nightfall agent to the devices using the steps above.
What permissions does Nightfall need in JAMF Pro?
Nightfall requires least privilege access to device inventory. It does not modify device settings or configurations. The user email to device attribution is automatically managed with API-based MDM onboarding and no manual scripts are needed.
What happens if API credentials expire or are revoked?
If credentials expire or are revoked:
Device syncing will stop. New devices added or removed will not be reflected in Nightfall during that time.
Nightfall will surface an error in the console.
You can re-authenticate or update credentials without reconfiguring policies.
Can I disconnect or change my MDM connection later?
Yes. Contact Nightfall Support to disconnect or update your MDM connection from Settings → MDM Profile.
Who should I contact if onboarding fails?
If you encounter issues:
Verify API credentials and permissions in JAMF Pro
Check the error message in the Nightfall console
Contact Nightfall Support for assistance
This guide explains multiple ways to deploy the Nightfall Agent (NightfallAgent.msi) with the required API_KEY and COMPANY_ID parameters.
We cover:
PowerShell scripts (local, network share, download from URL)
You have the MSI installer (NightfallAgent.msi) provided by Nightfall.
Installation requires two properties:
API_KEY="YOUR-API-KEY"
COMPANY_ID="YOUR_SECRET_VALUE"
Use this if you or your RMM tool place the .msi directly on the machine before running the script.
Use this if you keep the MSI on a file server. Make sure Domain Computers or the target machines have read access to the share.
⚠️ Use UNC paths (\\server\share\...) — mapped drives won’t work for GPO Startup scripts.
Use this if you host the MSI on an internal HTTPS server or CDN.
Recommended for domain-joined Windows machines. Use a Startup Script because the built-in “Software Installation” GPO cannot pass custom properties like API_KEY.
Steps:
Place the script (e.g., Install-NightfallAgent-FromShare.ps1) in
\\<domain>\SYSVOL\<domain>\scripts\Nightfall\
Ensure Domain Computers have read access.
In Group Policy Management:
Go to Computer Configuration → Policies → Windows Settings → Scripts (Startup/Shutdown).
If you have an MST transform that embeds API_KEY and COMPANY_ID, you can deploy the MSI via:
Computer Configuration → Policies → Software Settings → Software installation.
Add the MSI via UNC path.
Open its Properties → Modifications → Add your .mst.
Without an MST, use GPO via Startup Script instead. One-liner for Testing
Run manually on a single machine (PowerShell elevated):
Check for expected services:
Confirm presence of the Nightfall AI icon in the system tray (this may take a few seconds).
Double click the icon
You should see a connected status as seen in the image above.
AI Agent Security policies are configured as exfiltration policies in Nightfall. This guide walks through each step of the policy creation wizard.
Navigate to Configuration > Policies > Exfiltration.
Click + New Policy.
Select AI Agent Security as the integration type.
Enable one or more hook types. Each can be independently toggled:
Defines which MCP servers this policy is evaluated against. This scope also applies to tool responses (data coming back from the server, not just outbound calls). What happens when a match occurs - block, alert, etc. - is configured separately under Remediation Actions.
All MCP servers - the policy applies to every connected MCP server.
Specific MCP servers - the policy applies only to a chosen list of servers.
All except these MCP servers - the policy applies to every server except a chosen list of excluded servers.
When you select “Specific MCP servers” or "All except these MCP servers," a drop-down picker appears:
Select one or more named server collections. All servers across selected collections are combined.
There are pre-defined collections organized by category:
Code Hosting
Databases
Communication
You can navigate to Collections list page under AI Governance > Collections and manually add a new MCP server, tool calls for a server. Select individual servers and optionally limit to specific tools within each server. Tool inventory will be captured and will be available in the Collections list page via the Add server and Add tools button. There is no blanket collection which will have all the servers and tools discovered.
For example, you could allow the GitHub MCP server but only for read operations. To do so, specify this in the MCP server collection and configure an appropriate policy.
Nightfall identifies the MCP server from the tool name reported by each AI client. Because clients format these names differently, the server is not always identifiable. The table below uses the fetch tool on a server named github as an example.
Claude Code - Server-specific scoping works as expected.
GitHub Copilot - Server-specific scoping works in most cases. When a server or tool name contains underscores, Nightfall may not be able to tell the server and tool apart reliably.
Cursor - Cursor does not include the server name in its tool names. A Specific MCP servers or All except these MCP servers policy therefore cannot match Cursor traffic by server, and Cursor activity is treated as if All MCP servers were selected.
Recommendation: If you need to scope policies by server and your organization uses Cursor, pair the policy with a broader All MCP servers rule so Cursor traffic is still covered.
When Shell Commands monitoring is enabled, you can optionally scope to specific command patterns. Leaving this field empty scans all shell commands.
Enter patterns as chips (type + Enter to add). Recommended patterns are shown as clickable suggestions below the input.
Select the Nightfall detectors that define what sensitive data to look for. This works the same as any other exfiltration policy:
Built-in detectors: PII (SSN, credit cards, phone numbers), credentials (API keys, passwords, tokens), source code patterns
Custom detectors: Regular expressions, dictionaries, or ML-based classifiers you have created
Detection rule logic: Combine multiple detectors with AND/OR logic and set confidence thresholds
Configure where violation alerts are sent:
Slack - post to a channel
Jira - create a ticket
Email - send to specified recipients
Webhook - POST to a custom endpoint
End-user notifications are not available with AI Agent Security policy at this time. The custom message will be displayed in AI clients like Cursor, Claude Code & VS Code.
The notification text as per the custom block message (e.g., "This action was blocked because it contains sensitive data. Contact security@company.com for help.")
Policy name and description
Risk score - use the Nightfall default or set a custom severity (Critical, High, Medium, Low)
Here is an example of a common policy configuration:
AI Clients: Claude Code, Cursor, VS Code
Hook Types: User Prompts (Block), Tool Calls (Block), Shell Commands (Monitor)
MCP Server Scope: All MCP servers
Detection Rules: API Keys, Passwords, AWS Credentials (High confidence)
This policy prevents developers from accidentally pasting API keys or credentials into AI prompts or tool calls, while monitoring shell commands for credential exposure.
Nightfall uses two complementary mechanisms to monitor AI agent activity. This page explains the differences, when to use each, and the recommended deployment strategy.
Closes the violation
Create Jira Issue
Escalates to Jira
Notify via Slack / Email
Sends a notification to the violating user
15 seconds of inactivity
Max justification length
300 characters
Simultaneous prompts
One at a time (additional events are queued/suppressed)
Destination domain or application
Removable media
File name + device/volume label
Thick app upload (Outlook, iMessage, etc.)
App name + file name
Git push
Repository name
Printer name + print destination



Tool Responses
No
Tool output after execution (monitor only)
Model Responses
No
Model response after execution (monitor only)
Shell Commands
Yes
Shell command string before execution
Observability
Project Management
File System
mcp_<server>_<tool>
mcp_github_fetch
Usually
Cursor
MCP:<tool>
MCP:fetch
No
Action: Block
Alerts: Slack #security-alerts + Email to security team
Hook Type
Can Block
What It Scans
User Prompts
Yes
Prompt text before it reaches the AI model
Tool Calls
Yes
AI client
Tool name format
Example
Server identified?
Claude Code
mcp__<server>__<tool>
mcp__github__fetch
Yes
Action
Behavior
Block
The AI agent action is denied. The end-user sees a block message.
Monitor
The action proceeds. An incident is created for review.
Tool name and input parameters before execution
GitHub Copilot

Search the unique Exfiltration event ID.
event_type
Search the Exfiltration event type.
integration_name
Search the integration name.
last_action
Search the last action implemented on an event. Example of action can be Acknowledge, Ignore, Resolve, and so on.
last_actioned_by
Search for the user who last took an action on the event.
notes
Search the notes entered in an Event.
policy_id
Search the unique policy ID.
policy_name
Search the policy name.
resource_content_type
Search the resource type of the file that was exfiltrated. Resource type refers to the file format and can be PDF, .doc, d.ocx, and so on.
resource_id
Search the resource ID. This unique identifier is assigned to resources by their integration (Google Drive, Salesforce)
resource_name
Search the resource name (file name) that was exfiltrated.
resource_owner_email
Search the email of the user who owns the exfiltrated file.
resource_owner_name
Search the name of the user who owns the exfiltrated file.
state
Search the current status of the Event. This could be Active, Acknowledge, and so on.
violation_id
Search the unique violation ID of the event.
violation_type
Search the violation type
endpoint.browser_upload.domain
Search the domain name that was used to upload file.
Endpoint (Browser upload)
endpoint.browser_upload.file_name
Search the name of the file.
Endpoint (Browser upload)
endpoint.browser_upload.origin.browser_name
Search the browser from which the exfiltrated file emerged.
Endpoint (Browser upload)
endpoint.browser_upload.origin.domain
Search the domain from which the exfiltrated file emerged.
Endpoint (Browser upload)
endpoint.browser_upload.origin.url
Search the exact URL from which the exfiltrated file emerged.
Endpoint (Browser upload)
endpoint.browser_upload.url
Search the URL used to upload the exfiltrated file.
Endpoint (Clipboard Copy/Paste)
endpoint.clipboard_copy.destination.browser_name
Search the destination browser name to which the copied data was pasted.
Endpoint (Clipboard Copy/Paste)
endpoint.clipboard_copy.destination.domain
Search the destination domain name to which the copied data was pasted.
Endpoint (Clipboard Copy/Paste)
endpoint.clipboard_copy.origin.browser_name
Search the origin browser name from which the data was copied.
Endpoint (Clipboard Copy/Paste)
endpoint.clipboard_copy.origin.domain
Search the origin domain name from which the data was copied.
Endpoint (Clipboard Copy/Paste)
endpoint.clipboard_copy.origin.url
Search the origin URL from which the data was copied.
Endpoint (Cloud Sync)
endpoint.cloud_sync.account_name
Search the name of the account to which the file was uploaded.
Endpoint (Cloud Sync)
endpoint.cloud_sync.account_type
Search the account type (personal/business) of the account to which the file was uploaded.
Endpoint (Cloud Sync)
endpoint.cloud_sync.app
Search the cloud storage app name (Google Drive, OneDrive) to which the file was uploaded.
Endpoint (Cloud Sync)
endpoint.cloud_sync.destination_file_path
Search the destination directory in the storage app to which the file was exfiltrated.
Endpoint (Cloud Sync)
endpoint.cloud_sync.email
Search the email ID of the account to which the file was uploaded.
Endpoint (Cloud Sync)
endpoint.cloud_sync.file_name
Search the name of the file which was uploaded to a cloud storage app.
Endpoint
endpoint.device_id
Search the endpoint device ID of the device from which the exfiltration was performed.
Endpoint
endpoint.machine_name
Search the endpoint device name from which the exfiltration was performed.
Google Drive
gdrive.drive
Search a drive within Google Drive. Returns all the events that were exfiltrated from the searched drive.
Google Drive
gdrive.file_owner
Search a Google Drive user. Returns all the events that were owned by the searched user and were exfiltrated.
Google Drive
gdrive.label_name
Search a Google Drive label. Returns all the events that contained the searched label and were exfiltrated.
Google Drive
gdrive.permission
Search a Google drive permission (restricted, pubic). Returns all the events that contain the searched permission and exfiltrated.
Google Drive
gdrive.shared_external_email
Search the shared Gmail external email ID.
Google Drive
gdrive.shared_internal_email
Search the shared Gmail internal email ID.
Salesforce
salesforce.file.session_level
Search for Salesforce session level file
Salesforce
salesforce.file.source_ip
Search the IP address of the source machine that initiated the exfiltration of the file.
Salesforce
salesforce.report.description
Search the description provided in Salesforce report.
Salesforce
salesforce.report.event_source
Search the Salesforce report event source.
Salesforce
salesforce.report.operation
Search the Salesforce report operation.
Salesforce
salesforce.report.scope
Search the Salesforce report scope.
Salesforce
salesforce.report.session_level
Search the Salesforce session level report.
Salesforce
salesforce.report.source_ip
Search the source IP address of the Salesforce report.
actor_Email
Search using the Email ID of the actor whose action triggered the Event.
actor_Name
Search using the name of the actor (device name) from which the Event was triggered.
Endpoint (Browser upload)
endpoint.browser_upload.browser_name
Search the Web browser that was used to upload file.


event_id
Endpoint (Browser upload)
Installation is silent (/qn /norestart) and requires administrator rights.
Logging is enabled with /l*v for troubleshooting.
Add a Startup Script.
Script name: powershell.exe
Script parameters: -ExecutionPolicy Bypass -File "\\SYSVOL<domain>\scripts\Nightfall\Install-NightfallAgent-FromShare.ps1"
Apply the GPO to the desired OU.
Run gpupdate /force or reboot a target machine.

$msi = 'C:\\Windows\\Temp\\NightfallAgent.msi'
$args = @(
'/i', "`"$msi`""
'API_KEY="<API_KEY>"'
'COMPANY_ID="<COMPANY_ID>"'
'INSTALL_NF_DRIVER=1'
'/qn'
)
Start-Process msiexec.exe -ArgumentList $args -Wait -NoNewWindow# Uninstall "NightfallAI Agent" silently via MSI ProductCode, with full logging.
# Works for both 64-bit and 32-bit (WOW6432Node) installs.
$TargetDisplayName = 'NightfallAI Agent'
$UninstallHives = @(
'HKLM:\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall',
'HKLM:\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall'
)
Write-Host "Searching for '$TargetDisplayName' in uninstall registry..." -ForegroundColor Cyan
$found = $null
foreach ($hive in $UninstallHives) {
if (-not (Test-Path $hive)) { continue }
foreach ($sub in Get-ChildItem $hive -ErrorAction SilentlyContinue) {
try {
$p = Get-ItemProperty $sub.PSPath -ErrorAction SilentlyContinue
if ($p.DisplayName -eq $TargetDisplayName) {
$found = [pscustomobject]@{
KeyName = $sub.PSChildName
KeyPath = $sub.PSPath
DisplayName = $p.DisplayName
UninstallString = $p.UninstallString
}
break
}
} catch { }
}
if ($found) { break }
}
if (-not $found) {
Write-Host "Not installed: $TargetDisplayName — nothing to do." -ForegroundColor Yellow
exit 0
}
Write-Host "Found:" -ForegroundColor Green
Write-Host " Key: $($found.KeyPath)"
Write-Host " UninstallString: $($found.UninstallString)"
# Try to extract ProductCode (GUID) from key name or UninstallString
$guid = $null
if ($found.KeyName -match '^\\{[0-9A-Fa-f-]{36}\\}$') { $guid = $found.KeyName }
elseif ($found.UninstallString -match '\\{[0-9A-Fa-f]{8}(-[0-9A-Fa-f]{4}){3}-[0-9A-Fa-f]{12}\\}') { $guid = $matches[0] }
$LogPath = 'C:\\Windows\\Temp\\NightfallAgent-uninstall.log'
if ($guid) {
Write-Host "Using ProductCode $guid for silent uninstall via msiexec..."
$args = @('/x', $guid, '/qn', '/norestart', '/L*V', $LogPath)
$proc = Start-Process -FilePath msiexec.exe -ArgumentList $args -Wait -PassThru -NoNewWindow
$code = $proc.ExitCode
Write-Host "msiexec exit code: $code"
if (Test-Path $LogPath) { Write-Host "MSI log: $LogPath" }
exit $code
}
else {
# Fallback: run the UninstallString directly (best effort).
# If it's msiexec without silent flags, try to add /qn /norestart.
$cmd = $found.UninstallString
if ([string]::IsNullOrWhiteSpace($cmd)) {
Write-Error "UninstallString missing — cannot continue."
exit 1
}
if ($cmd -match 'msiexec(\\.exe)?\\s+/I\\s*(\\{[^\\}]+\\})') {
# Convert /I to /x for remove, add silent + log
$guid2 = $matches[2]
Write-Host "Converting msiexec /I to silent remove for $guid2"
$args = @('/x', $guid2, '/qn', '/norestart', '/L*V', $LogPath)
$proc = Start-Process -FilePath msiexec.exe -ArgumentList $args -Wait -PassThru -NoNewWindow
$code = $proc.ExitCode
Write-Host "msiexec exit code: $code"
if (Test-Path $LogPath) { Write-Host "MSI log: $LogPath" }
exit $code
}
elseif ($cmd -match 'msiexec(\\.exe)?') {
# It's some other msiexec form; append silent flags if missing
$aug = $cmd
if ($aug -notmatch '/qn') { $aug += ' /qn' }
if ($aug -notmatch '/norestart'){ $aug += ' /norestart' }
if ($aug -notmatch '/L\\*V') { $aug += " /L*V `"$LogPath`"" }
Write-Host "Running: $aug"
$proc = Start-Process -FilePath 'cmd.exe' -ArgumentList '/c', $aug -Wait -PassThru -NoNewWindow
$code = $proc.ExitCode
Write-Host "msiexec exit code: $code"
if (Test-Path $LogPath) { Write-Host "MSI log: $LogPath" }
exit $code
}
else {
# Non-MSI uninstaller (unlikely for your MSI). Launch as-is.
Write-Host "Non-MSI uninstall string; executing as-is."
$proc = Start-Process -FilePath 'cmd.exe' -ArgumentList '/c', $cmd -Wait -PassThru -NoNewWindow
$code = $proc.ExitCode
Write-Host "Uninstaller exit code: $code"
exit $code
}
}search operator name:"search term"State:"Active"# Install-NightfallAgent-Local.ps1
$msiPath = "C:\Temp\NightfallAgent.msi"
$apiKey = "REPLACE_WITH_API_KEY"
$companyId = "REPLACE_WITH_COMPANY_ID"
$logDir = "C:\Windows\Temp\Nightfall"
$logFile = Join-Path $logDir "NightfallAgent_Install.log"
New-Item -ItemType Directory -Path $logDir -Force | Out-Null
if (Test-Path $msiPath) {
Write-Output "MSI found at $msiPath. Starting install..."
$args = "/i `"$msiPath`" API_KEY=`"$apiKey`" COMPANY_ID=`"$companyId`" /qn /norestart /l*v `"$logFile`""
$proc = Start-Process "msiexec.exe" -ArgumentList $args -Wait -PassThru -NoNewWindow
if ($proc.ExitCode -eq 0) {
Write-Output "Nightfall agent installed successfully."
} else {
Write-Output "Installer returned exit code $($proc.ExitCode). Check log: $logFile"
exit $proc.ExitCode
}
} else {
Write-Output "MSI not found at $msiPath. Skipping install."
exit 2
}# Install-NightfallAgent-FromShare.ps1
$sourceMsi = "\\fileserver\software\Nightfall\NightfallAgent.msi"
$localMsi = "C:\Temp\NightfallAgent.msi"
$apiKey = "YOUR_API_KEY_HERE"
$companyId = "YOUR_SECRET_VALUE"
$logDir = "C:\Windows\Temp\Nightfall"
$logFile = Join-Path $logDir "NightfallAgent_Install.log"
New-Item -ItemType Directory -Path $logDir -Force | Out-Null
New-Item -ItemType Directory -Path (Split-Path $localMsi) -Force | Out-Null
Write-Output "Copying MSI from $sourceMsi to $localMsi..."
Copy-Item -Path $sourceMsi -Destination $localMsi -Force -ErrorAction Stop
if (Test-Path $localMsi) {
Write-Output "Copy complete. Starting install..."
$args = "/i `"$localMsi`" API_KEY=`"$apiKey`" COMPANY_ID=`"$companyId`" /qn /norestart /l*v `"$logFile`""
$proc = Start-Process "msiexec.exe" -ArgumentList $args -Wait -PassThru -NoNewWindow
if ($proc.ExitCode -eq 0) {
Write-Output "Nightfall agent installed successfully."
} else {
Write-Output "Installer returned exit code $($proc.ExitCode). Check log: $logFile"
exit $proc.ExitCode
}
} else {
Write-Output "MSI copy failed. Check share permissions and path."
exit 3
}# Install-NightfallAgent-FromUrl.ps1
# Purpose: Download the Nightfall MSI from a URL, validate it looks like a real MSI, then install silently.
# Notes:
# - Run elevated (admin). Works as a GPO Startup script.
# --- EDIT THESE VALUES ---
$downloadUrl = "https://example.com/NightfallAgent.msi" # <-- Replace with your direct MSI URL
$localMsi = "C:\Temp\NightfallAgent.msi"
$apiKey = "<API_KEY>" # <-- Replace
$companyId = "<COMPANY_ID>" # <-- Replace
# --------------------------
$ErrorActionPreference = "Stop"
# Paths for logging
$logDir = "C:\Windows\Temp\Nightfall"
$logFile = Join-Path $logDir "NightfallAgent_Install.log"
# Ensure folders exist
New-Item -ItemType Directory -Path (Split-Path $localMsi) -Force | Out-Null
New-Item -ItemType Directory -Path $logDir -Force | Out-Null
# Helper: quick MSI signature + size sanity check
function Test-IsMsi {
param([string]$Path)
if (-not (Test-Path $Path)) { return $false }
$len = (Get-Item $Path).Length
if ($len -lt 1MB) { return $false } # tiny files are likely HTML/error pages
# MSI is a CFBF (OLE) container: header D0 CF 11 E0 A1 B1 1A E1
$fs = [System.IO.File]::Open($Path, 'Open', 'Read', 'ReadWrite')
try {
$buf = New-Object byte[] 8
[void]$fs.Read($buf, 0, 8)
$hex = ($buf | ForEach-Object { $_.ToString("X2") }) -join " "
return ($hex -eq "D0 CF 11 E0 A1 B1 1A E1")
} finally {
$fs.Close()
}
}
Write-Output "Downloading MSI from $downloadUrl ..."
try {
# Use HttpClient for robust redirects + streaming
Add-Type -AssemblyName System.Net.Http
$handler = New-Object System.Net.Http.HttpClientHandler
$handler.AllowAutoRedirect = $true
$handler.AutomaticDecompression = [System.Net.DecompressionMethods]::GZip -bor `
[System.Net.DecompressionMethods]::Deflate -bor `
[System.Net.DecompressionMethods]::Brotli
$client = New-Object System.Net.Http.HttpClient($handler)
$client.Timeout = [TimeSpan]::FromMinutes(10)
$client.DefaultRequestHeaders.UserAgent.ParseAdd("Nightfall-Agent-Installer/1.0")
$response = $client.GetAsync($downloadUrl, [System.Net.Http.HttpCompletionOption]::ResponseHeadersRead).GetAwaiter().GetResult()
if (-not $response.IsSuccessStatusCode) {
throw "HTTP $([int]$response.StatusCode) $($response.ReasonPhrase)"
}
$stream = $response.Content.ReadAsStreamAsync().GetAwaiter().GetResult()
$tmp = "$localMsi.download"
$fs = [System.IO.File]::Open($tmp, [System.IO.FileMode]::Create, [System.IO.FileAccess]::Write, [System.IO.FileShare]::None)
try {
$buffer = New-Object byte[] (1024*256) # 256 KB chunks
while (($read = $stream.Read($buffer, 0, $buffer.Length)) -gt 0) {
$fs.Write($buffer, 0, $read)
}
} finally {
$fs.Dispose()
$stream.Dispose()
$client.Dispose()
$handler.Dispose()
}
if (Test-Path $localMsi) { Remove-Item $localMsi -Force }
Move-Item $tmp $localMsi -Force
} catch {
Write-Error "Download failed: $($_.Exception.Message)"
exit 100
}
# Validate the download looks like a real MSI
if (-not (Test-IsMsi -Path $localMsi)) {
$size = (Get-Item $localMsi).Length
Write-Error "Downloaded file does not look like a valid MSI (size=$size bytes). The URL may be a landing page or error."
exit 101
}
# Remove MOTW just in case
try { Unblock-File -Path $localMsi -ErrorAction SilentlyContinue } catch {}
# Install silently with logging
Write-Output "MSI validated. Installing Nightfall Agent..."
$args = "/i `"$localMsi`" API_KEY=`"$apiKey`" COMPANY_ID=`"$companyId`" /qn /norestart /l*v `"$logFile`""
$proc = Start-Process "msiexec.exe" -ArgumentList $args -Wait -PassThru -NoNewWindow
switch ($proc.ExitCode) {
0 { Write-Output "Nightfall Agent installed successfully."; exit 0 }
1603 { Write-Error "Fatal error during installation (1603). See log: $logFile"; exit 1603 }
1618 { Write-Error "Another installation is already in progress (1618)."; exit 1618 }
1620 { Write-Error "Package could not be opened (1620). File may be invalid. See log: $logFile"; exit 1620 }
default { Write-Error "Installer returned exit code $($proc.ExitCode). See log: $logFile"; exit $proc.ExitCode }
}$msiPath="C:\Temp\NightfallAgent.msi"; Start-Process msiexec.exe -ArgumentList "/i `"$msiPath`" API_KEY=`"YOUR_API_KEY_HERE`" COMPANY_ID=`"YOUR_SECRET_VALUE`" /qn /norestart /l*v `"`"C:\Windows\Temp\Nightfall\NightfallAgent_Install.log`"`"" -WaitGet-Service Nightfall*$ProductName = "NightfallAI Agent"
# Function to retrieve installed products matching product name
function Get-MatchingProducts($name) {
Write-Host "Searching for products matching: '$name'..."
Get-WmiObject -Class Win32_Product -ErrorAction SilentlyContinue |
Where-Object { $_.Name -like "*$name*" }
}
# Function to uninstall a product by ProductCode
function Uninstall-Product($product) {
$name = $product.Name
$productCode = $product.IdentifyingNumber
if ($productCode) {
Write-Host "Uninstalling '$name' (ProductCode: $productCode)..." -ForegroundColor Green
Start-Process "msiexec.exe" -ArgumentList "/x $productCode /qn" -Wait -NoNewWindow
Write-Host "Uninstalled: $name" -ForegroundColor Green
} else {
Write-Warning "Skipping ${name}: missing ProductCode."
}
}
# Try finding the initial product
$products = Get-MatchingProducts -name $ProductName
# If not found, try old NightfallAI Agent name 'Agent'
if (-not $products -or $products.Count -eq 0) {
Write-Warning "No installed products found matching: '$ProductName'"
Write-Host "Trying to search for old NightfallAgent name : 'Agent'" -ForegroundColor Yellow
$products = Get-MatchingProducts -name "Agent"
}
# Final check before uninstall
if (-not $products -or $products.Count -eq 0) {
Write-Host "No matching products found for either '${ProductName}' or 'Agent'."
exit 1
}
foreach ($product in $products) {
Uninstall-Product -product $product
}
Client Secret
The Jamf Pro API client must have permissions to read device and computer inventory.
Log in to your JAMF Pro instance
Navigate to Settings > System > API Roles and Clients
Under the API Roles tab, click the + New button.
Configure the following:
Display Name: Nightfall API Role
Privileges: Grant access to:
Read Computer Inventory Collection
Click Save
Next, navigate to the API Clients tab and click the + New button.
Configured the following:
Display Name: Nightfall API Client
Log in to the Nightfall Console at https://app.nightfall.ai
Navigate to Settings → MDM Profile
Click Add MDM
Select Jamf Pro from the list of supported MDM providers
Enter the following information:
Jamf Pro URL: Your JAMF instance URL (e.g., https://yourcompany.jamfcloud.com)
Client ID: The Client ID you created in JAMF Pro
Client Secret: The Client Secret you created in JAMF Pro
Click Connect
Nightfall will validate the credentials and begin syncing device information automatically.
Important: This API-based connection enables Nightfall to automatically map user email addresses to devices. You do not need to deploy any additional scripts for user-to-device mapping when using this method.
Once connected, Nightfall will periodically sync device inventory from JAMF Pro. You can now proceed to deploy the Nightfall agent to your devices following the steps below.
This script checks if the required profiles are installed and that the endpoint agent is at the desired version.
Unpack the zip file provided and locate the mdm_pre_install_check_script.sh file under the .\\mdm_scripts\\ folder
On Jamf Pro, navigate to Settings > Computer management > Scripts
Click the + New button.
Enter a display name for the script (e.g., "Nightfall AI Pre-Installation Check").
Click on the Script tab.
Paste the contents of mdm_pre_install_check_script.sh into the script editor.
Click Save.
This script configures the target machine and prepares it to connect to your Nightfall instance once the package is deployed.
Locate the mdm_pre_installation_script.sh file under the .\\mdm_scripts\\ folder
On Jamf Pro, navigate to Settings > Computer management > Scripts
Click the New button.
Enter a display name for the script (e.g., "Nightfall AI Pre-Installation Script").
Click on the Script tab.
Paste the contents of mdm_pre_installation_script.sh into the script editor.
Click Save.
In the downloaded folder, locate the README.md under /Profiles to learn about the various MDM profiles available.
Choose NightfallAI_Profile_with_Browser_Extensions.mobileconfig.
Log in to your Jamf Pro account.
Navigate to Computers > Configuration Profiles.
Click the Upload button.
Click the Upload button and upload NightfallAI_Profile_with_Browser_Extensions.mobileconfig.
In the Scope tab, add the target devices or device groups to which this profile should be deployed.
Click Save.
Once assigned, profiles will be automatically deployed as part of the next Jamf inventory cycle.
Navigate to Computers > Policies.
Click the + New button.
Enter a display name for the policy (e.g., "Deploy Nightfall AI").
From the General tab, configure the Trigger and Execution Frequency as needed.
Click Package from the left pane & click on configure
Add Nightfall AI Agent package
Click on Scripts from the left pane & click on configure
Add Pre-Install Check Script and Pre-Install Script. Ensure the Priority is Before and the sequence is [ The scripts must be run once & in sequence to prepare the machine for the package install. ] -
Pre-Install Check Script
Pre-Install Script
Click on Scope and determine the Target, Limitations, and Exclusions per need.
Click Save.
mdm_pre_installation_script.sh
The script is used by MDMs to ensure that a macOS machine is in a clean state before installing the Nightfall Agent. It wipes any existing Nightfall installation and prepares a clean environment for a new install, including:
Loading API keys
Rebuilding folders
Resetting launch daemons
NightfallAI_Profile_with_Browser_Extension.mobileconfig
This profile is designed to pre-authorize and enable what the Nightfall Endpoint Agent requires on a macOS machine without needing user prompts.
Silently installs/enables the Nightfall browser extension
Allows the extension to run without prompts
Authorizes required permissions (content inspection, file uploads, scanning)
Grants macOS Privacy Permissions required by Nightfall:
Full Disk Access (FDA)
System Events/Automation Permissions
Application Control Permissions
Configures the payloads for browser + system integration
Prevents users from tampering with the security controls
After the action completes
Can block actions
Yes
No - monitor only
Prompt text scanning
Yes
Yes (requires OTEL_LOG_USER_PROMPTS=1)
Tool I/O scanning
Yes
Yes (requires OTEL_LOG_TOOL_DETAILS=1)
Cost and token tracking
No
Yes (costUSD, inputTokens, outputTokens)
Model name
No
Yes (e.g., claude-sonnet-4-6)
Complete session audit trail
Partial (hook points only)
As supported via OTEL
API error tracking
No
Yes (failed requests, retries)
Detect hook bypass
No
Yes, Hooks status is available via device list page (detects if hooks were disabled)
Not every agent supports both mechanisms. Use this matrix to understand what is available for each agent:
Agent
Hooks
OTel
Enforcement Options
Claude Code
Yes
No
Block or Monitor
Block sensitive data from being sent to AI models or external tools
Prevent shell commands that could leak credentials
Enforce MCP server allowlists in real time
Stop tool calls to unauthorized services before they execute
Track costs - token usage and dollar cost per prompt
Audit complete session activity including tool decisions and API calls
Monitor Claude Cowork - the only mechanism available
Detect hook bypass - identify when developers disable or circumvent hooks
Compliance logging - capture every prompt for regulatory requirements
The Nightfall agent registers handlers for four hook points. Each hook fires at a specific moment in the AI agent's workflow:
Hook Point
When It Fires
What It Scans
Can Block?
User Prompts
Before the prompt is sent to the AI model
Full prompt text
Yes
Tool Responses capture content after the tool has already executed - the action has completed and cannot be reversed. Nightfall still scans the output for policy violations and creates incidents, but blocking is not possible at this point.
When a hook fires, the following happens:
The AI agent (Claude Code, Cursor, or VS Code) pauses the action and sends the content to the Nightfall agent running on the endpoint.
The Nightfall agent evaluates the content against your active AI agent policies and enforces remediation actions such as block user prompts, tool calls or shell commands.
The agent returns a verdict:
Allow - the action proceeds normally.
Block - the action is denied. The end-user sees a message explaining why.
If a violation is detected, the incident is recorded in your Nightfall console regardless of whether the action was blocked or monitored.
If the Nightfall agent is temporarily unavailable or takes longer than 15 seconds to respond, the hook fails open - the AI agent action proceeds normally. This ensures that developer workflows are never blocked by infrastructure issues.
When the agent recovers, hooks resume normal enforcement automatically.
Claude Cowork is monitored through OpenTelemetry (OTel) rather than hooks. You need to configure OpenTelemetry for Claude Cowork. You can follow the steps available here to setup OTel https://claude.com/docs/cowork/monitoring#events
Capability
Hooks (Real-Time)
OTel Telemetry (Async)
Timing
Before the action executes
Capture screen recordings around endpoint exfiltration events and store them in your own cloud bucket.
Session Replay (shown in the console as Record Before & After) captures the user's screen around an endpoint exfiltration event so investigators can review what happened. You can store those recordings in a cloud bucket that your organization owns.
This capability is available for macOS and Windows endpoint policies.
Enable Session Replay for your organization in Endpoint settings.
Connect a storage bucket (or use Nightfall-managed storage, if it is enabled for your account).
Turn on Record Before & After on each endpoint exfiltration policy that should capture recordings, and choose the storage destination.
When that policy detects an exfiltration event, Nightfall records the screen for a window before and after the event and writes the recording to the selected bucket.
Open the event in Nightfall to play the recording.
If an event matches more than one policy with recording enabled, Nightfall can write the recording to each policy's selected bucket.
On macOS, the Nightfall agent requires Screen Recording permission to capture recordings.
Your bucket stores the session recordings captured around matching exfiltration events.
Nightfall writes a recording when a policy with Record Before & After enabled is triggered. The recording covers the configured window before and after the event.
Nightfall recommends enabling encryption on the bucket (for example, AWS SSE-KMS, Google CMEK, or Azure customer-managed keys). Encryption is a best practice and is not required to connect the bucket.
The Nightfall endpoint agent is installed and connected on the device.
Session Replay is enabled in Endpoint → Settings.
A storage destination is available: a connected customer bucket, or Nightfall-managed storage if it is enabled for your account.
The Nightfall user who connects buckets has bucket management access.
In Nightfall, open Endpoint.
Open the Settings tab.
Enable Session Replay / Record Before & After.
Nightfall accesses the bucket with a cross-account IAM role. No long-lived access keys are stored.
What you enter in Nightfall
Create an IAM policy that grants Nightfall access to the bucket. Replace YOUR_BUCKET_NAME and, if you use SSE-KMS, YOUR_KMS_KEY_ARN.
If the bucket does not use KMS, you can omit the KMSAccess statement.
In the AWS IAM console, create a role.
Trusted entity: AWS account
Nightfall accesses the bucket by impersonating a service account in your Google Cloud project.
What you enter in Nightfall
Create a GCS bucket in your project.
Create a dedicated service account (for example, nightfall-dlp-worker@YOUR_PROJECT.iam.gserviceaccount.com).
Grant that service account Storage Object Admin and Storage Legacy Bucket Reader on the bucket.
If the bucket uses a customer-managed encryption key, grant the Cloud Storage service agent Cloud KMS CryptoKey Encrypter/Decrypter on that key.
Enter the bucket name and service account email in Nightfall and connect the bucket.
Nightfall accesses the container with federated identity. No long-lived secrets are exchanged.
What you enter in Nightfall
Create a storage account and a container for recordings.
Create a managed identity or app registration and add a federated credential. Nightfall provides the OIDC issuer, audience, namespace, and service account values during setup.
Grant the identity Storage Blob Data Contributor and Storage Blob Delegator on the storage account.
Optionally grant Reader on the storage account so Nightfall can check lifecycle policies.
AI Governance is the Nightfall console for MCP (Model Context Protocol) servers on developer machines. It covers local stdio servers and remote HTTP/SSE servers used by clients such as Claude Code, Cursor, VS Code, Windsurf, Codex, Copilot, and others.
Go to AI Governance. With the current inventory experience you get:
Inventory, with sub-tabs for MCP servers, Hooks, and Plugins
Collections
Users & Devices
Settings (notification triggers and alert channels)
Some tenants still see the older Server Inventory tab (servers only, no Hooks, Plugins, or Settings). If that is what you have, ask your Nightfall account team to enable the current AI Governance experience.
This page is about what is actually running on endpoints. Sanctioned remote servers that you want clients to call through Nightfall are documented on .
Filter High or Critical risk, or look for the Shadow badge, when you want unsanctioned servers first.
Use risk plus the tool list when you need to know whether a server only reads data or can write and delete.
Use the Managed filter when you want the list of servers that came from an org-managed config file. Treat project-level configs as extra review when they name servers that are not on your approved list.
When a DLP alert involves an agent tool call, open the server here. You can see the device, the user, the tools, and the config file that was in place.
Put approved servers in a collection, then scope an endpoint exfiltration policy to all MCP servers, only those collections, or everything except those collections. Binding by fingerprint keeps the policy on the same server if someone renames it in mcp.json.
MCP data shows up only when the endpoint agent can collect it:
macOS: Nightfall Agent v1.2.12.11 or later, plus MDM Profile v3. The agent can auto-update. The profile does not. IT or SecOps has to deploy v3. The profile ships in the macOS agent bundle from v1.2.12.9 onward.
Windows: Nightfall inventories MCP on Windows endpoints the same way. Confirm the minimum Windows agent build with your Nightfall account team.
Hooks and Plugins need the current inventory experience and the extra telemetry those views use. If servers appear but Hooks and Plugins do not, check the tenant experience first, then the agent version with Nightfall.
Inventory > MCP servers is the org-wide table. Each row is one server. The name cell can also show Managed and Shadow.
Recognized clients include Claude Code, Cursor, VS Code, Claude Cowork, Claude (including Claude Desktop), Windsurf, Codex, Copilot, and Antigravity. Anything else stays in the unrecognized list.
stdio: count of local process starts. The detail header labels this Process Starts. One typical agent session that uses the server is one start.
http / sse: bytes sent and bytes received (shown with up/down markers). High outbound volume is the number to look at if you are worried about data leaving the device.
Open a row for the server page. Tabs are Overview and Devices.
About: description from the public MCP registry. If the server is not listed, the card says so and points you at Identity.
Identity: Endpoint (remote URL, HTTP servers only), Package, Version, Source (repository link), Transport, Fingerprint (the server id), and Configured As (each configured name plus how many tools that name has).
Risk score: composite level and the signal groups behind it.
The header actions are Add to collection, Override risk, and Override provenance.
Who is using the server, on which endpoint, through which host app. Rows can also show provenance, risk, clients, and a logo when Nightfall can resolve one from the remote URL.
Each observation is tagged Config file, Process start, and/or Network, depending on how it was seen.
Nightfall keeps versions of the config files that mention the server, for example ~/.claude.json, .cursor/mcp.json, or the VS Code user-level mcp.json.
Files group by client and by scope: Global (all projects for that user) or Project (one repo or workspace). You get the path, the scope badge, last modified, and the file body at each version (v1, v2, and so on).
The Risk score card uses Known, Low, Medium, High, or Critical.
Signals are grouped as:
Each group has a contribution. Thin evidence gets a low confidence badge. Groups that do not apply are greyed out.
The written explanation is generated after the score. While that runs, the card shows Analyzing risk and the group breakdown is still the source of truth. If explanation generation fails, the breakdown stays and Nightfall retries on the next recompute.
To override: Override risk, pick Critical, High, Medium, or Low (not Known), and enter a reason. The card then shows the computed level, the level you set, who did it, when, and the reason. Revert to auto-detected clears the override.
Every discovered tool gets a category and a severity.
Category: Read-only, Read-write, or Destructive
Severity: Low, Medium, High, or Critical
Filter pills on the Tools card jump to a category or severity. You can override both values on a tool and clear the override later.
Provenance is where the server came from:
First-party: an admin added it as your organization's own
Official: matches a verified registry entry
Community: published in a community marketplace
Unknown: source could not be determined
Admins can override provenance and revert it.
Managed means the install came from an org-managed config file (admin or MDM). You can filter servers, hooks, and plugins to Managed.
Shadow means the server is not tied to a recognized MCP client, so it is running outside governed tooling. That raises its risk score.
A developer-added server inside Claude Code or Cursor is usually neither Managed nor Shadow.
Inventory > Hooks lists event-triggered commands that clients run during an agent session (for example a shell command before a tool call).
Columns:
Event: lifecycle event. Org-deployed hooks can show Managed
Handler: how the hook is invoked
Command: what it runs
Client: which AI application owns it
Filter by event or Managed. Open a hook for the full definition and the device list.
Inventory > Plugins lists extensions installed into AI clients. A plugin can ship its own MCP servers and hooks.
Columns include name and marketplace, Status, Trust, Provenance, client, and device count.
Status values are Available, Installed, and Enabled. The list hides Available (seen in a marketplace, not on a device) until you add it in the Status filter.
Trust is Allowed or Blocked, from the client's own trust state.
Open a plugin for the servers it bundles (transport, risk, provenance), the hooks it bundles (event and handler), and the devices that have it.
Users & Devices is the fleet view. Open a device for MCP servers, Hooks, and Plugins, each with a count.
Config files on that device are scanned. Scan status is shown, including when a scan produced a violation.
Collections are named sets of servers. You use them in reports and in endpoint exfiltration policies.
From a server page, Add to collection has two steps: Group selection, then Tool selection.
On group selection you either bind the entire server by fingerprint (default; every configured name stays in the collection) or pick specific configured names. Fingerprint-bound entries show Bound by fingerprint in collection management.
Manage collections under AI Governance > Collections.
In an endpoint exfiltration policy, MCP scope is:
All MCP servers
Specific MCP servers (the collections you pick)
All except these MCP servers
You can create a collection from the policy wizard (Create new collection). You can also add tool-name patterns. Those patterns are exclusions when the scope is All except these MCP servers. Details: .
AI Governance > Settings has two parts.
Notification triggers (nothing is sent until you save a preference; a company with no saved preferences is opted out):
Alert channels use Nightfall's standard integrations. You need at least one channel or nothing is delivered. Typical channels are email, Slack, and webhook.
A practical first save is config file Added, hook Added, and plugin Installed.
Opt out of all notifications clears every trigger.
This guide walks an MDM administrator through deploying Nightfall's Cursor hooks to corporate-managed developer devices, end to end. It covers all five supported MDMs in detail. The deployment package ships as a zip (Hooks Setup/cursor/) containing this payload, the install scripts, and a README.md quick reference. This guide is the long-form companion to that README.
This guide is for Cursor, which requires a MDM deployment of a system-level hooks.json.
Use the automatic path for Claude Code and VS Code. Use this guide to add reliable hook coverage for Cursor on managed devices.
Cursor reads its hook configuration from a single file at a fixed path and a fixed name (
Cursor
Yes (via Claude Code)
No
Block or Monitor
VS Code
Yes (via Claude Code)
No
Block or Monitor
Claude Cowork
No
Yes
Monitor only
Tool Calls
Before a tool executes
Tool name and input parameters
Yes
Tool Responses
After a tool finishes executing
Tool name and output content
Yes (Not supported in VS Code Copilot)
Model Responses
After a model finishes evaluating task
Model response
No
Shell Commands
Before a shell command executes
Full shell command string
Yes
Read Computers
API roles: Select the newly created role.
Enable/disable API Client: Enable the API client.
Click Save
Copy the Client ID and Client Secret. You will need these in the next step.
The MDM profile has to be deployed on target machines prior to deploying additional payload. In Jamf, you can enforce this requirement through the creation of a Smart Group in which you can set the presence of the profile created above as a pre-requisite for any other payload targeting the group.
Enforcement
Works with monitor, warn, and block policies
Storage
Amazon S3, Google Cloud Storage, and Azure Blob Storage
Nightfall-managed storage
Available when Nightfall has enabled it for your account
Displays
Multiple monitors
Playback
Exfiltration event Replay view, including timeline controls and event markers
The Nightfall user who plays recordings has screen recording access.
On macOS, Screen Recording permission is granted to the Nightfall agent.
Review Snapshot Frequency (every 1–5 seconds) and the Recording Window shown for the time before and after an event.
Snapshot frequency is configured at the organization level and applies to policies that have recording enabled.
Go to Settings → Storage Buckets.
Click Connect Bucket (or use the command palette and search for Connect Bucket).
Choose Amazon S3, Google Cloud Storage, or Azure Blob Storage.
Complete the cloud setup for that provider, then enter the connection details in Nightfall.
Nightfall validates access (write, read, and delete) before saving the bucket.
A successful connection may still show a warning if the bucket's lifecycle policy could remove recordings earlier than 180 days. You can continue and adjust the lifecycle policy in your cloud console.
Bucket statuses:
Active — Nightfall can store recordings.
Inactive — Access failed a health check. Use Reconnect after you restore permissions.
Disabled — The destination is turned off for the account.
You cannot delete a bucket that is still selected on a policy. Remove it from those policies first.
Create or edit an endpoint exfiltration policy.
On the Automated Actions step, enable Record Before & After.
Under Storage Destination, select the bucket for this policy.
If Nightfall-managed storage is available, you can keep Use Nightfall-managed storage (default) selected instead of a customer bucket.
Save the policy.
The policy toggle is available only after Session Replay is enabled for the organization. If no customer bucket is connected and Nightfall-managed storage is not available, connect a bucket before you save the policy.
Open Exfiltration Prevention and select an event.
On the event summary, click Replay.
Use the timeline to move through the recording. If the device has more than one display, switch between monitors in the player.
If the recording is still arriving from the device, the player shows that screenshots are still uploading. Refresh the event after a few minutes.
Account ID: 053737762392 (Nightfall).
Enable Require external ID and paste the External ID shown in Nightfall (your Company ID).
Attach the IAM policy from the previous tab.
Copy the role ARN into Nightfall and connect the bucket.
roles/iam.serviceAccountTokenCreator on itself).Allow Nightfall's hub service account to impersonate your service account:
Client ID
Application (client) ID of the identity Nightfall uses
Subscription ID and Resource group
Optional. Include these if you want Nightfall to check lifecycle policies
If you use customer-managed keys, grant Key Vault Crypto Service Encryption User on the key.
Enter the values in Nightfall and connect the bucket.
macOS devices are not producing recordings
Confirm Screen Recording permission is granted to the Nightfall agent.
Player says screenshots are still uploading
Wait for the post-event window to finish, then refresh the event.
Player cannot load the recording
Confirm the bucket is Active and that lifecycle rules have not removed the recording.
You cannot delete a bucket
Remove the bucket from every policy that uses it as the storage destination, then delete it.
Platforms
macOS and Windows
Policies
Endpoint exfiltration policies
Triggers
Bucket name
Name of the S3 bucket
IAM Role ARN
Role Nightfall assumes to access the bucket
External ID
Bucket name
Name of the GCS bucket
Service account email
Service account Nightfall impersonates
Storage account name
Azure storage account
Container name
Blob container for recordings
Tenant ID
Record Before & After is disabled on the policy
Enable Session Replay in Endpoint → Settings.
Nightfall asks you to connect a bucket before saving
Connect a bucket in Settings → Storage Buckets, or select Nightfall-managed storage if it is available.
Bucket is Inactive
Any endpoint trigger that produces an exfiltration event, including browser uploads, clipboard paste, desktop apps, cloud sync, removable media, print, and Git push
Filled automatically with your Nightfall Company ID
Microsoft Entra tenant ID
Restore write, read, and delete access in your cloud account, then use Reconnect. Recordings may not store correctly while the bucket is inactive.
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "S3Access",
"Effect": "Allow",
"Action": [
"s3:PutObject",
"s3:GetObject",
"s3:DeleteObject",
"s3:ListBucket",
"s3:GetBucketLocation",
"s3:GetLifecycleConfiguration"
],
"Resource": [
"arn:aws:s3:::YOUR_BUCKET_NAME",
"arn:aws:s3:::YOUR_BUCKET_NAME/*"
]
},
{
"Sid": "KMSAccess",
"Effect": "Allow",
"Action": [
"kms:GenerateDataKey",
"kms:Decrypt",
"kms:DescribeKey"
],
"Resource": "YOUR_KMS_KEY_ARN"
}
]
}gcloud iam service-accounts add-iam-policy-binding YOUR_SERVICE_ACCOUNT_EMAIL \
--role="roles/iam.serviceAccountTokenCreator" \
--member="serviceAccount:saas-hub-operator@gcs-byod-prod.iam.gserviceaccount.com"Provenance
First-party, Official, Community, or Unknown. See .
Users
How many users have this server.
Clients
Recognized AI clients plus any unrecognized process names. A +N chip means more clients than the row can show.
Volume
For stdio: how many times the process started. For remote: data sent and received.
Last Activity
Last time any device used the server.
Clients: recognized clients and a count of unrecognized ones.
Collections: collections this server is bound to.
Behavioral
What is it doing?
Devices: how many endpoints have it
Server Name
Name reported by the device (from mcp.json, claude.json, or similar). Remote container images often show as an image name. Version appears under the name when Nightfall has it.
Type
Transport. stdio is a local subprocess (no outbound network). http / sse are remote and send data off the device.
Risk
Capability
What can it do?
Provenance
Who made it?
Governance
MCP Servers
Config file changes: Added, Removed, Updated. Runtime detections: stdio servers, Remote servers
Hooks
Hook changes: Added, Removed, Updated
Plugins
If the Mac MDM profile is still below v3, AI Governance stays empty for those devices even when the agent is current and the feature is on for your tenant.
Known, Low, Medium, High, or Critical. A small dot on the badge means an admin overrode the computed level.
Is it sanctioned?
Plugin changes: Installed, Enabled, Disabled, Uninstalled
hooks.jsonStage the payload. Your MDM's file-distribution (or app-deployment) feature drops Nightfall's hooks.json at a staging path on each device.
Run the merge script. A script provided in the package splices Nightfall's entries into Cursor's hooks.json at the path Cursor actually reads.
The file Cursor reads (hooks.json) is shared - another security vendor or your own org policy may already own entries in it. And because the filename and path are dictated by Cursor, you can't rename or relocate it without Cursor ceasing to read it.
So the install scripts merge: they drop any existing Nightfall-marked entries, then append the staged Nightfall entries, leaving every other vendor's entries untouched. This makes re-runs idempotent - periodic re-execution never accumulates duplicates.
Before deploying the Cursor hooks payload:
The Nightfall endpoint agent is already installed and running on the managed devices. The agent owns the nightfall-hook-relay binary the hooks invoke.
You've selected the MDM scope (device group / smart group) that will receive the deployment.
jq is present on macOS devices where a hooks.json may already exist. The macOS install script refuses to run — rather than clobber another vendor's entries - if a target hooks.json exists and jq is not installed. (Greenfield devices with no existing hooks.json do not need jq.)
The scripts are MDM-agnostic - the same install.sh works whether your MDM is Rippling, Jamf Pro, Kandji, or Workspace ONE. The per-MDM sections below show which MDM feature to wire each script into.
Nightfall registers four Cursor events. The two pre-action events carry failClosed: true, which blocks the action if the hook crashes, times out, or returns invalid JSON.
Event
When it fires
failClosed
beforeSubmitPrompt
Before a prompt is submitted to the model
true
preToolUse
Before a tool executes
All four invoke the same command: nightfall-hook-relay --source cursor.
failClosed: true on the pre-action events (beforeSubmitPrompt, preToolUse) means the action is blocked if the hook can't complete cleanly. The post-action events (postToolUse, afterAgentResponse) observe content after the action has already happened, so they monitor only there is nothing left to block.
macOS
Windows
Staging path (MDM drops the payload here)
/opt/nightfall/hooks/cursor/hooks.json
C:\Nightfall\Hooks\cursor\hooks.json
Target path (Cursor reads from here)
/Library/Application Support/Cursor/hooks.json
The target path and filename are dictated by Cursor and must not be changed.
On macOS, a greenfield device (no existing target hooks.json) is handled by a plain cp - no jq required. If a target already exists, the script requires jq to merge and refuses to run without it. On Windows, the merge runs in PowerShell, writes the result as UTF-8 without a BOM, then locks the file down with icacls.
Every MDM follows the same two-step wiring: distribute the payload to the staging path, then run the install script to merge it into Cursor's hooks.json. The install scripts hard-fail unless run as root (macOS) or SYSTEM / Administrator (Windows), so always run them in a System / SYSTEM context.
macOS
Distribute the payload — Use Rippling's file/app distribution to place payloads/hooks.json at /opt/nightfall/hooks/cursor/hooks.json.
Run the merge — Create a Custom Script that runs scripts/macos/install.sh at System scope, triggered on enrollment and daily.
Windows
Distribute the payload to C:\Nightfall\Hooks\cursor\hooks.json.
Run the merge - Create a PowerShell Script that runs scripts/windows/install.ps1 at SYSTEM scope.
macOS
Distribute the payload to /opt/nightfall/hooks/cursor/hooks.json (e.g. via a package or a Files and Processes distribution).
Run the merge - Add scripts/macos/install.sh as a Script, then attach it to a Policy scoped to your device group with the triggers Recurring Check-in and Enrollment Complete.
macOS - Kandji's Custom Script library item pairs an audit script with a remediation script, which matches the package's presence-check model exactly:
Distribute the payload to /opt/nightfall/hooks/cursor/hooks.json (Custom App or file distribution).
Audit - Set scripts/macos/audit.sh as the Audit Script. It exits 0 when Nightfall's command is already present and exits 1 when remediation is needed.
Remediation - Set scripts/macos/install.sh as the Remediation Script. Kandji runs it only when the audit reports drift.
Windows - Wire into a Win32 / Proactive Remediation (Detection + Remediation):
Distribute the payload to C:\Nightfall\Hooks\cursor\hooks.json (e.g. a Win32 app).
Detection - Use scripts/windows/detect.ps1 as the Detection script. It exits 0 (present) when Nightfall's command is already in hooks.json and exits 1 to trigger remediation. Run it in the SYSTEM context (64-bit PowerShell).
Remediation - Use scripts/windows/install.ps1 as the Remediation script, also in the SYSTEM context.
Workspace ONE covers both platforms via its Scripts feature, run in the System / SYSTEM context with Periodic and Enrollment triggers.
macOS
Distribute the payload to /opt/nightfall/hooks/cursor/hooks.json.
Run the merge - Add scripts/macos/install.sh as a Script in the System context, scheduled Periodic + on Enrollment.
Windows
Distribute the payload to C:\Nightfall\Hooks\cursor\hooks.json.
Run the merge - Add scripts/windows/install.ps1 as a Script in the SYSTEM context, scheduled Periodic + on Enrollment.
Open the Devices page in the Nightfall console. Each device shows a per-client hook status indicator - a healthy status for Cursor means the deployment is working on that device. A healthy Cursor hook status on the Devices page confirms the payload was staged, the merge script ran, and Cursor is reading Nightfall's entries.
The audit/detection scripts (audit.sh / detect.ps1) check for the presence of Nightfall's command in hooks.json (a grep / regex match), not byte equality. Byte equality with the staged payload isn't meaningful because hooks.json is shared with other vendors.
The install scripts are idempotent: each run drops any existing Nightfall-marked entries and re-appends the staged ones, so periodic re-execution never accumulates duplicates and never disturbs other vendors' entries.
If the staging payload hasn't been deployed yet, the audit/detection scripts report present / exit 0 rather than failing. Remediation couldn't succeed without the staged file, so this stops the MDM from looping on a state it can't fix from the device.
To remove Nightfall's Cursor hooks, hand-edit hooks.json on the device (or push an edited copy via your MDM) and remove every entry whose command is nightfall-hook-relay --source cursor. Leave all other vendors' entries - and your own org policy's entries - untouched.
The nightfall-hook-relay binary stays installed; the Nightfall endpoint agent owns its lifecycle.
A scripted rollback may be added in a future release. For now, removal is a manual entry edit.
Symptom
Likely cause
Resolution
macOS install exits with "jq is not installed"
A hooks.json already exists and jq is missing, so the script refuses to merge
Install jq on the device and re-run the install script
Install exits with "must run as root" / "administrator privileges"
Script ran in a user context
Cursor enterprise hooks bug (Feb 2026): Hooks configured in Cursor's admin dashboard sometimes don't materialize at the expected endpoint path. MDM-deployed hooks.json is the reliable path until Cursor resolves this.
Cursor cloud agents don't yet honor team/enterprise-managed hooks — only a project-committed .cursor/hooks.json runs in cloud sessions. The MDM deployment in this guide covers local Cursor sessions on managed devices.
payloads/hooks.json # Nightfall's Cursor hook entries
scripts/macos/install.sh # MDM-agnostic merge (idempotent on re-run)
scripts/macos/audit.sh # presence check (grep)
scripts/windows/install.ps1 # MDM-agnostic merge (idempotent on re-run)
scripts/windows/detect.ps1 # presence check (regex match)
README.md
User session detection allows Nightfall to distinguish between corporate and personal account activity on supported web domains. When enabled in an Endpoint Exfiltration policy, Nightfall uses browser session context to determine whether data is being uploaded from (or pasted to) a corporate account or a personal account. This lets you create policies that, for example, only trigger on uploads from corporate Google Drive or only flag paste actions to personal ChatGPT.
Session detection requires the Nightfall browser extension to be installed and connected. It works by inspecting the active browser session on supported domains to determine account ownership.
Session detection is available on the following 32 domains, organized by category:
The supported domains pill in the policy UI groups these into display categories:
Google Workspace: Docs, Gmail, Calendar, Meet, Drive, Keep
Microsoft 365: Teams, SharePoint, Outlook, OneDrive, Office apps
Cloud Storage: Box, Dropbox, iCloud
AI Assistants: Claude, ChatGPT, Gemini, Copilot, Perplexity
When creating or editing an Endpoint Exfiltration policy, the Trigger step is where you configure session detection. The Trigger step contains two main sections: Asset Origin and Action.
The Action dropdown selects the type of endpoint activity to monitor. Available actions:
AI Agent Security - Monitors AI agent activity (Claude Code, Cursor, VS Code, Claude Cowork)
Browser uploads to - File uploads through the browser
Cloud syncing to - Cloud sync applications (Google Drive, Dropbox, OneDrive, Box, iCloud)
Git Push to - Git push operations to remote repositories
The Asset Origin section lets you scope monitoring to assets originating from specific sources:
Select Source (Domain / URL-Based) from the scope dropdown
Choose Source in or Source not in to include or exclude specific domain collections
Select a domain collection from the collection picker
When you select collections, each collection pill displays with color coding:
Violet: The collection contains domains that support session detection and session check is enabled
Default: Standard collection display
When the selected source collections include domains that support session detection, the Corporate accounts only toggle appears. Enabling this toggle restricts the policy to only trigger on data originating from corporate account sessions on supported domains.
The toggle only appears when:
The action is Browser uploads to, Paste to, or Git Push to
The scope is set to Source in (not "Source not in" or "Any source")
At least one selected collection contains session-detection-supported domains
For actions like Browser uploads to, Paste to, and Git Push to, you can also scope the destination:
Select the action type from the dropdown
Choose destination scope (Any, specific collections included, or specific collections excluded)
Select domain collections for the destination
When the selected destination collections include domains that support session detection, the Personal accounts only toggle appears. Enabling this toggle restricts the policy to only trigger on data sent to personal account sessions on supported domains.
The toggle only appears under the same conditions as the Corporate toggle (appropriate action type, "Source in" scope, and session-detection-supported domains in the selected collections).
When you select a domain collection, the UI shows an "X of Y domains supports session detection" indicator. This tells you how many of the domains in your selected collection are in the supported domains list. For example, if your collection has 10 domains and 6 are in the supported list, it shows "6 of 10 domains supports session detection."
Content Scanning configuration has been moved from the Scope step to the Trigger step, keeping all trigger-related settings in one place.
By default, with no session detection enabled, Nightfall monitors all uploads and paste events across all account types on all configured domains - it does not distinguish whether a user is in a personal Google account or a corporate Workspace account.
Session detection lets you scope monitoring to an account context. There are two independent toggles, each controlling a different axis:
These toggles are independent - enabling one does not affect the other.
Behavior by state
Session detection coverage is domain-dependent. Not all domains in a collection support session detection. The UI shows how many domains in your selected collection are covered (e.g., "3 of 12 domains across 2 collections support session detection"). Domains outside coverage are always monitored for all account types, regardless of toggle state. If none of the selected domains support session detection, the toggle has no effect and all domains are monitored for all account types.
Destination toggle - personal account monitoring
The most common pattern. Enable this when your primary concern is data ending up in a personal account on a domain your organization also uses corporately.
Common policies seen in practice:
"Block Uploads to Personal Storage Accounts"
"PII to Personal Accounts"
"ChatGPT/Claude/Dropbox - Uploads to Personal Accounts"
"PHI Upload to Personal Account"
Why this matters: On domains like drive.google.com, dropbox.com, or chatgpt.com, the same domain hosts both corporate and personal accounts. Without session detection, a policy scoped to these domains fires on all uploads - including uploads from an employee using their company-issued Google Workspace account, which is typically approved. Enabling the destination toggle narrows the policy to only fire when the upload goes into a personal session, eliminating noise from legitimate corporate activity.
Recommended use:
Cloud storage: Separate a policy for drive.google.com personal from corporate Workspace. Enable destination toggle; scope collection to personal Google accounts.
AI tools: Most AI tools (ChatGPT, Claude) don't have a corporate/personal domain split - chatgpt.com is used by both. If your organization has a corporate ChatGPT Enterprise deployment on a subdomain, use the destination toggle on the public domain to filter for personal sessions only.
Sanctioned vs. unsanctioned: Some organizations run two policies on the same domain - one with session detection (alert-only for personal account use) and one without (broader coverage for truly unsanctioned destinations).
Source toggle - corporate account monitoring
Enable this when you want to track data that originated from a corporate account, regardless of where it ends up - including destinations that don't support session detection.
Common policies seen in practice:
"Personal Account Upload From Corporate Account"
"Block Uploads of Corporate Docs to Unsanctioned Apps"
"Monitor Uploads of Customer Lists to Unsanctioned Cloud Storage"
"Departing Users - Block Google Workspace"
Why this matters: The destination toggle only catches events where the destination domain supports session detection. If an employee copies a file from their corporate Google Drive and uploads it to a small SaaS tool or a domain that Nightfall can't distinguish account types on, the destination toggle misses it. The source toggle catches it because it evaluates account context at the point of copy, not the point of upload.
This is also the appropriate pattern for departing user policies, where the goal is to track all outbound movement from corporate accounts during an offboarding window - regardless of destination.
Recommended use:
Departing users: Enable source toggle scoped to all corporate domain collections. Apply to a user group or device scope targeting the departing user.
Broad corporate data egress: When you want to monitor "anything that left a corporate account session today" as an audit trail, source-only gives you the widest coverage without depending on destination session support.
Important: Source-only policies deliberately monitor destinations outside Nightfall's session detection coverage. This is by design, not a misconfiguration. Do not add a destination toggle to these policies expecting it to refine them - it will instead restrict coverage and may miss the exfiltration paths the policy was built to catch.
Applies to: Browser Uploads, Clipboard Paste, Git Push Monitoring
Session detection works identically for these three triggers. For clipboard paste, the source toggle checks which account session the copied content came from; the destination toggle checks where the paste event lands. Given that clipboard events often land on domains with limited session detection support (note-taking apps, internal tools, miscellaneous SaaS), source-only session detection is generally more effective for clipboard monitoring than destination-only. For git push monitoring, content scanning is not supported - Nightfall monitors the source code originating from a corporate organization and subsequently getting transferred to a non-corporate organization or repository.
The toggle only appears when all three conditions are met:
The action type supports session detection (Browser uploads, Paste to browser)
The collection scope is set to Source in (specific included collections)
At least one domain in the selected collections supports session detection
If your selected collections don't include any of the 32 supported domains, the toggle will not appear.
This indicator shows how many domains in your selected collection are in Nightfall's supported domains list. Only those domains will have session-level account detection. Other domains in the collection will still be monitored but without corporate/personal distinction.
Check the following:
Supported domains: Verify the source domains are in the supported list above
Browser extension: Ensure the Nightfall browser extension is installed, enabled, and connected on the user's device
Correct browser: Session detection requires a supported browser with the extension (Chrome, Edge, Firefox). Safari require the extension to be installed separately
Not incognito
Git Push to: Yes, session detection is available
Print: No. Print operations don't have browser context
To removable media: No. File transfers to external drives don't involve browser sessions
CLI Transfer / AirDrop / Bluetooth: No. These triggers do not use browser session context. Corporate accounts only and Personal accounts only do not appear.
See the Supported Domains section above for the full list of 32 supported domains organized by category.
The Corporate/Personal accounts only toggle will not appear. The policy will still work for monitoring the selected domains, but without the ability to distinguish between corporate and personal accounts.
Session detection is not available in the following scenarios:
Actions without browser context: Cloud syncing, Print, To removable media, Uploads to desktop app, CLI Transfer, AirDrop, and Bluetooth operate outside the browser and cannot access session information
AI Agent Security: This action type uses hooks and OpenTelemetry for monitoring, not browser context
Domains not in the supported list: Even with the browser extension installed, session detection only works on the 32 listed domains
Perform insider risk investigations and threat hunting across all detected data exfiltration events — not only policy-triggered alerts.
Forensic Search provides a searchable timeline of detected data exfiltration events across your employee base. The search events include all events for all supported exfiltration vectors — not only policy-triggered alerts.
Security teams use Forensic Search to investigate how organizational data moves to external destinations such as cloud storage platforms, SaaS applications, and external email systems.
The interface allows analysts to search, filter, and review exfiltration events to determine:
which user moved data
which device performed the action
where the data was sent
whether sensitive data was involved
This enables rapid investigation of insider risk incidents and potential data exfiltration activity.
Forensic Search with Date Range and Actions filter applied.
Use the following steps to quickly investigate suspicious data movement.
Navigate to Discovery → Forensic Search.
Select the user of interest with User filter.
Set the Time Range to Last 7 days.
Add a Risk filter and select:
Security teams use Forensic Search to investigate how organizational data moves to external destinations and to identify potential data exfiltration activity.
Common investigation scenarios include:
Investigating departing employees
Reviewing unusual data transfer alerts
Performing threat hunting for data exfiltration
Auditing data movement to external services
Forensic Search tool zeroing in on a suspicious cloud sync activity.
Forensic Search allows analysts to reconstruct how data moved outside the organization by examining sequences of exfiltration events.
Data exfiltration rarely occurs as a single action. Instead, it typically appears as a pattern of related events occurring over a short period of time.
Security analysts often look for the following behavioral patterns when investigating potential exfiltration.
Most investigations follow this workflow:
Identify suspicious data movement or receive an alert.
Filter events by user and/or time range.
Review event details and destinations.
Identify patterns of data movement.
This workflow allows analysts to quickly determine whether activity represents legitimate work or potential data exfiltration.
To assist in identifying potentially risky behavior, Nightfall assigns a risk score to individual exfiltration events observed in Forensic Search. Each event receives a risk level that helps analysts prioritize investigations and quickly surface higher-risk data transfers.
Event-level risk scoring is currently in beta and is intended to provide investigation guidance rather than definitive risk determinations. Analysts should evaluate events within the broader context of user activity and look for patterns of behavior across multiple events, rather than relying on a single event score.
In the current release, event risk scores are calculated are based on two primary signals:
Application Risk Level
User Session Context (Corporate vs Personal Account)
These signals help determine whether data is being transferred to a higher-risk application or outside corporate identity boundaries.
Every destination application detected in an exfiltration event inherits a baseline risk level from App Intelligence.
App Intelligence continuously discovers and classifies the web applications employees interact with. Each application is categorized based on its function and typical data exposure risk, such as:
Cloud storage
File sharing
Developer tools
GenAI and AI Agent tools
Applications that enable easy external data transfer or lack strong identity controls typically carry higher baseline risk.
Risk scoring also considers whether the user is operating within a corporate identity boundary.
When available, Nightfall determines whether a user is authenticated to a corporate account or a personal account within the destination application.
Examples:
Transfers to personal accounts represent a significantly higher risk of data exfiltration because the organization does not control those accounts.
Investigators can export results using Export Events.
Exports include:
event fields
timestamps
risk scores
Exports are commonly used for:
incident response documentation
compliance reporting
deeper analysis in SIEM platforms
Exports respect active filters, allowing analysts to export specific investigation scopes.
Open Forensic Search.
Set the time range to Last 30 days.
Filter by the employee's email.
Review the timeline histogram for activity spikes.
Set the time range to Last 7 days.
Review the timeline for late-night activity.
Zoom into suspicious time windows.
Filter by High and Critical risk events.
Filter by Upload or Cloud Sync.
Filter by Critical and High risk events.
Look for sequential transfers to external services.
Review event details to confirm file types and destinations.
Events can be searched for up to 180 days. Currently, the earliest available events begin on February 6, 2026, so searches cannot return events earlier than that date.
Events typically appear within 30 minutes of occurring.
Yes. Events matching current filters can be exported to CSV.
Saved searches are planned for a future release.
Access is controlled through Nightfall role-based permissions.
No. It must be explicitly enabled in endpoint exfiltration policies.
Session differentiation only applies to supported domains and actions. If unavailable, the field remains empty.
Yes. Differentiation is based on account session, not just domain.
Yes. Use Domain in with Corporate Domains and enable User Session Check.
Nightfall automatically populates the Corporate Domains collection by analyzing user email addresses and email alias domains from all connected identity providers (IdPs), including Okta, Entra ID, and Google Directory. Any domain or alias domain associated with users in these directory services is treated as a corporate domain.
The initial population happens when the Nightfall endpoint agent is first enabled (on the first provisioned OS, macOS or Windows). At that time, Nightfall fetches all user email and alias domains from the connected identity providers and populates the Corporate Domains collection.
After the initial population, the collection is periodically refreshed (hourly) to capture any newly discovered domains or updates from the connected identity providers.
Yes. All supported browsers provide identical protection across file uploads, clipboard actions, and personal vs. business enforcement.
true
postToolUse
After a tool finishes executing
-
afterAgentResponse
After the agent returns its response
-
C:\ProgramData\Cursor\hooks.json
Re-run in the System (macOS) or SYSTEM (Windows) context via your MDM
Install exits with "payload not found"
The payload wasn't staged before the script ran
Deploy hooks.json to the staging path first, then re-run
Windows hooks.json fails to parse on re-run
A UTF-8 BOM was written by an older PowerShell 5.1 run
Re-run the current install.ps1 — it strips the BOM on read and writes UTF-8 without a BOM
Cursor hook status not showing in console
Hooks not yet merged, or agent not connected
Confirm the install script ran successfully and the Nightfall agent is running on the device
Paste to - Clipboard paste actions (browser or desktop apps)
Print - Print operations
To removable media - File transfers to USB/external drives
Uploads to desktop app - File uploads through thick/desktop applications
CLI Transfer - File upload or download through selected CLI tools (scp, curl, wget, rsync, aws s3, npm)
AirDrop - File transfers sent with Apple AirDrop
Bluetooth - Bluetooth file transfers (not pairing or audio)
Incognito/private browsing: Browser extensions are typically disabled in private windows by default
Firefox/Safari without extension: These browsers require separate extension installation;
Domain collections with "Source not in" scope: Session check toggles only appear when using "Source in" (include) scope, not "Source not in" (exclude) scope
Category
Domains
Google Workspace
*.google.com, docs.google.com, drive.google.com, mail.google.com, calendar.google.com, meet.google.com, cloud.google.com, keep.google.com, gemini.google.com
Microsoft 365
*.microsoft.com, teams.microsoft.com, teams.live.com, *.cloud.microsoft.com, *.cloud.microsoft, *.officeapps.live.com, *.sharepoint.com, *.live.com, outlook.office.com, outlook.office365.com, outlook.cloud.microsoft, onedrive.live.com
Apple
icloud.com
Cloud Storage
box.com, dropbox.com, *.dropbox.com
AI Assistants
chat.openai.com, chatgpt.com, claude.ai, perplexity.ai
Browser uploads to
Yes
Requires browser extension
Paste to (Browser)
Yes
Corporate accounts only (source)
Only tracks events where the file or content originated from a corporate account session
You care about where data came from
Personal accounts only (destination)
Only tracks events where the upload destination is a personal account session
Off
Off
All events on all domains, no account-type distinction
Off
On
Critical
High
Sort the event table by Timestamp to review the most recent events first.
Scan the Destination column for external services such as:
personal cloud sync
personal accounts
file-sharing sites
Click any event to open the Event Detail Panel.
Review the following fields:
User – who performed the action
Asset – what file or content was transferred
Destination – where the data was sent
If suspicious activity is confirmed, include all events by deleting the Risk Filter, and click Export Events to download a CSV for documentation or further investigation.
Identifying early adopters of Gen AI and AI Agent tools
Investigating suspicious cloud storage activity
Export events for investigation documentation.
Filter to Critical and High risk events.
Review destinations and file metadata.
Zoom in on suspicious events by clicking on timeline.
Remove Risk filter and expand date range to review surrounding behaviors.
Export relevant events for documentation.
Review upload destinations.
Export events if escalation is required.
Burst Uploads
Large numbers of uploads occurring in a short time window.
May indicate bulk data staging prior to exfiltration.
Off-Hours Activity
Transfers occurring late at night or on weekends.
🚨 Critical
Immediate investigation recommended
🔴 High
Elevated risk signals detected
🟡 Medium
Upload to corporate Google Drive
Low risk
Upload to personal Google Drive
Critical risk
Files uploaded or copy-pastes to a GenAI site using a corporate account
Safari is supported but Nightfall has not yet enabled Safari extension distribution. As a result, customers cannot currently deploy a publicly available Nightfall plugin on Safari but can install a private package.
Perplexity Comet’s Windows version prevents third-party browser extension installation, which blocks Nightfall deployment.
ChatGPT Atlas is not available on Windows at this time.
The below capabilities are not support on Perplexity Comet and OpenAI/ChatGPT Atlas.
ChatGPT Atlas
Personal vs. Business, menu + paste blocking are not supported; File upload monitoring and blocking is supported
Sidebar assistant: Cannot monitor activity in the sidebar assistant
Perplexity Comet
File upload monitoring and blocking is supported
Nightfall browser plugin cannot track activity until a URL is loaded
Paste-then-navigate scenario: If users paste content in the initial attempt before URL changes, Nightfall cannot track it
Menu + Paste scenarios: Not supported when you open and paste in a new tab; Cannot monitor content on new tabs ()
No. Arc, Brave, and Vivaldi receive full feature parity with Chrome.
Yes. Nightfall policies apply consistently across all supported browsers and operating systems.
macOS & Windows: Fully supported
Capabilities: File uploads, clipboard copy/paste, and personal vs. business detection
Notes: Full feature parity across both operating systems
macOS & Windows: Fully supported
Capabilities: File upload protection, clipboard monitoring, and personal vs. business enforcement
Notes: Equivalent security coverage to Chrome
macOS & Windows: Fully supported
Capabilities: Full data exfiltration protection including file uploads, clipboard actions, and personal vs. business detection
Notes: No functional differences across OS
macOS: Fully supported
Windows: Not supported
Capabilities: File uploads, clipboard protection, and personal vs. business detection
Notes: Full feature parity with Chrome
macOS: Fully supported
Windows: Not supported
Capabilities: Complete exfiltration protection including file uploads, clipboard actions, and personal vs. business detection
Notes: No feature gaps compared to Chrome
macOS: Fully Supported
Windows: Not supported
Capabilities: Full coverage for file uploads, clipboard monitoring, and personal vs. business enforcement
Notes: Consistent functionality across OS
macOS: Supported
Windows: Not supported
Capabilities (macOS): Exfiltration protection including file uploads, clipboard actions.
Notes: Windows version blocks third-party extension installation
macOS: Supported
Windows: Not supported
Capabilities (macOS): File uploads, clipboard monitoring
Notes: Personal vs. business detection is not currently supported
macOS: Not currently supported for deployment
Windows: Not supported
Notes: Safari extension distribution is not yet available
*Safari is supported, but Nightfall has not yet enabled Safari extension distribution. As a result, customers cannot currently deploy a publicly available Nightfall plugin on Safari but can install a private package.
While configuring the Scope section, if I use the Filter and add my Slack domain. Now, if I download a file from the Slack app will Nightfall monitor this download?
Yes. Nightfall monitors the downloads even from the Slack app.
What happens if I don’t configure any removable media filters?
If no Device Type, Vendor, or Serial Number filters are configured, the policy applies to all removable media by default. This is equivalent to selecting Monitor all for every device filter.
How do include and exclude filters work together?
Nightfall evaluates device filters using the following precedence:
Include rules are evaluated first
Exclude rules always override include rules
If no include filters are set, the policy defaults to include all
This ensures that exclusions (for example, approved corporate devices) are always respected.
What if I select a specific vendor and a specific serial number in the removable media filters?
Both conditions must match for the policy to apply:
The device must belong to the selected vendor
The device’s serial number must match the specified serial number
If either condition does not match, the policy is not triggered.
What happens if a removable media device matches an included vendor but is explicitly excluded by serial number?
The device will not trigger the policy. Serial number exclusions always take precedence, even if the vendor or device type is included.
What if the device does not report a serial number?
If a removable device does not expose a serial number:
Vendor and Device Type filters are still evaluated
Serial number–based include or exclude rules will not match
In these cases, enforcement behavior is determined by the remaining configured filters.
Can I allow only a small number of approved USB devices?
Yes. Configure:
Action: To removable media
Serial Number: Specific serial numbers
Enforcement: Block
Only the listed devices will be allowed. All other removable media will be blocked.
Can I block unknown USB drives but allow corporate-issued ones?
Yes. You can either:
Exclude approved vendors, or
Exclude approved serial numbers
All other removable devices will remain in scope for enforcement.
Does Nightfall continuously support new removable media vendors?
Yes. Nightfall supports ~1,200 removable media vendors out of the box, and vendor recognition is continuously updated as new devices are observed in the wild.
Customers do not need to manually onboard new vendors to receive baseline coverage.
Is enforcement applied if no sensitive data is detected?
Removable media policies are only enforced when sensitive content is detected according to your configured detection rules. If no sensitive data is found, the file transfer is allowed. You can also block usage of removable media based on a data lineage policy without any content scanning enabled.
Can I both monitor and block removable media activity?
Yes. Policies can be configured to block transfers while still logging events for audit and investigation purposes.
Which operating systems are supported?
Endpoint Exfiltration Prevention for removable media is supported on:
Windows endpoints
macOS endpoints
Behavior may vary slightly based on OS-level device reporting, but enforcement logic remains consistent.
Does Nightfall inspect or scan my source code?
No. Git Push Monitoring does not inspect source code, commits, diffs, file names, or repository contents. Nightfall evaluates only metadata associated with the Git push action, such as the destination URL, repository name, user, and device. To scan secrets or any other PII, PCI, PHI or file classifiers in GitHub, you can use Nightfall’s detection and response policies.
Is any code copied, stored, or transmitted to Nightfall?
No. Nightfall does not collect or store source code. Only high-level metadata required to identify the Git push event is processed.
Does Nightfall block Git pushes?
No. Git Push Monitoring is a monitor-only control. Git operations always complete successfully. When a policy violation occurs, Nightfall generates an event but does not interrupt developer workflows.
What Git commands are supported?
Nightfall detects Git push activity regardless of how the push is initiated. The following commands are supported and validated through testing:
git push
git push origin <branch>
git push --set-upstream origin <branch>
git push -u origin <branch>
Pushes triggered indirectly (for example, by scripts or wrappers that ultimately invoke git push) are also detected.
Are both HTTPS and SSH Git pushes supported?
Yes. Git Push Monitoring supports:
HTTPS-based Git remotes (e.g., https://github.com/org/repo.git)
SSH-based Git remotes (e.g., git@github.com:org/repo.git)
The destination domain is extracted and evaluated consistently across both protocols.
Are IDE-based Git actions supported?
Yes. Git pushes initiated from popular IDEs and Git clients are supported, including:
VS Code Git integration
JetBrains IDEs (IntelliJ, PyCharm, WebStorm, etc.)
GitHub Desktop
Sourcetree
As long as the IDE ultimately invokes a Git push operation on a managed endpoint, Nightfall detects the activity.
Are terminal / CLI Git pushes supported?
Yes. Git pushes executed directly from:
macOS Terminal
iTerm
Windows Git Bash / PowerShell (where supported by the endpoint agent)
are fully supported.
How does Nightfall handle multiple Git remotes?
If a repository has multiple remotes configured (for example, origin and personal), Nightfall evaluates the specific remote used during the push.
Example:
git push origin main → evaluated against origin destination
git push personal main → evaluated against personal destination
Events accurately reflect the remote and destination URL used.
What happens with new, empty, or scratch repositories?
Nightfall detects Git pushes to:
Newly created repositories
Empty repositories
Scratch or temporary repositories
Even if the repository has no prior history, detection is based on the destination domain and repository URL.
How are corporate GitHub and GitLab organizations supported?
Customers can define approved Git destinations using Domain Collections, including:
GitHub organizations (e.g., github.com/company-org/*)
GitLab cloud namespaces
Wildcard matching is supported to simplify configuration.
What happens if a developer pushes to a personal GitHub account?
If the destination domain or repository does not match the approved domain list:
The push succeeds
A Git Push event is generated
Security teams can investigate and respond
Are unmanaged devices monitored?
No. Git Push Monitoring requires the Nightfall endpoint agent. Git activity from unmanaged or offline devices is not detected.
What are the supported scenarios and capabilities with git push monitoring?
Support Matrix - The following matrix summarizes supported scenarios with git push monitoring by Nightfall:
The CLI Tools picker offers: scp, curl, wget, rsync, aws s3, npm. You must select at least one or you cannot continue. Other command-line programs are not covered by this trigger.
The policy scope is Windows only. wget and rsync cannot be enforced on Windows. rsync has no native Windows binary. PowerShell wget is an alias for Invoke-WebRequest, so the agent never sees a process to intercept. On a mixed macOS and Windows policy those two stay selectable and show a warning that they apply to Mac only.
No. Git Push to watches git push (and IDE git that ends in a push). CLI Transfer watches the tools you check (scp, curl, and the rest). Git Push is monitor-only. CLI Transfer can block.
No. CLI Transfer has no destination domain or host list. Scope by users, devices, OS, optional asset origin, and which tools you enable.
No. Only file upload or download through the selected tools.
File transfers sent with Apple AirDrop from a managed Mac. It does not watch AirPlay, Continuity, or iCloud Drive.
No. There is no recipient or device filter. Data Source and Data Destination are not applicable.
AirDrop events come from macOS. Include macOS in scope.
Yes, when you enable the block action. End-user notification, if used, is titled Assets transferred via AirDrop.
Bluetooth file transfers only. Pairing, audio, and HID use are not this trigger.
No. Removable Media has vendor and serial filters. Bluetooth does not. Device name, type, vendor, and MAC appear on the event for investigation.
They are not used for Bluetooth file transfer.
Yes, when you enable the block action. End-user notification, if used, is titled Assets transferred via Bluetooth and can list the other device names.
Step-by-step instructions for deploying Nightfall's Claude Code hooks to corporate-managed employee devices via your MDM.
Nightfall ships a managed-settings drop-in (payloads/nightfall-hooks.json) that registers the nightfall-hook-relay binary against four Claude Code events:
copilot.microsoft.comm365.cloud.microsoft/chatRequires browser extension
Git Push to
Yes
Not applicable
Cloud syncing to
No
Personal Google Drive, OneDrive, Dropbox are supported with session differentiation; Does not rely on browser extension
No
No browser context available
To removable media
No
No browser context available
Uploads to desktop app
No
Desktop apps lack browser session info
AI Agent Security
No
Hooks-based monitoring, no browser context
CLI Transfer
No
Process interception. No browser session. Corporate/personal toggles are hidden.
AirDrop
No
File transfer. Data Source and Data Destination are not applicable.
Bluetooth
No
File transfer. Data Source and Data Destination are not applicable.
You care about where data is going
Only uploads/pastes into personal account sessions
On
Off
Only uploads/pastes from corporate account sessions, regardless of destination
On
On
Both constraints apply independently
unfamiliar SaaS domains
Device – which device performed the action
Unexpected activity outside normal working hours may indicate suspicious behavior.
Multiple External Destinations
Sequential uploads to several different services.
May indicate attempts to bypass security controls or distribute data across multiple locations.
Personal Cloud Storage
Uploads to personal accounts such as Google Drive (Personal) or Dropbox (Personal).
Personal accounts are outside corporate control and represent higher exfiltration risk.
Moderate risk indicators
🟢 Low
Activity appears consistent with expected usage
⚪ Unknown
Insufficient context to determine risk
Low risk
Files uploaded or copy-pastes to a GenAI site using a personal account
High risk


Sidebar: Cannot monitor sidebar activity
Chrome, Edge, Firefox, Arc, Brave, Vivaldi
Comet, Atlas, Safari*
git push --force / git push -f
git push --tags
SSH Git Remotes
✅
Multiple Git Remotes
✅
New / Empty Repositories
✅
Force Push (--force)
✅
Tag Pushes
✅
Approved Domain Allowlist
✅
Domain Not-In Enforcement
✅
Managed Endpoints
✅
Unmanaged Endpoints
❌
Push Blocking
❌
OS
Fully Supported
Supported
Not Supported
Windows
Chrome, Edge, Firefox
Comet, Atlas, Safari, Arc, Brave, Vivaldi
Git Push (CLI)
✅
Git Push (IDE-integrated)
✅
HTTPS Git Remotes
macOS
✅
PreToolUse
Before Claude Code runs a tool (file write, bash, etc.)
Inspect/intercept the action before it happens
PostToolUse
After a tool runs
Capture the result
UserPromptSubmit
When the developer submits a prompt
Inspect prompt content
Stop
When the agent finishes responding
Capture the completed turn
Every event runs the same command — nightfall-hook-relay --source claude_code - with a 15-second timeout. The payload also sets "allowManagedHooksOnly": true, which prevents users from registering their own hooks alongside the managed ones.
Each device needs two things to happen, in order:
Payload staged - the JSON file lands at a fixed staging path, delivered by your MDM's file-distribution / app-deployment feature.
Install script runs - copies the staged payload into Claude Code's managed-settings.d/ drop-in directory and locks the file permissions.
Developer relaunches Claude Code - Managed settings are read at startup. Any Claude Code session already running when the file lands will not pick up the hooks until it is fully quit and reopened. Hooks take effect on the next launch — there is no live reload.
The install scripts are idempotent: re-running just re-copies the file, so it's safe to wire them to a recurring trigger.
Platform
Staging path (step 1)
Target path (step 2)
macOS
/opt/nightfall/hooks/claude-code/nightfall-hooks.json
/Library/Application Support/ClaudeCode/managed-settings.d/nightfall-hooks.json
Windows
C:\Nightfall\Hooks\claude-code\nightfall-hooks.json
The drop-in directory
managed-settings.d/accepts multiple vendor files, so Nightfall'snightfall-hooks.jsoncoexists with anything else already there. The install just adds one file.
Deliver payloads/nightfall-hooks.json to /opt/nightfall/hooks/claude-code/nightfall-hooks.json using your MDM's file-distribution or app-deployment feature (e.g. wrap the JSON in a .pkg, or use Workspace ONE's Files feature).
Wire scripts/macos/install.sh into your MDM as a System-context script. It:
Verifies it's running as root (exits early if not — deploy at System scope).
Confirms the staged payload exists.
Creates …/ClaudeCode/managed-settings.d/ if needed.
Copies the payload in, then sets chmod 644 and chown root:wheel.
scripts/macos/audit.sh compares the deployed file against the staged payload byte-for-byte (cmp -s):
Exit 0 > in sync, no action.
Exit 1 > drift detected, run install.sh to remediate.
(If the staging file is missing, audit exits 0 to avoid a remediation loop it can't fix.)
Deliver payloads/nightfall-hooks.json to C:\Nightfall\Hooks\claude-code\nightfall-hooks.json using your MDM's file-distribution feature (e.g. an .msi or .intunewin).
Wire scripts/windows/install.ps1 into your MDM as a SYSTEM-context script. It:
Verifies it's running as administrator (exits early if not).
Confirms the staged payload exists.
Creates C:\Program Files\ClaudeCode\managed-settings.d if needed.
Copies the payload in, then locks the ACL with icacls — full control for
Administrators and SYSTEM, read-only for Users.
scripts/windows/detect.ps1 compares the deployed file against the staged payload by SHA256:
Prints present, exit 0 → in sync.
Prints staging-missing, exit 0 → staging not deployed yet (no remediation loop).
Exit 1 → drift, run install.ps1 as the remediation.
The scripts are MDM-agnostic - the same install script works regardless of vendor. Wire each into the matching MDM feature:
MDM
Platform
Wire into
Script
Rippling
macOS
Custom Script (on enrollment + daily)
scripts/macos/install.sh
Two drift strategies:
Re-run on a schedule (Rippling / Jamf / Workspace ONE) - the install script is idempotent, so a periodic trigger simply re-copies and re-locks. Simplest.
Audit/detect → remediate (Kandji / Intune) - pair the audit/detect script with the install script so a re-install only fires when drift is detected.
After deployment, open the Devices page in the Nightfall console. Each device shows a per-client hook status indicator. A healthy status for Claude Code means the hooks are registered and the relay is responding - the deployment is working.
On a single device you can also confirm the file landed at the target path and that nightfall-hook-relay resolves on PATH (the endpoint agent provides it).
Admin-side (on the device):
ls -l "/Library/Application Support/ClaudeCode/managed-settings.d/nightfall-hooks.json" # exists, root:wheel, 644which nightfall-hook-relayDeveloper-side (in a fresh Claude Code session) — this is the missing one:
Run
/hooks. You should see four hooks (PreToolUse, PostToolUse, UserPromptSubmit, Stop), each runningnightfall-hook-relay --source claude_code. If the list is empty, Claude Code has not loaded the managed file — confirm you relaunched after deployment and that your Claude Code version is current (Section X).
Delete the deployed file; the relay binary stays installed (the Nightfall agent owns its lifecycle):
macOS: /Library/Application Support/ClaudeCode/managed-settings.d/nightfall-hooks.json
Windows: C:\Program Files\ClaudeCode\managed-settings.d\nightfall-hooks.json
If you wired the install to a recurring trigger, remove that MDM assignment first - otherwise the next check-in will re-deploy the file.
Hooks for Claude Code are not firing? Work through the checks below in order. Each step narrows down where the chain is broken: MDM deployment → file on disk → Claude Code loads it → relay runs → event reaches Nightfall. Most "deployed but not working" cases are resolved at Step 1.
The logic is the same on macOS and Windows; where a command or path differs, both variants are shown.
Managed settings are read only at startup. A Claude Code session that was already open when the MDM pushed the file keeps running without the hooks — there is no live reload.
Fix: Fully quit and reopen Claude Code, then re-test.
macOS: Quit with Cmd+Q (don't just close the window); confirm no claude process remains, then relaunch.
Windows: Close all Claude Code windows and confirm no claude process remains in Task Manager, then relaunch.
This is the most common cause. If hooks were deployed while Claude Code was open, this step alone usually fixes it.
In a fresh Claude Code session, run:
You should see four hooks — PreToolUse, PostToolUse, UserPromptSubmit, Stop — each running nightfall-hook-relay --source claude_code.
Hooks listed → Claude Code loaded the managed file. Skip to Step 5.
List empty / hooks missing → Claude Code did not load the file. Continue to Step 3.
You can also run /doctor for a built-in settings/installation diagnostic.
Confirm the file exists at the target path with the correct ownership/permissions.
macOS:
ls -l "/Library/Application Support/ClaudeCode/managed-settings.d/nightfall-hooks.json"Expect: file exists, owner root, group wheel, mode 644 (-rw-r--r--).
Windows (PowerShell):
Get-Acl "C:\Program Files\ClaudeCode\managed-settings.d\nightfall-hooks.json" | Format-ListExpect: file exists, ACLs locked to SYSTEM/Administrators (as set by install.ps1).
If the file is missing: the MDM install step did not complete on this device. Confirm the payload was staged, then re-run the install script at System scope (see the macOS/Windows setup sections). If the file exists but content looks wrong, validate it parses as JSON and matches the deployed payload.
Managed-settings drop-in directories (managed-settings.d/) and allowManagedHooksOnly require a recent Claude Code build. Pin managed devices to a current release; builds that predate this support will not register managed hooks even when the file is present and correct.
CLI vs. VS Code extension: the Claude Code VS Code extension bundles its own CLI binary, which can be a different version than the standalone
claudeCLI. Verify hooks (Step 2) in whichever surface the developer actually uses, and update the CLI and the extension independently.
After updating, fully relaunch Claude Code (Step 1) and re-check /hooks.
Confirm the relay binary is on PATH and returns a valid response.
macOS:
which nightfall-hook-relayecho '{}' | nightfall-hook-relay --source claude_codeWindows (PowerShell):
Get-Command nightfall-hook-relay'{}' | nightfall-hook-relay --source claude_codeExpect output {"continue":true} and a success exit code. If the relay is missing or errors, re-check the deployment; the relay must be installed and on PATH for the hook command to succeed.
If /hooks shows the hooks and the relay responds, but the Devices page shows no hook activity, the events are being captured locally but not reaching Nightfall. Check the device's network egress to endpoint.nightfall.ai — TLS, DNS, proxy, or connectivity failures will drop event uploads even though hooks are working correctly. This is a network/connectivity issue, not a hooks issue.
Collect and send to Nightfall support:
/hooks output (screenshot or text)
claude --version, and whether the developer uses the CLI or the VS Code extension
The Step 3 file listing
The Step 5 relay output and exit code
This set pinpoints exactly which link in the chain is broken.
Hooks not active after deployment? The file is loaded only at app launch. A Claude Code instance open since before the MDM push keeps running without the hooks. Fully quit (Cmd+Q / confirm the process is gone) and relaunch.
User-consent dialog. Any managed Claude Code setting that contains hooks triggers a one-time security dialog the user must accept. Plan internal comms before rollout so employees aren't surprised.
Anthropic Windows path migration (March 2026). Claude Code on Windows moved managed-settings to C:\Program Files\ClaudeCode. The shipped scripts target this new path — pin managed devices to a recent Claude Code version so the path matches.
Multi-vendor coexistence. The managed-settings.d/ drop-in directory accepts multiple vendor files. Nightfall's nightfall-hooks.json coexists with anything else there - the install adds a single file and never overwrites others.
allowManagedHooksOnly: true. This locks out user-defined hooks. If a team has a legitimate need for their own Claude Code hooks, that's a policy decision to revisit before rollout.
Minimum / recommended version. Managed-settings drop-in directories (managed-settings.d/) and allowManagedHooksOnly require recent changes to Claude Code. Check with claude --version; pin managed devices to a recent release.
CLI vs. VS Code extension. The Claude Code VS Code extension bundles its own CLI binary, which may be a different version than the standalone claude CLI. Both should read system managed-settings, but verify hooks in whichever you actually use — running /hooks in that surface. Update the extension and the CLI independently.
Event
When it fires
Purpose
{
"hooks": {
"PreToolUse": [ { "hooks": [ { "type": "command", "command": "nightfall-hook-relay --source claude_code", "timeout": 15 } ] } ],
"PostToolUse": [ { "hooks": [ { "type": "command", "command": "nightfall-hook-relay --source claude_code", "timeout": 15 } ] } ],
"UserPromptSubmit": [ { "hooks": [ { "type": "command", "command": "nightfall-hook-relay --source claude_code", "timeout": 15 } ] } ],
"Stop": [ { "hooks": [ { "type": "command", "command": "nightfall-hook-relay --source claude_code", "timeout": 15 } ] } ]
},
"allowManagedHooksOnly": true
}sudo ./scripts/macos/install.shpowershell -ExecutionPolicy Bypass -File .\scripts\windows\install.ps1/hooksclaude --versionThe Scope section enables you to create an asset lineage based policy in which you can track the journey of an asset from source to destination.
Security administrators can set precise exfiltration policies to protect sensitive files that originate from high-value SaaS locations from being exfiltrated to unsanctioned destinations
High performance security teams can focus their energy and resources on monitoring assets from high value SaaS domains.
By combining content download origin to upload destination, organizations can extend their monitoring to cover any cloud application accessed through the browser, even those without direct API integration.
Nightfall provides a set of reference policy configurations for common data exfiltration scenarios. Each template below describes recommended trigger types, detection rules, scope settings, and actions that you can use as a starting point when creating a new policy in the Nightfall console.
Block employees from uploading files or pasting sensitive data into external AI assistants such as ChatGPT, Claude.ai, Microsoft Copilot, and Google Gemini.
Scope
OS: macOS and Windows
Step-by-step instructions for deploying Nightfall's VS Code Copilot hooks to corporate-managed developer devices via your MDM. For the package overview and MDM mapping table, see README.md; this guide walks through the actual setup, end to end.
Heads up: VS Code Copilot hooks are Preview. Unlike Claude Code (one drop-in file) or Cursor (one merged file), VS Code needs two things per device: the hook file and an enterprise policy that tells Copilot to read it. Both steps are covered below.
Nightfall ships a Copilot hook config (payloads/nightfall.json) that registers the nightfall-hook-relay binary against four VS Code Copilot events:
C:\Program Files\ClaudeCode\managed-settings.d\nightfall-hooks.json
Rippling
Windows
PowerShell Script
scripts/windows/install.ps1
Jamf Pro
macOS
Script + Policy (Recurring Check-in + Enrollment)
scripts/macos/install.sh
Kandji
macOS
Custom Script — Audit
scripts/macos/audit.sh
Kandji
macOS
Custom Script — Remediation
scripts/macos/install.sh
Microsoft Intune
Windows
Win32 Remediation - Detection
scripts/windows/detect.ps1
Microsoft Intune
Windows
Win32 Remediation - Remediation
scripts/windows/install.ps1
Workspace ONE
macOS
Script (System context, Periodic + Enrollment)
scripts/macos/install.sh
Workspace ONE
Windows
Script (SYSTEM context, Periodic + Enrollment)
scripts/windows/install.ps1
Allows security teams to monitor and prevent data exfiltration not just through direct browser uploads but also through cloud storage sync applications, providing a multi-layered defense against data leaks.
With lineage-based policies, organizations can proactively identify and manage risks associated with sensitive content movement, ensuring compliance with data security standards and preventing potential breaches before they occur.
The Scope page consists of the following sections.
This section allows you to select the operating systems to which the policy must be scoped. Nightfall supports the Microsoft's Windows and Apple's MAC operating systems. You can either choose any one of the operating system or both the operating systems, based on your organization's requirements. You must click the check box of the respective operating system to include it in the scope of the policy. All the devices that belong to the selected operating system(s) are monitored by Nightfall.
By default, Nightfall monitors all the devices that belong to the selected operating system(s). However, you can choose to exclude trusted devices from being monitored. The Exclude Devices section consists of a drop-down menu. This menu lists all the devices that belong to the selected operating system(s). You can select the devices that you wish to exclude from being monitored.
The Content Scanning section allows you to scan the downloaded content for sensitive data. You can choose the Nightfall detection rules that you wish to use for scanning the downloaded data. With this feature, you can monitor exfiltration attempts on sensitive data. For instance, you can monitor if any of the content uploaded to unsanctioned destinations contains regulated information like PCI, PII, PHI or organization's secrets like credentials, API keys, and so on. You can combine content scanning with Trigger and the Block features to prevent any exfiltration files containing sensitive data.
To use this feature, you must first select the On option from the drop-down menu and then select the required Nightfall detectors.
If a downloaded file contains sensitive data, it is reported in the exfiltration event. You can check the assets tab of an exfiltration event to view the sensitive data found. In the following image, you can see that a Detector called Credit Card Number is violated 20 times in one of the files uploaded to through the browser.
The filters section provides you the flexibility to include and exclude users at a granular level. Once you select the operating system and the devices to be monitored, you can further drill down your scope by using filters. You can apply filters to only monitor assets downloaded from specific domains. Conversely, you can also choose to exclude the monitoring of assets downloaded from specific domains. Additionally, you can also apply filters to only monitor or exclude the monitoring of assets downloaded by specific high risk, like departing users, or function user groups, like HR, Finance or Engineering.
The Asset Origin filter allows you to limit the scope of the policy to only those assets which originated from a specific source. To use the asset origin filter, you must click Add Filter and select Asset Origin.
The Asset Origin filter provides the following options:
Any Domain: If you select this option, Nightfall monitors the assets originated (downloaded) from any domain, present in any of the domain collections.
Domain in: If you select this option, you must additionally also select the domain collections, created in the domain collections section. In this case, Nightfall monitors only those assets that originated from a domain, which is a part of any of the selected domain collection(s).
Once you select a domain collection, it is displayed on the screen and greyed out from the drop-down menu. You can use the drop-down menu to select additional domain collections.
Domain Not in: If you select this option, you must additionally also select the domain collections, created in the domain collections section. In this case, Nightfall does not monitor those assets that originated from a domain, which is a part of any of the excluded domain collection(s).
Once you select a domain collection, it is displayed on the screen and greyed out from the drop-down menu. You can use the drop-down menu to select additional domain collections.
User Session Differentiation (also referred to as User Session Check) enables Nightfall to distinguish between personal and corporate user accounts on supported SaaS applications, cloud storage platforms, and AI web apps. This capability addresses a critical data exfiltration capability by detecting and enforcing policies when sensitive data moves from corporate contexts to personal contexts, even when both occur on the same domain.
This feature is available on macOS and Windows.
Traditional DLP solutions struggle to differentiate who a user is logged in as on dual-use platforms like Google Drive, Microsoft 365, or AI assistants. This creates blind spots where users can bypass controls by switching to personal accounts.
User Session Differentiation enables:
Prevention of shadow exfiltration via personal accounts
Context-aware enforcement (corporate to corporate vs. corporate to personal)
Clear audit trails showing account type involved in an event
Confident blocking of high-risk transfers without disrupting legitimate workflows.
When enabled, Nightfall:
Detects whether the source and/or destination account is corporate or personal
Applies policy logic based on session context (not just domain)
Captures session metadata for investigation and audit
As an example, if an employee:
Downloads a file from their corporate Google Drive
Uploads it to their personal Google Drive
Nightfall can detect, alert, or block this action.
Supported Coverage
User Session Differentiation works across 35+ supported domains, including:
Google Workspace
Drive, Docs, Gmail, Calendar, Meet, Keep
Microsoft 365
OneDrive, SharePoint, Teams, Outlook, Office apps
Cloud Storage
Dropbox, Box, iCloud
AI / Shadow AI Apps
ChatGPT, Claude.ai, Gemini, Copilot, Perplexity
Session context is captured for:
Browser file uploads
Clipboard copy/paste actions
How It Works
Browser Extension captures session context on supported domains
Directory Sync from Okta, Entra ID, Google Directory identifies corporate accounts and domains
Corporate Domains collection is populated automatically with the domains from directory sync
User Session Check evaluates source and destination sessions
Policy enforcement occurs based on configuration
Corporate Domains Collection
The Corporate Domains collection represents domains associated with corporate identities (for example, contoso.com). It is required for session differentiation.
Automatically populated when the endpoint agent is enabled and once the directory sync is setup
Happens once, based on the first OS provisioned (macOS or Windows)
After initial population, the collection is refreshed via an hourly job
You can add more domains to this collection as needed
Note: Corporate Domains are populated immediately upon directory sync and once one or more endpoint agents are installed.
Enabling User Session Differentiation
Requirements
Endpoint agent with browser extension
macOS: Chrome (1.2.9.x+)
Windows: Chrome, Edge, Firefox (1.2.32+)
Directory sync enabled (Okta, Google Directory, or Entra ID)
Corporate Domains collection configured
Browser extension deployed (via MDM or manual install)
macOS (MDM)
Deploy NightfallAI_Profile_with_Browser_Extensions.mobileconfig
Automatically installs browser extension and logs users in
Windows
No additional MDM profile required
User Session Differentiation is available in Endpoint Exfiltration policies and requires the User session check toggle to be enabled.
Where It Appears
The toggle is shown when:
Monitoring supported domains
Using Domain / URL-based sources or destinations
How to Configure User Session Check
Asset Origin (Trigger)
Defines where data originates from.
Supported operators:
Domain in, Domain not in, Any domain
Example Configurations
Monitor Corporate Sources Only - Use case: Detect data originating from corporate accounts only.
Source: Domain in equals Corporate Domains
User session check: Enabled
Exclude Corporate Sources - Use case: Focus on external or unmanaged sources.
Source: Domain not in equals Corporate Domains
Action (Destination)
Defines where data is going (upload, paste, transfer).
Supported actions include:
Browser uploads to, Clipboard copy/paste
Supported operators:
Domain in, Domain not in, Any domain
Common Policy Use-Cases
Block Corporate to Personal AI Uploads
Source: Domain in → Corporate Domains
Action: Browser upload to → Domain in → AI Assistants
User session check: Enabled
Outcome: Blocks uploads when destination account is personal
Allow Corporate → Corporate, Block Corporate → Personal
Source: Domain in → Corporate Domains
Destination: Domain in → Supported Domains
User session check: Enabled
Detect Personal Account Usage on Approved Apps
Action: Browser uploads to → Domain in → Google Workspace
User session check: Enabled
Use case: Visibility into personal account usage on approved SaaS.
Broad Monitoring (Any → Personal)
Source: Any domain
Destination: Domain in → Supported Domains
User session check: Enabled
Specific User(s): You must choose this option to monitor the actions of specific internal users. Once you choose this option, Nightfall populates the list of users from the synced IdPs in Directory Sync. You must select the required users.
All Users, except for: You must select this option to exclude the monitoring of specific internal users. Once you choose this option, Nightfall populates the list of users from the synced IdPs in Directory Sync. You must select the required users.
Specific Group(s): You must choose this option to monitor of specific internal groups. Once you choose this option, Nightfall populates the list of internal groups from the synced IdPs in Directory Sync. You must select the required groups.
All Groups, except for: You must choose this option to exclude monitoring of specific internal groups. Once you choose this option, Nightfall populates the list of internal groups from the synced IdPs in Directory Sync. You must select the required groups.
Endpoint URL and subpath filtering allows administrators and security teams to precisely control which file exfiltration events are reported or blocked by Nightfall. By creating exclusions at the file, file path, or file type (extension) level, teams can reduce noise, prevent false positives, and maintain focus on genuine data risk. This section explains:
How URL and subpath filtering works
The end‑to‑end user experience
Supported exclusion types
Practical use‑cases
Important behavioral details and limitations
This functionality is available within:
Exfiltration Prevention → Event Details → Assets tab
Integrations → Endpoint → Exclusion List
It applies to endpoint‑level exfiltration signals such as:
Browser uploads
File transfers via removable media
File sync
How it works
Exfiltration Event Detected An endpoint event (for example, a Browser Upload) is detected and logged under Exfiltration Prevention. Each event includes:
Risk level (Low / Medium / High)
Actor (device and user)
Asset involved (file name, path, size, medium)
Destination (e.g., drive.google.com, chat.deepseek.com)
Viewing Asset Details When an event is opened:
Navigate to the Assets tab
Select the relevant asset (e.g., Customer List.xlsx)
The Asset Details panel displays:
File name
Full local file path (e.g., /Users/anantmahajan/Downloads/Customer List.xlsx)
Medium (Browser)
Size
Activating File or Path Exclusion From the Asset Details panel:
Click “Click to activate file & file path exclusion (macOS only)”
A modal titled File & File Path Exclusion appears with three options:
Exclusion Options
Ignore file
Excludes this exact file (specific file name + path)
Ignore path
Excludes all files within the selected directory and its subpaths
Ignore all files with .xlsx extension
Excludes all Excel files across the endpoint
Selecting an option and clicking Continue proceeds to confirmation.
Confirmation Modal
A confirmation dialog clearly states: "Future activity involving this file will not be reported. Existing events won't be affected."
Optional setting:
Apply rule to all endpoints (if enabled, the exclusion applies globally rather than device‑specific)
Click Ignore to finalize the exclusion.
Exclusion Is Applied
Once confirmed:
The exclusion takes effect immediately
Future matching events are suppressed
Past events remain visible for audit and investigation
The exclusion appears under: Integrations → Endpoint → Exclusion List
Each entry shows:
Excluded item (file, path, or extension)
Type (File Name, File Path, or Extension)
Time created
User who created the exclusion
Scope (specific device or all endpoints)
URL & Subpath Filtering Behavior
URL Matching
When a browser upload occurs, Nightfall evaluates:
The destination domain (e.g., drive.google.com)
The local file path on the endpoint
If the local file matches an exclusion rule, the upload event is:
Not reported
Not blocked (unless another policy applies)
Subpath Matching
For Ignore path exclusions:
All files under the selected directory are excluded
Subdirectories are included automatically
Example:
/Users/johndoe/Downloads/
Excludes:
/Users/johndoe/Downloads/Customer List.xlsx
/Users/johndoe/Downloads/Exports/Q4/customers.csv
Supported Exclusion Types
File
Single file only
Known safe document repeatedly triggering alerts
Path
Directory + subdirectories
Trusted export folders or generated reports
Extension
All files of a type
Common Use‑Cases
Suppressing Known Safe Files
Scenario: A finance team routinely uploads a standardized customer spreadsheet to Google Drive.
Solution: Ignore file: Customer List.xlsx
Outcome:
Prevents repeated high‑risk alerts for a known workflow
Maintains visibility into other files
Ignoring Automated Export Directories
Scenario: An application exports reports into a fixed local directory before upload.
Solution: Ignore path: /Users/*/Downloads/Exports/
Outcome:
Reducing Alert Fatigue from Common File Types
Scenario: Large volumes of Excel files are shared internally and trigger frequent alerts.
Solution: Ignore all files with .xlsx extension
Outcome:
Incident‑Driven Exception Handling
Scenario: An investigation confirms a flagged upload was legitimate.
Solution: Create a targeted file or path exclusion directly from the event
Outcome:
Best Practices
Exclusions apply only to future activity and Existing events are never retroactively modified.
Path exclusions are recursive and include subpaths.
Extension‑based exclusions are global and high‑impact.
Use Apply to all endpoints sparingly.
Periodically review the Exclusion List for stale rules. Document the reason for exclusions internally when possible.
URL and subpath filtering for endpoint exclusions gives security teams fine‑grained control over exfiltration monitoring. By embedding exclusions directly into the investigation workflow, Nightfall enables fast, contextual decisions without compromising visibility into real risk.
This approach balances strong data security with practical, low‑friction operations.
Kindly note that some of the advanced policy features like , , and automated actions are not yet available on Windows—but stay tuned, as we’re working to bring these capabilities soon!
Content scanning: Enabled
Triggers
Trigger
Setting
Browser uploads
Domain in: AI Tools domain collection (add chat.openai.com, claude.ai, gemini.google.com, copilot.microsoft.com, perplexity.ai, and any others in use)
Desktop app
Enabled - covers thick-app versions of ChatGPT, Microsoft 365 Copilot (Word, Excel, PowerPoint, Teams AI)
Detection rules
Enable content scanning with the following detectors:
PII - names, SSNs, driver's license numbers, dates of birth
PCI - credit card numbers, routing numbers, IBAN
PHI - patient records and health information
Credentials & API keys - secrets, tokens, private keys
File classifiers - financial, HR, legal, M&A, source code documents
Actions
Automated action: Block
End-user notification: Enabled - recommended message: "This file or content contains sensitive data and cannot be uploaded to external AI tools. Contact your security team if you have a business need."
Allow override with justification: Optional - enable if your organization wants users to self-certify a business reason before the action is allowed.
Mac Agent v1.2.11.x or later (desktop app monitoring)
Windows Agent v1.4.9.0 or later (thick app: Outlook, Teams, WhatsApp); v1.4.11.0 or later (M365 Copilot)
AI Tools domain collection created under Domain Collections
Nightfall browser extension deployed to managed browsers
Prevent employees from copying corporate files to personal Google Drive, Dropbox, OneDrive, or Box accounts - including both browser-based uploads and locally synced folders.
Scope
OS: macOS and Windows
Session detection: Enable corporate/personal account differentiation - this ensures the policy fires only when the destination is a personal account, not a corporate Google or Microsoft account
Users: All users
Triggers
Trigger
Setting
Browser uploads
Domain in: Personal Cloud Storage domain collection (drive.google.com, dropbox.com, onedrive.live.com, box.com)
Cloud syncing
Enabled - select Google Drive, OneDrive, Dropbox, Box
Detection rules
Enable content scanning with:
PII, PCI, PHI, Credentials & API keys - broad sensitive data coverage
File classifiers - financial, legal, HR, M&A, source code
Actions
Automated action: Block
Admin alert: Enabled - route to your security team's notification channel
End-user notification: Enabled - "Corporate files cannot be transferred to personal cloud storage accounts."
Mac Agent v1.2.10.x or later
Windows Agent v1.4.9.0 or later
Directory sync configured (required for corporate/personal account differentiation)
Personal Cloud Storage domain collection created
Use case: Block secrets - API keys, passwords, and cryptographic private keys - from being uploaded or pasted to any external destination.
Scope
OS: macOS and Windows
Users: All users; consider prioritizing engineering and DevOps groups for immediate rollout
Triggers
Trigger
Setting
Browser uploads
Any domain
Clipboard paste
Any destination
Desktop app
Detection rules
Enable content scanning with:
API keys & secrets - AWS, Azure, Google, Stripe, Okta, Slack, GitHub, and 50+ service-specific key formats
Passwords & credentials - username/password patterns in text and code
Cryptographic keys - RSA private keys, EC private keys (PEM-encoded)
Actions
Automated action: Block
End-user notification: Enabled - "A secret or API key was detected. This content cannot be shared externally. Rotate the key immediately if it was already exposed."
Note: This template has a low false-positive rate because credential detectors are highly specific. Block mode is safe to enable from the start.
Mac Agent v1.2.11.x or later
Windows Agent v1.4.9.0 or later
Nightfall browser extension deployed
Use case: Prevent proprietary source code from being pushed to personal or unauthorized repositories, or uploaded to external destinations via browser or cloud sync.
Scope
OS: macOS (git push monitoring is macOS-only)
Users: Engineering and DevOps groups
Content scanning: Enabled
Triggers
Trigger
Setting
Git push
Enabled - monitors pushes to remote repositories not in your approved list
Browser uploads
Domain in: Personal Code Repos domain collection (add personal GitHub, GitLab, Bitbucket URLs; e.g., github.com personal paths)
Cloud syncing
Detection rules
Enable content scanning with:
File classifiers - source code classifier for language-agnostic detection
Custom regex (optional) - add patterns for internal project identifiers, copyright headers, or proprietary module names
Actions
Automated action: Block
Admin alert: Enabled
Mac Agent v1.2.10.x or later (git push monitoring)
Nightfall browser extension deployed
Personal Code Repos domain collection created
Directory sync configured (for group-based scoping)
Use case: Detect and block patient health information (PHI) from leaving the endpoint across all exfiltration channels - a foundational policy for HIPAA-covered organizations.
Scope
OS: macOS and Windows
Users: All users - or scope to clinical, operations, and data teams if starting with a pilot
Content scanning: Enabled
Triggers
Use all available triggers in independent policies:
Browser uploads
Cloud syncing
Clipboard paste
Desktop app (thick app monitoring)
Removable media
Printer
Git push
Detection rules
Enable content scanning with:
PHI - patient health information combining personal identifiers with medical context (diagnoses, medications, provider details, insurance data)
PII - names, SSNs, dates of birth (supplements PHI detection)
Actions
Automated action: Block
Admin alert: Enabled - route to compliance and security teams
End-user notification: Enabled - "This content contains protected health information (PHI) and cannot be shared externally. Contact your compliance team for assistance."
Allow override with justification: Enabled - log all overrides for HIPAA audit trail
Mac Agent v1.2.11.x or later (for full trigger coverage including print and thick apps)
Windows Agent v1.4.11.0 or later
Directory sync configured
Use case: Block sensitive files from being copied to USB drives, external hard drives, and other removable storage devices.
Scope
OS: macOS and Windows
Users: All users
Content scanning: Enabled
Triggers
Trigger
Setting
Removable media
Enabled
Detection rules
Enable content scanning with:
PII - personal identifiable information
PCI - payment card data
PHI - health information
Credentials & API keys
File classifiers - HR, financial, legal, M&A documents, source code
Actions
Automated action: Block - the file transfer is blocked at the point of write to the removable device
End-user notification: Enabled - "Files containing sensitive data cannot be transferred to removable storage devices."
Note: This trigger does not require domain collections. No additional collection setup is needed beyond enabling content scanning.
Mac Agent v1.2.10.x or later
Windows Agent v1.4.9.0 or later
Coverage for ~1,200+ removable media vendors
Use case: Protect payment card data and financial records from exfiltration across browser, clipboard, desktop app, and cloud sync channels - supports PCI DSS compliance requirements.
Scope
OS: macOS and Windows
Users: Finance, accounting, and billing teams - scope to these groups for initial rollout; expand to all users after validation
Content scanning: Enabled
Triggers
Trigger
Setting
Browser uploads
Any domain
Clipboard paste
Any destination
Desktop app
Detection rules
Enable content scanning with:
PCI - credit card numbers (Visa, Mastercard, Amex, Discover, JCB, UnionPay), routing numbers, IBAN, SWIFT codes
File classifiers - financial documents
Actions
Automated action: Block
Admin alert: Enabled - route to security and compliance teams
Mac Agent v1.2.11.x or later
Windows Agent v1.4.9.0 or later
Directory sync configured (for group-based scoping)
Nightfall browser extension deployed
Use case: Prevent strategically sensitive documents - M&A materials, legal contracts, HR records, and internal financial reports - from being uploaded to external destinations.
Scope
OS: macOS and Windows
Asset origin filter: Optionally restrict to assets originating from corporate domains (files downloaded from internal tools or corporate Google Workspace/SharePoint)
Users: Leadership, finance, legal, HR, and strategy teams - scope via directory sync groups
Triggers
Trigger
Setting
Browser uploads
Any domain (or refine with a High-Risk Destinations domain collection)
Cloud syncing
Enabled
Desktop app
Detection rules
Enable content scanning with:
File classifiers - M&A, legal, financial, HR, regulatory documents
Custom keywords (optional) - add internal project codenames, product names, or division identifiers relevant to your organization
Actions
Automated action: Block
Admin alert: Enabled
Allow override with justification: Recommended - many IP-related transfers have legitimate business reasons; log justifications for audit
Mac Agent v1.2.11.x or later
Windows Agent v1.4.9.0 or later
Directory sync configured (for group-based scoping)
Nightfall browser extension deployed
Use case: Detect and block sensitive content copied from internal tools and pasted into personal email, consumer AI assistants, social platforms, or other unsanctioned destinations - using corporate/personal account differentiation.
Triggers
Trigger
Setting
Clipboard paste
Destination: Domain in Unsanctioned Destinations domain collection
Build your Unsanctioned Destinations domain collection to include:
Personal email: mail.google.com, outlook.live.com, yahoo.com
Consumer AI: chat.openai.com, claude.ai, gemini.google.com
Social media: twitter.com, linkedin.com, facebook.com, reddit.com
Personal cloud: drive.google.com, dropbox.com
Use corporate/personal session detection to ensure the policy fires only when the destination session is a personal (non-corporate) account on supported domains.
Detection rules
Enable content scanning with:
PII, PCI, PHI - broad regulated data coverage
Credentials & API keys
File classifiers - financial, legal, HR, M&A
Scope
OS: macOS and Windows
Session detection: Enable corporate/personal account differentiation (requires directory sync and Corporate Domains collection)
Users: All users
Actions
Automated action: Block
End-user notification: Enabled - "This content contains sensitive data and cannot be pasted into personal accounts or external services."
Allow override with justification: Enabled - allows employees to self-certify a business justification; logged for review
Mac Agent v1.2.11.x or later
Windows Agent v1.4.9.0 or later
Directory sync configured
Corporate Domains collection configured (for personal vs. corporate account filtering)
Unsanctioned Destinations domain collection created
Each policy recommendation above is a starting point. Common adjustments:
Narrow the scope - start with a specific user group (e.g., finance or engineering) before rolling out to all users, to validate detection accuracy before broad enforcement.
Start in detect-only mode - leave the automated action unset and enable admin alerts only. Review policy incidents for 1–2 weeks before switching to Block.
Add custom detectors - supplement built-in detectors with custom LLM based file or prompt based classifiers specific to your organization's sensitive data.
Tune domain collections - review and expand domain collections regularly as new AI tools, cloud apps, and risky destinations emerge. You can automate this via the apps discovered categorized by risk in App Intelligence. Expand the list of domains or apps to monitor and block via the domain collections.
Event
When it fires
Purpose
UserPromptSubmit
When the developer submits a prompt
Inspect prompt content
PreToolUse
Before Copilot runs a tool (file write, terminal, etc.)
Inspect/intercept the action before it happens
Every event runs the same command - nightfall-hook-relay --source vscode_copilot - with a 15-second timeout. The relay binary is resolved by name on the system PATH, so the one config file works unchanged on both macOS and Windows.
Nightfall endpoint agent is installed on every target device. The agent auto-installs and keeps nightfall-hook-relay updated, and adds it to the system PATH. The hooks call the binary by name, so without the agent the hooks resolve to nothing.
MDM scope selected - the device group / Blueprint / Smart Group / assignment that will receive the deployment.
VS Code + Copilot extension are reasonably current on managed devices, and ideally pinned during the pilot (hooks are Preview).
You have the pieces from this package for your platform: the hook payload (payloads/nightfall.json), the matching policy source (payloads/nightfall-vscode-copilot.mobileconfig on macOS, payloads/hookFilesLocations.json on Windows), and the scripts in scripts/macos/ or scripts/windows/.
VS Code Copilot won't read the hook file unless chat.hookFilesLocations is set as an enterprise policy. So each device needs two things to happen:
Drop the hook file - the install script copies nightfall.json to a fixed file path.
Set the policy - the policy script registers that file path in chat.hookFilesLocations (a Configuration Profile on macOS, a registry policy on Windows).
Both the install scripts and the policy scripts are idempotent, so they're safe to wire to a recurring trigger.
Platform
Staging path
Hook file target (step 1)
macOS
/opt/nightfall/hooks/vscode/nightfall.json
/Library/Application Support/Copilot/hooks/nightfall.json
Windows
`C:\Nightfall\Hooks\vscode
ightfall.json`
Platform
Policy mechanism
What it sets
macOS
Configuration Profile (com.microsoft.VSCode)
chat.hookFilesLocations → /Library/Application Support/Copilot/hooks/nightfall.json: true
Windows
Registry under HKLM\Software\Policies\Microsoft\VSCode
Both policy mechanisms are additive: macOS profile layering preserves other vendors' Configuration Profiles for the
com.microsoft.VSCodedomain, and the Windows policy script merges Nightfall's entry into any existingchat.hookFilesLocations. Nightfall never clobbers another vendor's hook-file registration.
Deliver payloads/nightfall.json to /opt/nightfall/hooks/vscode/nightfall.json using your MDM's file-distribution or app-deployment feature (e.g. wrap the JSON in a .pkg, or use Workspace ONE's Files feature).
Wire scripts/macos/install.sh into your MDM as a System-context script. It:
Verifies it's running as root (exits early if not - deploy at System scope).
Confirms the staged payload exists.
Creates /Library/Application Support/Copilot/hooks/ if needed.
Copies nightfall.json into place.
Wire scripts/macos/install-policy.sh into your MDM (also System-context). It installs payloads/nightfall-vscode-copilot.mobileconfig via sudo profiles install, which sets chat.hookFilesLocations so Copilot reads the file dropped in Step 2. The profile uses a stable PayloadIdentifier (ai.nightfall.hooks.vscode), so re-installs update in place. Alternatively, on profile-aware MDMs (Jamf, Kandji, Workspace ONE), upload the .mobileconfig directly as a Configuration / Custom Settings Profile instead of running the script.
scripts/macos/audit.sh compares the deployed hook file against the staged payload byte-for-byte (cmp -s):
Exit 0 > in sync, no action.
Exit 1 > drift detected, run install.sh to remediate.
(If the staging file is missing, audit exits 0 to avoid a remediation loop it can't fix.) The policy install is naturally idempotent and can simply be re-run on any trigger.
Deliver payloads/nightfall.json to C:\Nightfall\Hooks\vscode\nightfall.json using your MDM's file-distribution feature (e.g. an .msi or .intunewin).
Wire scripts/windows/install.ps1 into your MDM as a SYSTEM-context script. It:
Verifies it's running as administrator (exits early if not).
Confirms the staged payload exists.
Creates C:\ProgramData\Copilot\hooks if needed.
Copies nightfall.json into place.
Wire scripts/windows/install-policy.ps1 into your MDM (also SYSTEM-context). It merges Nightfall's entry into chat.hookFilesLocations under HKLM\Software\Policies\Microsoft\VSCode, preserving any entries other vendors have already registered. The merged value mirrors payloads/hookFilesLocations.json.
Alternatively, import VS Code's ADMX template and set the policy via the Intune UI, or push the same value via an OMA-URI Custom Configuration Profile.
scripts/windows/detect.ps1 compares the deployed hook file against the staged payload by SHA256:
Prints present, exit 0 > in sync.
Prints staging-missing, exit 0 > staging not deployed yet (no remediation loop).
Exit 1 → drift, run install.ps1 as the remediation.
The policy merge script is idempotent and can be re-run on any trigger.
The scripts are MDM-agnostic - the same scripts work regardless of vendor. Note that VS Code has two install scripts per platform (file drop + policy), so most rows below pair them:
MDM
Platform
Wire into
Script
Rippling
macOS
Custom Script — file drop
Two drift strategies for the file drop:
Re-run on a schedule (Rippling / Jamf / Workspace ONE) - the install script is idempotent, so a periodic trigger simply re-copies the file. Simplest.
Audit/detect → remediate (Kandji / Intune) - pair the audit/detect script with the install script so a re-install only fires when drift is detected.
The policy scripts are idempotent regardless of strategy (profile install updates in place via the stable PayloadIdentifier; registry merge re-applies the same entry), so wire them to the same trigger as the file drop.
After deployment, open the Devices page in the Nightfall console. Each device shows a per-client hook status indicator. A healthy status for VS Code Copilot means the hooks are registered and the relay is responding - the deployment is working.
On a single device you can also confirm:
The hook file landed at the target path.
chat.hookFilesLocations includes that path - check the installed Configuration Profile (macOS) or the registry key under HKLM\Software\Policies\Microsoft\VSCode (Windows).
nightfall-hook-relay resolves on PATH (the endpoint agent provides it).
If the file is present but hooks don't fire, the policy is almost always the missing piece - Copilot silently ignores hook files at paths not listed in chat.hookFilesLocations.
Remove both pieces; the relay binary stays installed (the Nightfall agent owns its lifecycle):
Delete the hook file:
macOS: /Library/Application Support/Copilot/hooks/nightfall.json
Windows: C:\ProgramData\Copilot\hooks\nightfall.json
Remove the policy entry for Nightfall's path from chat.hookFilesLocations:
macOS: remove the ai.nightfall.hooks.vscode Configuration Profile.
Windows: remove the Nightfall path entry under HKLM\Software\Policies\Microsoft\VSCode (leave other vendors' entries intact).
If you wired the install/policy scripts to a recurring trigger, remove those MDM assignments first — otherwise the next check-in will re-deploy.
VS Code Copilot hooks are Preview. The configuration format and behavior may change. Pin to specific VS Code and Copilot extension versions during pilot.
Two-step deployment is mandatory. Dropping the file without setting chat.hookFilesLocations does nothing — Copilot won't read an unregistered hook file. This is the most common cause of a "deployed but not working" report.
Multi-vendor coexistence. Both policy mechanisms are additive - macOS profile layering and the Windows registry merge preserve other vendors' hook-file registrations. Nightfall adds a single path entry and never overwrites others.
Copilot CLI and Copilot coding agent (cloud) are out of scope - hook coverage doesn't apply there.
Claude Code spillover into VS Code. By default VS Code Copilot may also read ~/.claude/settings.json. If you observe Claude's user-level hooks firing inside VS Code and want to suppress that, add "~/.claude/settings.json": false to the policy.
{
"hooks": {
"UserPromptSubmit": [ { "type": "command", "command": "nightfall-hook-relay --source vscode_copilot", "timeout": 15 } ],
"PreToolUse": [ { "type": "command", "command": "nightfall-hook-relay --source vscode_copilot", "timeout": 15 } ],
"PostToolUse": [ { "type": "command", "command": "nightfall-hook-relay --source vscode_copilot", "timeout": 15 } ],
"Stop": [ { "type": "command", "command": "nightfall-hook-relay --source vscode_copilot", "timeout": 15 } ]
}
}sudo ./scripts/macos/install.shpowershell -ExecutionPolicy Bypass -File .\scripts\windows\install.ps1Enabled - covers messaging apps and email clients
Enabled - detects source code written to personal sync folders
Enabled
Cloud syncing
Enabled
Enabled
PostToolUse
After a tool runs
Capture the result
Stop
When the agent finishes responding
Capture the completed turn
`C:\ProgramData\Copilot\hooks
ightfall.json`
chat.hookFilesLocations → `C:\ProgramData\Copilot\hooks
ightfall.json: `true
scripts/macos/install.sh
Rippling
macOS
Custom Script — policy install
scripts/macos/install-policy.sh
Rippling
Windows
PowerShell Script — file drop
scripts/windows/install.ps1
Rippling
Windows
PowerShell Script — policy merge
scripts/windows/install-policy.ps1
Jamf Pro
macOS
Script + Policy — file drop
scripts/macos/install.sh
Jamf Pro
macOS
Script + Policy — policy install
scripts/macos/install-policy.sh (or upload the .mobileconfig directly as a Configuration Profile)
Kandji
macOS
Custom Script — Audit (file)
scripts/macos/audit.sh
Kandji
macOS
Custom Script — Remediation (file)
scripts/macos/install.sh
Kandji
macOS
Custom Script — Policy install
scripts/macos/install-policy.sh (or upload the .mobileconfig as a Kandji Custom Profile)
Microsoft Intune
Windows
Win32 Remediation — Detection
scripts/windows/detect.ps1
Microsoft Intune
Windows
Win32 Remediation — Remediation
scripts/windows/install.ps1
Microsoft Intune
Windows
Custom Configuration Profile / ADMX — policy
scripts/windows/install-policy.ps1 (or import VS Code's ADMX and set the policy via UI)
Workspace ONE
macOS
Script — file drop
scripts/macos/install.sh
Workspace ONE
macOS
Script — policy install
scripts/macos/install-policy.sh (or upload the .mobileconfig as a Custom Settings Profile)
Workspace ONE
Windows
Script — file drop
scripts/windows/install.ps1
Workspace ONE
Windows
Script — policy merge
scripts/windows/install-policy.ps1 (or set OMA-URI under HKLM\Software\Policies\Microsoft\VSCode via a Profile)
Result:
Corporate → corporate transfers allowed
Corporate → personal transfers blocked
Use case: Identify any data entering personal accounts.
Eliminates alert noise from automated processes
Still monitors uploads from other locations
Significant noise reduction
Should be used carefully due to broad scope
Fast remediation
No policy rewrites required
Suppress noisy file types like .log or .xlsx







Identify, classify, and assess risk for SaaS and AI applications used across your environment.
App Intelligence gives your security team a complete, continuously updated view of every SaaS application and AI tool your employees are actually using — not just the ones on your approved list.
In most organizations, employees use five to fifteen times more applications than IT formally manages. This includes AI assistants like ChatGPT and Claude, personal cloud storage, file-sharing services, and agentic AI tools that act on behalf of users. Until now, this activity has been largely invisible to security teams.
App Intelligence changes that. Using data movement APIs provided by Apple and Microsoft, Nightfall's lightweight agent detects paste and file upload activity to automatically discover these applications, assign a risk score, categorize them by functional type, and surface early adopters — with none of the latency associated with traditional DLP tools.
Nightfall classifies every detected app into one of twelve categories. Categories reflect the nature of the product and its typical data exposure potential — they form the foundation of how risk is calculated. Your team can use categories to filter, prioritize, and focus on the parts of your app landscape that matter most.
A note on cloud productivity suites: Nightfall classifies by the actual product surface an employee uses, not the parent company brand. For example, Google Workspace Mail and Google Docs are classified as Business SaaS because their primary function is collaboration and editing. Google Drive is classified as Cloud Storage / Sync because its primary function is file storage and bulk sync. The same principle applies to Microsoft 365, AWS, and Salesforce subdomains.
Every app in App Intelligence displays one of four risk labels: Low, Medium, High, or Critical. These reflect Nightfall's assessment of how much data exposure risk the app represents in your environment.
Risk is calculated in two steps. First, every app starts with a baseline risk level inherited from its category — for example, File Sharing apps start at Critical and Core Systems start at Low. Second, Nightfall adjusts the score for the specific app within that category: if an app is consumer-focused, allows anonymous access, or is less governed than its peers, the risk increases. If the app is unusually well-governed for its category — for example, enterprise-only access with mandatory SSO — the risk may decrease.
Access App Intelligence from the Discovery section of the left-hand navigation menu.
The App Intelligence list view, showing 5,892 total apps discovered across the organization.
The page is divided into two main sections:
App Insights (Top Panel) The insights panel gives you a quick summary of what's happening across your app landscape. It shows:
Total Apps discovered, AI Apps in use, and Total Users observed
Top AI Apps by Adoption — the GenAI tools growing fastest in your environment over the last 30 days, shown as a percentage of users
Top Apps by Data Volume — the apps handling the most data, with user counts and data sizes
App List (Bottom Panel) The full table of all discovered applications. Each row shows:
Use the filter bar above the app list to narrow results by:
Time range (e.g., Last 30 Days)
App Name — search by name or keyword
Domain — filter to a specific domain
Category — show only GenAI, Cloud Storage, etc.
Clicking any app in the list opens its detail page.
The App Details view for Wisprflow (wisprflow.ai), an AI agent platform classified as High risk.
The detail view includes:
Summary stats — total users, when first and last seen
App Risk panel — a plain-language explanation of why Nightfall assigned this risk level, covering category, identity boundaries, and data exposure
Destination List — a breakdown of every subdomain or endpoint within the app where data was sent, including per-destination user counts, data volume, and activity timestamps. This helps you understand whether a tool is being used for its core purpose or whether data is flowing to admin panels, APIs, or documentation portals.
Goal: Understand which apps are active in your environment and identify where to focus first.
Steps:
Navigate to Discovery → App Intelligence in the left sidebar.
Review the App Insights panel at the top of the page. Note:
How many Total Apps have been discovered.
Which AI Apps
Goal: Understand why an app received a high risk score and gather the information your team needs to take action.
Steps:
Filter the App List by Risk = High and sort by Users to surface the most widely adopted high-risk apps first.
Click on an app to open its Detail View.
Read the App Risk explanation on the right side. This gives you Nightfall's reasoning in plain language — for example, whether the tool is an AI agent that can access data on behalf of users, or whether it lacks standard enterprise governance controls.
Goal: Understand the risk signals behind a specific app and determine whether action is needed.
Steps:
Identify an app of interest in the App List — for example, an AI Agents tool or a GenAI service you don't recognize.
Wisprflow appears in the App List as an AI Agents tool with a High risk rating, 28 users, and 2.2 GB of data sent — with activity as recently as 5 hours ago.
Click the app row to open its Detail View.
In the App Risk panel, read Nightfall's risk explanation. For an AI Agents tool, this will typically explain that the platform is designed to build and deploy autonomous agents that can access and move data across multiple systems — and why this elevates the risk classification above the category baseline.
Check Total Users and compare it to First Seen. If a large number of users adopted the tool quickly, that's a signal of fast organic growth that may have outpaced governance review.
A security team at a mid-size technology company suspects employees are using unauthorized GenAI tools but has no visibility into which ones or how widely.
They open App Intelligence, filter by Category = GenAI, and sort by Users. Within minutes, they can see that three GenAI tools not on the approved list have been adopted by dozens of employees. They use the details view to assess each tool's risk score and destination activity, then route the highest-risk findings to the IT governance team with the context they need to take action.
An insider risk analyst receives an alert about unusual data movement patterns. They open App Intelligence and sort by Last Seen to find recently active apps. They spot an AI Agents platform that was first seen a month ago but has seen a spike in data volume in the last 24 hours.
Clicking into the app detail, they see the risk explanation highlights that the tool is designed to build autonomous agents capable of accessing data across multiple systems — and that several API-level destinations are active. The analyst notes their findings and escalates to the security team for deeper investigation.
An IT Policy Owner needs to audit which high-risk apps are active in the environment as part of a quarterly governance review. Rather than sifting through all discovered apps manually, they filter the App List to Risk = High or Critical, sort by Users, and work through the results.
Using the risk scores and destination breakdowns, the owner quickly identifies which apps need immediate attention from the security team and which are low-risk tools that don't require escalation. Within a single session they have a clear picture of their app risk landscape to bring into the governance review.
A data security engineer reviewing App Intelligence notices a file-sharing site with Critical risk that has been used by multiple employees to send data externally. Rather than just flagging it for review, they want to act immediately.
From the app's detail page, they click Add to Collection and add the domain to their organization's block list collection — the same list already enforced by Nightfall's exfiltration control policies. The domain is now blocked from receiving corporate data without any separate policy configuration required. For a second app — an approved cloud storage tool that was mistakenly triggering alerts — they add it to the allow list collection instead, suppressing false positives going forward.
App Intelligence becomes the discovery layer that feeds directly into enforcement, closing the loop between visibility and protection.
A CISO preparing for an upcoming compliance review needs a clear picture of all AI tools in use across the organization, including what data types are being transmitted. They use the Top AI Apps by Adoption insight to see which GenAI tools are most widely used, then filter the app list to Category = GenAI to review risk levels across the full set.
For any GenAI tool with a High risk rating, they open the detail view to review the risk explanation and destination breakdown. This gives them the documentation they need to demonstrate that the organization has visibility into AI tool usage and the risk signals associated with each one.
How often is the app data refreshed? App Intelligence data is refreshed hourly. The "Last updated" timestamp in the top right corner of the page shows when the data was last synced.
How does Nightfall discover which apps employees are using? Nightfall uses data movement APIs provided by Apple and Microsoft to detect paste and file upload activity on enrolled devices — not network traffic or keystrokes. This lightweight approach means App Intelligence can identify which apps employees are sending data to without the performance impact or latency of traditional DLP tools. No additional configuration is required; new apps are detected automatically.
How exactly is an app's risk score calculated? Nightfall uses a two-step process. First, every app starts with a baseline risk level inherited from its category — for example, File Sharing apps start at Critical and Core Systems start at Low. Second, Nightfall evaluates the specific app within its category: if it's consumer-focused, allows anonymous access, or is less governed than peers, the risk increases. If the app is unusually well-governed for its category — mandatory SSO, enterprise-only access — the risk may decrease. This category-based assessment is then combined with usage signals including behavioral patterns and identity boundary data to produce the final label.
When reviewing individual events in Forensic Search, scoring goes a step further. If your organization has completed MDM integration, Nightfall can determine whether a user is sending data to a corporate or personal account at a given destination — for example, distinguishing between a managed Google Workspace account and a personal Gmail account at the same domain (mail.google.com). This account context is factored into the event-level risk score in Forensic Search, giving you a more precise signal when investigating specific user activity.
Can I override the risk level Nightfall assigns? Not in v1. The ability to apply custom risk overrides is planned for a future release.
Why do some apps show a high Destination Count? Destination Count reflects the number of distinct subdomains or endpoints Nightfall has observed data flowing to within a single app's domain. For many apps, destinations are specific enough to tell you something meaningful about how the app is being used.
GitHub is a good example: each destination corresponds to a specific repository. A SecOps admin reviewing GitHub's destination list can research individual repos to determine whether employees are pushing data to a corporate repository, a public open-source project, or a personal account — a meaningful distinction when assessing data exposure risk. The same principle applies to other developer tools, cloud storage platforms, and any app where the destination encodes context about the recipient or purpose.
Will App Intelligence block apps or take enforcement actions? App Intelligence itself is a visibility tool — it does not block apps directly. However, you can act on what you find by using the Add to Collection button in any app's detail view. This lets you add the app's domain to a domain collection, which feeds directly into Nightfall's exfiltration control policies. Adding a domain to a block list collection will prevent data from being sent to that destination; adding it to an allow list collection explicitly permits it and suppresses false positives. Automated enforcement actions beyond this are planned for a future release.
Does App Intelligence cover desktop apps like Slack or Zoom? Not yet — but coming soon! The current release focuses on web apps and GenAI tools accessed through the browser. Coverage for native desktop applications is on the roadmap for an upcoming release.
What should I do first if I'm new to App Intelligence? Start with the App Insights panel to understand the shape of your environment — how many apps are active, which AI tools are growing fastest, and where the most data is flowing. Then filter the App List to Risk = High or Critical, sort by Users, and work through the results. This gives you a focused view of the apps that carry the most risk and the widest reach across your organization.
For additional help, contact Nightfall support or reach out to your Customer Success Manager.
Risk — focus on High or Critical apps
Which apps have the most users over the last 30 days (Top Apps by User Count, 30d).
In the App List, sort by Risk to bring the highest-risk apps to the top. Look for any apps labeled Critical or High that you don't recognize.
Example showing a small tenant environment. Deepseek is flagged as Critical risk — a GenAI tool with elevated data exposure signals.
Sort by Last Seen to find apps with very recent activity, then cross-reference with First Seen to spot newly adopted tools your team may not be aware of.
Use the Category filter and select GenAI and AI Agents to see all AI tools in use. This is a fast way to understand your organization's AI footprint.
Note the Total Users and First Seen date. If adoption is recent and growing, that context is useful when escalating to your IT or security governance team.
If your team decides to act on what you've found, use the Add to Collection button to add the app's domain to a domain collection. Choose a block list collection to prevent data from flowing to the app, or an allow list collection to explicitly permit it within your exfiltration control policies.
Cross-reference the Data Volume against the number of users. Disproportionately high data volume relative to user count can indicate automated workflows, bulk uploads, or exfiltration-style behavior.
Click Show Events on a destination row to see the individual users and corresponding events associated with that site. This is one of the most powerful features in App Intelligence — it lets you move from aggregate risk signals to the specific people and actions driving them.
Share your findings with your IT or security governance team, including the risk score, user count, data volume, any API-level destinations observed, and the specific user activity surfaced via Show Events.
Core System
Low
Business systems of record with strict identity controls and low exfiltration risk.
Workday, NetSuite, SAP, Salesforce CRM
🟢 Low
Minimal concern; typically well-governed, established tools with strong identity boundaries.
🟡 Medium
Worth monitoring; may involve less-governed surfaces or moderate data exposure potential.
🔴 High
App Name
The detected application, grouped under its canonical domain
Domain
The primary domain associated with the app
Destination Count
Business SaaS
Low
Enterprise productivity and collaboration tools.
Slack, Notion, Figma, Canva, Asana, Loom
Internal Apps
Low
Internal or private applications, staging/QA environments, and SSO-only portals.
Internal dashboards, staging portals, *.internal domains
Public Web
Low
General consumer or informational websites not primarily designed for file transfer.
YouTube, Wikipedia, Medium, Amazon
Social / Messaging
Medium
External messaging or social platforms where users can send or post corporate data.
WhatsApp Web, Telegram, Discord, LinkedIn, X/Twitter
Cloud Providers / Infra
Medium
Cloud consoles and infrastructure administration surfaces.
AWS Console, GCP Console, Azure Portal, Cloudflare
GenAI
High
LLMs, AI assistants, and AI-powered creation tools that may ingest internal data.
ChatGPT, Claude.ai, Gemini, Perplexity, DeepSeek
Developer Tools
High
Platforms hosting source code, configuration, logs, or automation pipelines.
GitHub, GitLab, Replit, Databricks, Netlify
Unknown
High
Domains that cannot be reliably classified (e.g., raw IPs or unrecognized destinations).
Unclassified IPs, localhost, unresolved domains
AI Agents
Critical
Autonomous or semi-autonomous systems that act on behalf of users to access and move data.
Wisprflow, Glean, n8n, Zapier Desktop Runner
Cloud Storage / Sync
High
Cloud-based file storage and synchronization platforms with high exfiltration risk due to bulk file movement and multi-device sync.
Google Drive, Dropbox, Box, iCloud, OneDrive
File Sharing
Critical
Public or anonymous file-sharing services with minimal identity boundaries.
WeTransfer, file.io, Snapdrop, Pastebin
Requires attention; elevated data risk or boundary concerns detected.
🚨 Critical
Immediate review recommended; significant risk signals across multiple dimensions.
Number of distinct subdomains or destinations observed
Category
App type classification
Risk
Nightfall's computed risk level
Users
Number of users or unique devices observed accessing this app
Data Volume
Total data transmitted to this destination
First Seen
When Nightfall first detected activity to this app
Last Seen
Most recent observed activity




MCP Gateway sits between your AI clients (Cursor, Claude Code, Claude connectors, ChatGPT, VS Code, Windsurf) and the remote MCP servers those clients call (GitHub, Linear, Notion, an internal HTTPS service). People stop pasting vendor URLs and personal tokens into mcp.json. They point one Nightfall URL. You decide which servers and tools exist, whose credentials are in play, and you get a log of what was asked.
Use MCP Server Visibility when the question is "what is already running on laptops," including local stdio servers and shadow installs nobody approved. Visibility does not broker credentials or sit on the call path.
Use MCP Gateway when you want a sanctioned remote path that you can shrink, revoke, and audit. Typical jobs:
Do not use the gateway to inventory local filesystem or stdio MCP. That is . The gateway also does not stop someone from typing a vendor URL into a local Cursor or Claude Code config. It governs the traffic that uses the Setup URL.
Enabling a server is not all-or-nothing. Pick the smallest control that matches the risk. These four actions do not overlap.
Leave a catalog row disabled (do not click Enable) when the server is not sanctioned yet. Uncertified catalog rows cannot be enabled in place; add them as custom only if you accept that risk.
New tools discovered on refresh start enabled. After Refresh tools, open the Write and Delete groups and disable anything you do not want in agents. The org-wide Tools tab is a read-only index (name, server, description). You change enablement on the server, not on that tab.
Block vs disable tools: Block is the whole vendor. Disable is one capability. If Linear is approved but delete_* is not, disable those tools. If Linear should not be reachable at all this week, Block.
A disabled or blocked tool is how you hide a capability from clients today. Endpoint DLP that mentions MCP collections is a different surface: .
Two MCP roles exist. Settings lists them as Mcp Gateway Admin and Mcp Gateway User. In the gateway they show as MCP Admin and MCP User.
MCP Admins see every sub-tab, in this order:
Audit
Server Catalog
Enabled Servers
Tools
MCP Users (members) see Enabled Servers and Setup only. They land on Enabled Servers. They can connect their own OAuth or PAT. They cannot enable servers, invite people, or open Audit.
People who only have MCP Gateway access (and no other Nightfall products) get a standalone MCP Gateway app at /mcp-gateway, with the same sub-tabs their role allows. Everyone else uses AI Governance > MCP Gateway. The dropdown label looks like MCP Gateway: Setup.
If your role is still loading, the UI stays open (admin-capable) until the server says you are a member. Server-side checks still apply.
An admin enables a server from the catalog or adds one by URL.
Each person points Cursor, Claude Code, Windsurf, or VS Code at the tenant MCP endpoint URL from Setup.
The client opens a browser. Nightfall asks them to Approve or Deny access to the gateway.
If the upstream server needs GitHub (or similar), they click Connect
Two different "Connect" moments: the browser page Connect to Nightfall MCP Gateway is client-to-gateway. Connect on a server row is gateway-to-upstream (GitHub, Linear, and so on).
The gateway is a Nightfall-hosted remote MCP server. Clients that speak streamable HTTP and OAuth use the URL from Setup.
It does not proxy local stdio servers (a filesystem server on a developer's machine, for example). Those stay on . The gateway is for remote HTTP MCP: GitHub, Linear, Notion, an internal service you expose over HTTPS, and the like.
It aggregates tools. MCP prompts and resources are not served through the gateway in this release.
There is no separate gateway password. Sign-in is Nightfall SSO (or whatever identity you already use on the platform). When a client connects, the browser redirects to Nightfall for authentication and consent.
The workspace path in the Setup URL routes traffic to your tenant. Access still requires a Nightfall sign-in and membership. A URL by itself is not a credential.
Every call through the gateway uses two different secrets:
The client's gateway token. Issued after Approve on Connect to Nightfall MCP Gateway. It proves the person to Nightfall. It is scoped to your tenant and is not sent to GitHub, Linear, or any other backend.
The backend credential. The user's OAuth tokens or PAT for that upstream server. Nightfall stores those encrypted and injects them when calling the backend. Clients never see them.
Admins can see that a connection exists, how many people are connected, and connection health (Connected, Token expired, Not connected). They cannot see token or key values. OAuth client secrets on Set OAuth client are write-only; you will not see the secret again.
For OAuth backends, each person's Connect flow talks to the provider. Nightfall does not see that password. After approval, calls from that person's clients use that person's identity at the backend, so the provider's own permissions and audit trail match a real user.
If a backend is down, calls fail with the backend error. Repeated calls to a failing server are short-circuited so clients fail fast instead of hanging. Other enabled servers keep working.
Custom Remote URL values must be public http(s) MCP endpoints. Private, link-local, and cloud-metadata addresses are rejected. Use Add custom server for internal servers only when they are reachable from Nightfall's hosted service over HTTPS.
You have MCP Admin or System Administrator privileges in Nightfall. The tab is visible. You want one working client today.
Open AI Governance > MCP Gateway > Setup. The card title is Connect your MCP client.
You should see MCP endpoint URL and Copy. If you see Your MCP endpoint is unavailable right now, provisioning is not finished. If you see Couldn't load your MCP endpoint, retry. If you still get the "isn't enabled" screen, your Nightfall rep has more work to do.
Go to Server Catalog. Description in the product: curated servers you can enable; anything else is Add custom server.
Search by name, or filter Certification to Certified / Uncertified.
Certified rows have Enable. Uncertified rows do not. The tooltip says to add those manually via Add custom server.
Click Enable. Set Alias (max 24 characters; letters, numbers, hyphens, underscores). Tools will appear as <alias>__<tool>.
Columns: Alias, Canonical name, URL, Auth, Status, Validation, Connected.
Auth values you may see: None, OAuth (DCR), OAuth (static), OAuth (CIMD), PAT.
Validation values: Pending, Config valid, Config valid - manual OAuth, Awaiting first user OAuth, Tools discovered, Tools discovery failed, Reconnect required.
Use Validate or, on the server page, Validate now. Refresh tools pulls a new tool list. View check results shows the raw checks.
Setup has four client tabs. Use the snippet the console generates (it already has your URL). The shapes are:
Cursor (~/.cursor/mcp.json or project .cursor/mcp.json):
Reload Cursor's MCP server list, or restart Cursor.
Claude Code (no config file):
It registers immediately. No restart.
Windsurf (~/.codeium/windsurf/mcp_config.json). Note serverUrl, not url:
Reload Cascade's MCP list from Windsurf settings.
VS Code (workspace .vscode/mcp.json or user profile). Note servers and "type": "http":
Run MCP: List Servers to confirm.
The client opens Connect to Nightfall MCP Gateway. Sign in if asked. Approve. If the window is wrong, Deny and close the tab. Switch account if you are in the wrong Nightfall user.
Then invoke a tool. Open Audit. You should see User, Server, Tool, Method, Event, Status, Time.
You have MCP User. You do not see Catalog, Tools, Users, or Audit.
Open Setup. Copy the snippet for your client. Same four clients as above.
Approve the Nightfall consent page when the browser opens.
Open Enabled Servers. Member copy: MCP servers your company has enabled. Connect your own credentials where required.
Blocked servers are hidden from you. If the list is empty: No servers enabled for your company
Disabled tools are hidden from MCP clients. Tools discovered later start enabled.
Use this for an internal remote MCP server, or an uncertified catalog entry.
Server Catalog > Add custom server.
Alias and Remote URL (https://host/mcp). Invalid URLs get Enter a valid http(s) URL.
Add. Toast: Added "<alias>". It now appears under Servers.
If the catalog table itself is empty, you can still add by URL.
Uncertified catalog rows cannot be enabled in place. The product tells you to add them as custom if you need them now. Ask your Nightfall account team if you want an entry certified.
Tool lists refresh when you enable a server, after a user's first connection, on Refresh tools, and in the background. New tools start enabled. Disable the ones you do not want clients to see.
Admin enables the certified GitHub catalog entry (or adds it as custom if that is how you run it).
If the provider needs a static OAuth app, an admin uses Set OAuth client / Update OAuth client. Credentials are write-only. You will not see the secret again.
Each member clicks Connect and finishes GitHub's consent.
Admins see N connected
Set OAuth client is also on the server detail Setup card when the product has setup guidance for that server.
Auth type PAT:
Credential scope: Shared plus Paste PAT (shared): one token, injected for everyone.
Credential scope: Per-user plus each person Set my PAT: no fallback to a shared token.
PAT auth header on the server detail page defaults to Default (Authorization: Bearer) unless an admin changes it.
Admins can paste a PAT on a None auth server to switch it to PAT.
You approved GitHub, then legal says pause it, or the vendor is in an incident. You do not want to rebuild the alias and OAuth app next week.
Open Enabled Servers.
Block. The confirm dialog warns if people are still connected. Status becomes Blocked. Members no longer see the row. Clients lose every tool from that alias.
Unblock when the pause is over.
Use Remove only when the server should not return and stored credentials should die with it. The dialog says this cannot be undone.
Rename changes the alias, which changes the <alias>__<tool> names clients already have. Do that on purpose, not as a substitute for Block.
GitHub (or Linear, Notion, any catalog server) ships read, write, and delete in one package. Most teams want search and list, not delete_* or admin.
Open the server (row click). Breadcrumb: Enabled Servers › {alias}.
On the Tools card, use the Write, Delete, and Unspecified groups. Columns: Tool Name, Description, Enabled (admin) or Enabled for me (member).
Select the tools you do not want in agents. Bulk Disable.
Admins can also see Disabled for me when a member hid a tool only for themselves. That does not protect the company. Org risk belongs on the admin Enabled column.
After Refresh tools, walk Write and Delete again. New tools start enabled.
The Tools tab (admin, org-wide) is an index only: Exposed name, Server, Description. Search there. Change enablement on the server. If the index is empty: Refresh tools on a server from the Servers tab.
Users (admin): Console users with MCP Gateway access. Invite people from your company directory without exposing them in the admin user list.
Invite users.
Directory search or Upload CSV (one email per line).
Assign MCP Admin or MCP User.
Outcomes you may see: already invited, already has this role, or a cross-company conflict.
The table: Email, Role, Created, Status (ACTIVE, or EXPIRES IN N DAY(S)).
Edit changes Admin ↔ User. Delete removes MCP Gateway access only. Other Nightfall access stays. You cannot edit or remove yourself.
Pending invitations appear in the table. There is no revoke action on a pending invite in the current console.
MCP-only users are not a replacement for Nightfall Settings → Users & Roles. Invite here when you want gateway access without a full console seat.
Audit (admin). Default window is the last 7 days.
Columns: User, Server, Tool, Method, Event, Status, Time. Search by server or tool name. Status values are humanized: success, failure, error, denied, blocked.
Open a row for Request, Identifiers (User, Session, Event ID, Request URL), and Request payload.
Export to CSV → Send Download Link. You get email within 15 minutes.
You can deep-link with ?userId= on the Audit URL. There is no "View logs" button on user rows yet.
Members who hit Audit see You don't have access to audit logs.
This tab is a call log. It does not show a separate "would block" or policy-reason column. To take a capability away, Block the server or Disable the tool (see What you can turn off).
Audit stores who called, which server and tool, method, event, status, identifiers, and the request arguments (capped at 8 KiB). Backend tool responses are not stored.
When someone leaves: Delete their MCP Gateway access on Users (or remove them from Nightfall). Revoke or reconnect is per server via Connect / disconnect on Enabled Servers. Their next client call should fail once access is gone. Re-inviting them later starts a fresh sign-in.
These clients use custom connectors, not the four Setup file snippets. Copy the MCP endpoint URL from Setup first.
You need a Claude Team or Enterprise plan for an org-wide connector. Only an Owner or Primary Owner can add it to the organization.
In Claude, open Organization settings > Connectors (or Admin settings > Connectors).
Add / Add custom connector. If asked for a type, choose Custom then Web.
Name it something people will recognize, for example Nightfall MCP Gateway.
Each member still selects Connect on that connector, signs in to Nightfall, and Approve. Adding the connector does not grant access by itself.
In a conversation, turn the connector on with + then Connectors. Tools show as <alias>__<tool>. Some backends still need Connect on Enabled Servers in Nightfall (GitHub is the usual case).
To make the gateway the only Claude path: add only this connector, and do not add direct Linear/Notion/GitHub connectors for the same services. On Team and Enterprise, members cannot add org connectors themselves. Claude Code still reads a local config file a user can edit.
On Pro or Max, a person can Add custom connector themselves with the same URL and empty OAuth fields.
If tools are missing in chat: the connector may be off for that conversation, Nightfall sign-in may be incomplete, or the backend still needs Connect in the Nightfall console. HIPAA-ready Claude Enterprise plans can block custom connectors org-wide; that is a Claude admin setting, not Nightfall.
ChatGPT can attach the same Setup URL as a custom MCP app on Business, Enterprise, and Edu workspaces (developer mode). Individual paid plans can do this in developer mode as well.
A ChatGPT admin turns on developer mode / custom MCP connectors under workspace permissions (exact labels vary by ChatGPT plan).
Settings > Apps & Connectors > Create. Name it Nightfall MCP Gateway. Set the connector URL to the MCP endpoint URL from Setup. Authentication: OAuth. Leave static client fields empty.
Scan tools and complete Nightfall sign-in when prompted. Publish when you are ready.
ChatGPT can further restrict which of the gateway's tools that app may call. Nightfall still decides which servers and tools exist at all. Prefer doing tool governance in Nightfall so Cursor, Claude, and ChatGPT see the same set.
On Enterprise/Edu, refresh the app's action list when you enable new Nightfall servers. On Business, published apps may be frozen; you may need to recreate the app to pick up new tools.
Members authenticate individually on first use. Publish only the gateway app for services you already route through Nightfall; do not also enable ChatGPT's direct connector for the same GitHub or Linear instance if you want a single path.
Server info can include Alias, Canonical name, Remote URL, MCP URL, Transport, Additional headers, PAT auth header, Created, Last validated, Last tools refresh, Validation, Check results, OAuth client ID, Scopes, and Discovered OAuth endpoints.
Remove server and Validate now sit in the header next to Connect.
If the alias is wrong: Server not found.
URL shape: /mcp/authorize with request_id and short_code from the client.
Missing params: This link is invalid. Restart from the MCP client.
Loading: Signing you in...
Main: Connect to Nightfall MCP Gateway. Copy explains that an MCP client is requesting access; decline if you did not start it.
Logged in as {email}. Switch account
Questions on that page go to your Nightfall admin or .
Command palette (when you have access): Go to MCP Gateway Setup, Go to Enabled Servers, Go to Server Catalog, Go to Gateway Tools, Go to Gateway Audit, Go to Gateway Users.
is the inventory of what endpoints already run, including servers nobody approved. The gateway is only the servers you enable here, plus the credentials and the call log.
A usual split: find shadow MCP on Visibility, decide what is allowed, enable that set on the gateway, point clients at Setup, and use Audit (and Visibility notifications) for everything else.
File-configured clients (Cursor, Claude Code, VS Code, Windsurf) can still be pointed at a vendor URL instead of Setup. This tab does not override those files. Claude.org connectors and ChatGPT workspace apps are admin-controlled on the higher plans.
Setup
The client lists tools as <alias>__<tool> (for example github__search).
Each invocation shows up on Audit.
Some OAuth servers ask for a client id and secret in the wizard. Those fields are optional here. You can leave them blank and use Set OAuth client on the server later.
Success toast: Enabled "<alias>". It now appears under Servers.
For OAuth servers, click Connect. Allow popups. If you see Popup blocked, allow popups and click Connect again.
Connection states: Connected, Token expired, Not connected.
For PAT servers, use Set my PAT.
On a server's tool list you can turn Enabled for me off for tools you do not want in your client. Admins can also disable a tool for everyone.
Confirm in a client: those names are gone from the tool list and a call to them fails.
Add.
After deny: Access declined. Close the tab.
Failure: Couldn't complete this request. Close the tab and connect again.
IT cannot see or revoke the GitHub / Linear tokens sitting in every developer's client
Broker those credentials. Admins see that a connection exists and can cut it. They never see the secret.
You cannot answer "who called delete_issue last week, with what arguments"
Audit records user, server, tool, status, and request payload.
Someone left and their AI connectors still work until each vendor token expires
Remove MCP access (or the Nightfall user). The next client call fails. Revoke the upstream connection so the provider is told to invalidate its token.
GitHub MCP is useful for search, dangerous for write and delete
Keep the server enabled. Disable the write and delete tools. Clients stop listing them and cannot call them.
A vendor is having an incident, or you want Linear gone from every client today
This server must stop for everyone, but you may bring it back
Block on Enabled Servers
Members lose the row. Tools vanish from the aggregator.
Alias, URL, auth setup, stored credentials
{
"mcpServers": {
"nightfall": {
"url": "<MCP endpoint URL from Setup>"
}
}
}claude mcp add --transport http nightfall <MCP endpoint URL from Setup>{
"mcpServers": {
"nightfall": {
"serverUrl": "<MCP endpoint URL from Setup>"
}
}
}{
"servers": {
"nightfall": {
"type": "http",
"url": "<MCP endpoint URL from Setup>"
}
}
}MCP Gateway isn't enabled for your organization
Nightfall rep. Then Check again.
Still not enabled - check back again shortly.
Provisioning still running.
Your MCP endpoint is unavailable right now
Block the server. Config stays. Tools disappear. Unblock when you are ready.
You are done with a server and want credentials wiped
Remove. This cannot be undone.
Contractors should use the gateway without a full Nightfall admin seat
Invite them as MCP User on the Users tab.
Claude or ChatGPT should not also have a direct GitHub connector
Publish only the Nightfall URL as the org connector. Do tool governance once, here.
This server must go away for good
Remove
Gone.
Nothing. Tools cache and credentials are deleted.
The server stays. These tools must not exist for anyone (delete, admin, write)
Disable on the server's Tools card (admin Enabled column). Bulk select works.
Disabled tools drop out of listings and cannot be invoked. Other tools stay.
The server, other tools, everyone's connections
The server is fine for the company. I do not want this tool in my client
Turn off Enabled for me
Only that person's client loses the tool
Org-wide enablement. Admins still see Disabled for me
Wait for tenant provisioning to finish.
Catalog Enable disabled, uncertified tooltip
Use Add custom server.
Popup blocked
Allow popups, click Connect again.
Token expired
Connect again on that server.
Tools missing in the client
Server blocked, tool disabled, or you still need Connect / Set my PAT. Validation may be Tools discovery failed or Awaiting first user OAuth.
No tools cached on the Tools tab
Refresh tools on Enabled Servers.
Client cannot authenticate
Confirm you pasted the URL from Setup. Cursor uses url, Windsurf uses serverUrl, VS Code uses servers + type: http, Claude Code uses the CLI.
The Device List page is the fleet view for the Nightfall endpoint agent. It shows every macOS and Windows device that has checked in to your Nightfall tenant, along with the agent state, MDM profile state, browser-extension state, and any active policy exceptions for each device.
Use this page to:
Confirm a fresh rollout reached every device you targeted.
Find devices that need attention (agent in error, macOS permissions missing, MDM profile out of date, extension not installed).
Confirm the Nightfall browser extension is loaded and enabled on the browsers your users actually run.
Triage a single device by opening the side panel for full status detail.
Remove a device that is decommissioned or no longer in scope.
Where to find it. Configuration → Integrations → Mac or Windows Endpoints.
At the top of the page you will see:
Device Information heading, with the line "The Nightfall endpoint agent has been deployed to the following devices. After installation, the agent automatically receives updates to ensure it stays secure and up to date."
A 60-day cleanup notice: "Devices that have been disconnected for more than 60 days are automatically removed from this list." Once a device is removed, the only way to bring it back is for that device to reconnect and check in.
Total device count. Shown immediately above the table as N devices (or 1 device). This number reflects all filters and search applied to the page.
When a new macOS agent version ships with new security features that require an updated MDM profile, an orange button labeled MDM Profile Update Required (Mac Only) appears in the filter row.
Clicking the button opens the MDM Profile Update Required modal:
Headline: "Profile update required for devices."
Body: "Agent version X.Y.Z includes new security features that require an updated MDM profile. Devices will continue to function but may have limited capabilities until the profile is updated."
Devices Requiring Update count, sourced from the agent's profile-version handshake against the latest published profile.
What's New in This Profile
If you do not see this banner, your fleet's profiles are at the expected version and no action is needed.
Four single-click chip filters sit in the filter row. Click a chip to apply, click again to clear. Clicking a chip replaces any other filters you have set.
The Add Filters dropdown gives you the full filter set. Filters compose with AND across types.
Filter selections are stored in the URL so you can bookmark or share a filtered view.
Columns appear in this order. Click the header tooltip (the small info icon) to see the in-product description.
Tooltip: "Operating system reported by the device at last check-in."
Renders the OS logo (Apple or Windows). Hover the cell to see the OS version reported by the device.
Tooltip: "Hostname and unique device identifier."
Two-line cell: device hostname (bold) above the unique device ID. Hover to see both spelled out. This column is sortable.
Tooltip: "Primary user signed in to this device (from MDM or directory sync)."
The user-account email Nightfall received from your MDM or directory sync. Shows — when no user is associated.
Tooltip: "Connection state and last-seen timestamp."
Pill badge plus a relative timestamp below it (for example, "3 minutes ago"). Hover the cell to see the absolute timestamp.
Tooltip: "The agent updates automatically - no manual action required. If a device hasn't been online recently, the version shown here may be outdated."
The version string the agent last reported. If the version is older than the latest published version for that OS, an amber warning triangle appears next to it. Hover the triangle to see "Outdated version. Latest: X.Y.Z."
Tooltip: "macOS system permissions and agent runtime errors detected on this device."
Two states:
All granted (green check). No missing macOS permissions and no agent runtime errors. Hovering reveals what was checked: on macOS, the three permissions (Full Disk Access, Screen Recording, Accessibility) plus "No agent errors"; on Windows, "No issues detected" plus "No agent errors."
For each missing permission, the tooltip shows:
The three macOS permissions tracked here are:
Full Disk Access. Required to scan files outside the user's home directory.
Screen Recording. Required for screen-based exfiltration detection.
Accessibility. Required for thick-app and clipboard monitoring.
For each agent error, the tooltip shows "Agent error: name." The six error codes are:
User Agent Not Connected. The user-space agent component is not running or cannot reach the system extension.
Driver Missing. The Nightfall kernel or system driver is not present on the device.
Driver Not Loaded. The driver is installed but did not load. Usually a reboot or an MDM payload approval is needed.
User Data Missing.
Profile status sub-line (macOS). When MDM profile state is available, it appears under the permissions summary as one of: Up to Date, Out of Date, or Not Installed. This pairs with the MDM Profile Update Required banner described in 3 above.
Tooltip: "Browsers with the Nightfall extension installed and any attached profiles."
Shows up to three browser icons inline, each with a status dot. A +N chip appears when more than three browsers report state.
Hover the cell for the full list. Each row pairs the browser, the status text, and the status dot.
Supported browsers. Chrome, Edge, Firefox, Safari, Arc, Atlas, Brave, Chrome Beta, Comet, Vivaldi. Safari and Atlas were added in agent v1.2.13.x on macOS and v1.4.35.x on Windows.
Tooltip: "Whether the agent runs without end-user UI."
Green On badge: the agent is running in stealth mode (no tray icon, no notifications).
Gray Off badge: the agent runs visibly to the end user.
Not Available: the device runs an older agent build that does not report stealth state.
Tooltip: "Active policy overrides currently applied to this device."
None when zero active exceptions exist.
N active (violet) when one or more exceptions are scoped to this device. Click the link to jump to the Policy Exception tab in the side panel.
This column is visible only when policy exceptions are enabled on your tenant.
A trash icon at the end of each row. Click to open the single-device delete confirmation. See 7.
Sort. Click the Device Name & ID column header to toggle ascending or descending sort. This is the only sortable column on this page.
Row select. A checkbox in each row. A header checkbox selects every row on the current page. The header checkbox shows a partial-select indicator when some rows on the page are selected.
Bulk delete. When at least one row is selected, a red Delete N Device(s) button appears in the filter row. Clicking it opens the bulk delete confirmation.
Are you sure you want to remove this device?
Removing this device will take it off the monitored list. If the device reconnects to your Nightfall tenant, it will automatically reappear.
What happens next?
This device will no longer appear in the monitored list.
Are you sure you want to remove these N devices?
Removing these devices will take it off the monitored list. If the devices reconnect to your Nightfall tenant, they will automatically reappear.
Disclaimer: This action does not block, disable or uninstall the Nightfall agent from the devices.
Primary: Remove Devices.
Bulk delete is capped at 100 devices per call. If you need to remove more, do it in batches.
Click any row to open the side panel. It has three tabs in this order: Summary, Browser Extension, Policy Exception. The Policy Exception tab is visible only when policy exceptions are enabled on your tenant. Navigate between devices on the current page using the arrows at the top of the panel.
Nine fields in this order:
Operating System. OS logo plus version.
User Email. Or — if not associated.
Agent Status. The same pill described in §6.4.
Last Connection.
Lists every browser on this device that has the Nightfall extension installed.
For each browser:
Browser icon and name.
Connected (green dot) or Disconnected (red dot). Disconnected typically means the browser is closed; reopen the browser and the extension reconnects.
Per-profile count (for browsers that support profiles, like Chrome). Green dot = every profile has the extension enabled; amber = some profiles do; red = none do.
Click the row to expand the per-profile table: Profile name, profile email,
If the device has no browser-extension data yet, the tab reads "No browser extension data available." If it has data but no extensions are installed, it reads "No browser extensions detected."
Lists every active policy override scoped to this device, with policy name, scope, and expiration. From here you can view or revoke an exception. This tab is available when policy exceptions are enabled on your tenant.
Most columns work the same on macOS and Windows. The ones that do not:
The Phase 2 Windows parity for the Device List page shipped in Windows agent v1.4.35.x.
How long until a device shows up after I install the agent?
On the agent's first successful heartbeat, the device appears. Heartbeats run on a short interval after install, so a device that completes install while online typically appears within a minute.
When does a device flip from Online to Disconnected?
When no heartbeat has been received from the agent for more than six hours. The threshold is set tenant-wide and applies equally to macOS and Windows.
When is a device removed from this list?
After 60 consecutive days disconnected. The agent record is deleted from the page; if that device comes back online and checks in, it reappears with a fresh record.
A user changed Mac. Will the old device still appear?
Yes, until 60 consecutive disconnected days pass. If you want to remove the old device sooner, delete it from this page. The agent on the new Mac will appear once it checks in.
Does deleting a device uninstall the agent?
No. Delete only takes the device off the monitored list. The agent keeps running on the device, and if it heartbeats again, the device reappears. To remove the agent itself, run the uninstall through your MDM or follow the manual uninstall steps.
Why can a removed device come back automatically?
Delete sets the device record to "removed" in the Nightfall backend. The agent on the device does not know about the deletion. On its next heartbeat the backend creates a new record, which causes the device to show up again. If you want a permanent removal, uninstall the agent through your MDM or device management workflow.
How many devices can I delete at once?
Up to 100 per bulk delete. If you have more, run a few batches.
Why does the "Disconnected" filter chip include Offline too?
The "Stale Devices" chip is meant as a one-click view for any device that is not actively reachable. Offline is a reserved status today; selecting Stale Devices covers both states so you do not miss anything when the platform expands.
Why is the Agent Errors filter showing six options but the Permissions / MDM column says "N issues"?
"N issues" counts every missing macOS permission and every active agent error code on that device. The Agent Errors filter only filters on the agent error side; if you need to filter on missing permissions, use the Missing Permissions filter instead.
A device has an error code like "ES Client Unauthorized" and stays in Error after a reboot. What now?
This usually means the system extension or kernel driver was denied at the OS layer. On macOS, that is typically a missing Allow Endpoint Security Client approval in your MDM configuration profile. Push the corrected profile via your MDM. If you do not run macOS through MDM, approve manually in System Settings → Privacy & Security.
The MDM Profile Update Required banner appeared, but the devices I patched still show "Profile out of date."
The agent re-reports profile version on its next heartbeat. If the profile reached the device but the column has not updated, wait one heartbeat cycle. If it still shows out of date after that, confirm in your MDM that the profile is delivered and approved on the affected device.
Why does Stealth show "Not Available" on some devices?
Older agent builds do not report stealth state. Update the agent to the current build; the column populates on the next heartbeat.
I see a browser as "Disconnected" in the side panel even though the extension is installed. Why?
Browser extensions only heartbeat when the browser is open. A closed browser shows as Disconnected. Open the browser and the status returns to Connected within a few seconds.
Why is Safari extension state showing up on some devices but not others?
Safari extension tracking was added in macOS agent v1.2.13.x. Devices on older agent builds will not report Safari state until they update.
Can I force-install the extension from this page?
The Device List page reports state; it does not push the extension. Force-install runs through your browser-management mechanism (Google Workspace policy for Chrome, MDM-delivered policy for Edge, Firefox, Brave, Arc, Atlas, Comet, and Vivaldi). Safari is manual install only.
The Permissions / MDM column shows "All granted" but the user can't paste in Claude. What gives?
"All granted" only confirms macOS system permissions and agent runtime health. If a paste is blocked, the cause is usually a Detection & Response policy match, not a permissions issue. Open the Detection & Response page and filter by that user to find the violation.
Where does the CSV export go?
The "Export to CSV" button generates a CSV reflecting the current filters and search, then emails a download link to the address you are signed in with. The link expires after the standard Nightfall report retention window.
Can I export only the devices I have selected?
The CSV export reflects the current filters and search, not the per-row selection. To export a subset, filter to that subset first, then export.
Why does the column tooltip mention "from MDM or directory sync" for User Email, but my device shows —?
A device shows — when Nightfall has not received a user mapping. The two paths that populate this field are: MDM-pushed user assignment in the install payload, and identity-provider sync (Okta, Microsoft Entra ID, Google Workspace). If you have neither configured for that device, the column stays blank.
Why is the Stealth column populated for some devices and not others?
The agent only reports stealth state from v1.2.12.x onward. Devices on older builds will show "Not Available" until they update to the supported version range.
What is the Nightfall Diagnostics tab I sometimes see in the side panel?
That tab is gated to Nightfall support staff. If you see it, it is because your account is impersonating into a support session. There is no customer-facing configuration in it.
For power users:
The following browsers are recognized: Chrome, Firefox, Edge, Safari, Edge, Arc, Brave, OpenAI Atlas, Perplexity Comet, Vivaldi.
Search. A search box, placeholder "Search devices". When any filter is active, the placeholder changes to "Search filtered devices". Search matches against the device ID prefix.
Export to CSV. Opens an "Export as CSV" modal. The full export is delivered by email to your signed-in address. The modal reads "A download link for your report will be sent to your-email-address." The primary action is "Send Download Link."
How to Update lists four steps: download the profile, upload it to your MDM (Kandji, Jamf, Intune, and so on), push it to affected devices, and let the agent re-apply on next check-in.
Primary action: Download Updated Profile.
Browser Extension Not Connected. The agent expects a browser extension that is not currently reporting in.
ES Client Unauthorized. macOS denied the Endpoint Security client. Reapprove the system extension through your MDM.
If the device reconnects, it will be added back automatically.
This action does not block, disable or uninstall the Nightfall agent from the device.
Primary: Remove Device. Secondary: Cancel.
—Agent Version. Current reported version.
Missing Permissions. None when complete, or the list of missing macOS permissions in amber.
Profile Status. Up to Date, Out of Date, Not Installed, or Unknown.
Stealth Mode. On, Off, or Not Available.
MAC Addresses. Every MAC address the device reports. Hidden if the device reports none.
Chip
What it matches
Needs Attention
Any of: connection status is Error; any required macOS permission is missing (Full Disk Access, Screen Recording, or Accessibility); MDM profile is Not Installed; the Nightfall extension is not installed on Chrome, Edge, Firefox, Safari, Arc, or Brave.
Stale Devices
Connection status is Disconnected or Offline.
Update Available
Filter
Values
Notes
OS
macOS, Windows
Agent Status
Status
Color
Meaning
Online
Green
The agent is heartbeating to Nightfall normally.
Disconnected
Missing {permission}:
macOS requires {permission} to monitor file operations and detect
sensitive data exfiltration.
Guide users to: System Settings → Privacy & Security → {permission}
→ Enable NightfallDot color
State
Green
Extension installed and connected.
Amber
Browser installed but the Nightfall extension is not installed yet.
Red
Symptom
What to check first
Status is Disconnected.
The device may be off, asleep, or off-network. If it has been disconnected for under six hours, wait. If longer, confirm the device is online and that the Nightfall agent service is running. If the device is decommissioned, delete it from the list.
Status is Error.
Open the side panel, look at the agent error code under Permissions / MDM, and follow the matching action (driver reload, reapprove system extension, restart the agent service).
Status is Missing full disk access (macOS).
Surface
macOS
Windows
OS column
Apple logo
Windows logo
Agent Status: Missing full disk access
Proto field
UI label
Notes
os
OS
MAC_OS, WINDOWS.
device_name
Agent is on a version older than the latest published version for that OS.
No MDM Profiles
MDM profile status is Not Installed or Out of Date. (macOS only.)
Online, Disconnected, Error, Offline
Agent Version
Up to Date, Out of Date
Compared against the latest published version per OS.
Stealth Mode
Active, Inactive
Profile Status
Up to Date, Out of Date, Not Installed
macOS only. Hidden on Windows.
Missing Permissions
Full Disk Access, Screen Recording, Accessibility
macOS only. Hidden on Windows. Multi-select.
Agent Errors
User Agent Not Connected, Driver Missing, Driver Not Loaded, User Data Missing, Browser Extension Not Connected, ES Client Unauthorized
Multi-select.
Browser Extensions
Chrome, Edge, Firefox, Safari, Arc, Brave, each with "Installed" or "Not Installed"
Multi-select. Pairs of browser + installed state.
Red
The agent has not sent a heartbeat for more than six hours. The device may be powered off, asleep, off-network, or the agent service may be stopped.
Error
Red
The agent is reachable but has reported one or more runtime errors (see the Permissions / MDM column for the specific error codes).
Missing full disk access
Amber
macOS-only. The agent is running but cannot scan files because Full Disk Access has not been granted in System Settings.
Starting
Gray
The agent is in the middle of starting up. This state is brief and usually resolves on the next check-in.
Offline
Gray
Reserved status. Treat the same as Disconnected for action.
NA
Gray
The status was not reported. Usually means an older agent build that pre-dates the current status fields.
Error reading extension state.
Gray
Browser not installed on this device, or status unknown.
Guide the user to System Settings → Privacy & Security → Full Disk Access → enable Nightfall. The agent re-checks within one heartbeat.
N issue(s) with missing permissions.
macOS permissions cannot be force-enabled by the agent itself. Either guide the user through System Settings, or push the permission via your MDM payload.
Profile not installed (macOS).
Use the MDM Profile Update Required banner to download the latest profile and push it via your MDM.
Profile out of date (macOS).
Same path: pull the latest profile and push it to the affected devices. The agent works with the old profile but may lack newer capabilities.
Extension not installed on a supported browser.
Force-install via Google Workspace policy (Chrome) or your MDM's browser-extension payload (Edge, Firefox, Brave, Arc, Atlas, Comet, Vivaldi). Safari is manual install only.
Extension installed but Disconnected in the side panel.
Usually the browser is closed. Reopen the browser; the extension reconnects on launch. If it persists with the browser open, reinstall the extension.
Stealth = Off on a device you expected to be stealth.
Stealth mode is set at agent install time and is not flipped by a config push. Re-deploy the agent with stealth selected to convert.
Agent version is outdated.
No action needed. The agent self-updates on its next check-in. The amber triangle clears automatically.
Yes
Not applicable
Permissions / MDM column: macOS permissions
Full Disk Access, Screen Recording, Accessibility tracked
Not tracked
Permissions / MDM column: agent errors
All six error codes
All six error codes
Permissions / MDM sub-line: profile status
Yes
Not applicable
Stealth column
Reported (On / Off)
Reported (On / Off)
Browser Extensions: Safari
Yes (added in v1.2.13.x)
Not applicable
Browser Extensions: authoritative install state
Agent reports
Agent uses an on-disk scan to verify the extension is actually loaded (since v1.4.22)
MDM Profile Update Required banner
Yes
Not applicable
Profile Status filter
Yes
Hidden
Missing Permissions filter
Yes
Hidden
Device Name
Hostname.
device_id
Device ID
Unique device identifier assigned by the agent.
user_email
User Email
From MDM or directory sync.
connection_status
Agent Status
CONNECTED → Online; DISCONNECTED → Disconnected; ERROR → Error; MISSING_FULL_DISK_ACCESS → Missing full disk access; STARTING → Starting; OFFLINE → Offline; unspecified → NA.
last_connection
Last Connection
Used to render the relative time below the status pill.
agent_version
Agent Version
Compared to latest published version per OS to drive the outdated triangle.
os_version
OS Version
Shown on hover over the OS column.
extension_installation_statuses
Browser Extensions
One entry per browser. BROWSER_INSTALLED (browser present, no extension), EXTENSION_INSTALLED (extension present), ERROR, BROWSER_NOT_INSTALLED, UNKNOWN.
BrowserExtensionStatus.extension_connected
Per-browser Connected/Disconnected
True when at least one profile in that browser is heartbeating.
BrowserProfile.name / .email / .enabled
Per-profile row in the side panel
policy_overrides_count
Policy Exceptions
0 → None; >0 → "N active" link.
stealth_mode
Stealth
STEALTH_MODE_STATUS_ACTIVE → On; STEALTH_MODE_STATUS_INACTIVE → Off; STEALTH_MODE_STATUS_UNKNOWN → Not Available.
profile_status
Profile Status
PROFILE_STATUS_UP_TO_DATE, PROFILE_STATUS_OUT_OF_DATE, PROFILE_STATUS_NOT_INSTALLED, PROFILE_STATUS_UNKNOWN. macOS only.
missing_permissions
Missing Permissions
AGENT_PERMISSION_FULL_DISK_ACCESS, AGENT_PERMISSION_SCREEN_RECORDING, AGENT_PERMISSION_ACCESSIBILITY. macOS only.
errors
Agent Errors
USER_AGENT_NOT_CONNECTED, DRIVER_MISSING, DRIVER_NOT_LOADED, USER_DATA_MISSING, BROWSER_EXTENSION_NOT_CONNECTED, ES_CLIENT_UNAUTHORIZED.
mac_addresses
MAC Addresses
One per row in the Summary tab.