Only this pageAll pages
Powered by GitBook
1 of 97

Data Exfiltration Prevention

Loading...

Loading...

Nightfall Detection Platform

Nightfall Copilot - NyX

Loading...

Dashboard and Events

Loading...

Exfiltration Prevention for Google Drive

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Exfiltration Prevention for Endpoint

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Exfiltration Prevention for Salesforce

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

AI Agent Security

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Loading...

Forensic Search

Loading...

App Intelligence

Loading...

What is Data Exfiltration

Data exfiltration, also known as data theft, data exportation, or data extrusion, is the unauthorized transfer of data from a device or network. It can occur as part of an automated attack or can be performed manually. The illegitimate transfer of data often looks very similar to legitimate transfers, making it difficult to detect.

Common Techniques for Data Exfiltration

Data exfiltration can occur in various ways and through multiple attack methods. Here are some of the most commonly used techniques:

  • Social Engineering and Phishing Attacks: These attacks trick victims into downloading malware and giving up their account credentials.

  • Outbound Emails: Cyber criminals employees or intruders use email to exfiltrate any data that sits on organizations’ outbound email systems.

  • Downloads to Insecure Devices: Data is transferred by users from secure, trusted systems to an insecure device. From there, the attacker can infiltrate the device and exfiltrate the data.

  • Uploads to Cloud Storage: Data can be exfiltrated from cloud storage when data is uploaded to insecure or misconfigured resources.

Nightfall provides a highly revolutionised solution to data exfiltration. Nightfall AI's exfiltration prevention capabilities easily integrate with existing tools, thus catering to security teams and companies across industries. Nightfall's exfiltration solution is much more than just a tool; it proactively protects against data breaches, providing tangible benefits for organizations striving to secure their sensitive information.

Data exfiltration, also known as data theft, data exportation, or data extrusion, is the unauthorized transfer of data from a device or network. It can occur as part of an automated attack or can be performed manually. The illegitimate transfer of data often looks very similar to legitimate transfers, making it difficult to detect.

Data exfiltration can occur in various ways and through multiple attack methods. Here are some of the most commonly used techniques:

  • Social Engineering and Phishing Attacks: These attacks trick victims into downloading malware and giving up their account credentials.

  • Outbound Emails: Cyber criminals employees or intruders use email to exfiltrate any data that sits on organizations’ outbound email systems.

  • Downloads to Insecure Devices: Data is transferred by users from secure, trusted systems to an insecure device. From there, the attacker can infiltrate the device and exfiltrate the data.

Nightfall provides a highly revolutionised solution to data exfiltration. Nightfall AI's exfiltration prevention capabilities easily integrate with existing tools, thus catering to security teams and companies across industries. Nightfall's exfiltration solution is much more than just a tool; it proactively protects against data breaches, providing tangible benefits for organizations striving to secure their sensitive information.

Nightfall Data Exfiltration Prevention

Uploads to Cloud Storage: Data can be exfiltrated from cloud storage when data is uploaded to insecure or misconfigured resources.

Nightfall Exfiltration Solution

Common Techniques for Data Exfiltration

Nightfall Exfiltration Solution

Cover

Exfiltration for Google Drive

Cover

Endpoint Exfiltration Prevention

Cover

Exfiltration for Salesforce

Cover

App Intelligence

Cover

Forensic Search

Cover

AI Agent Security

Configuring Google Drive Policies

Exfiltration policies allow you to monitor download events across your Google Drive environment. Through real-time download monitoring, you can identify insider risk and anomalous behaviour before it escalates to large scale security incidents. You can monitor download activity for specific users or user groups, specific drives containing valuable sensitive assets, or downloads of any files containing sensitive data types as discovered and classified by Nightfall's ML/AI based detectors.

You can set up your policies to monitor only, to educate users in real-time about your download and data governance policies, or to automatically suspend user access to the Google Workspace to enforce zero tolerance policies.

The detailed steps to configure the Google Drive Exfiltration policy is explained in the following documents.

Google Drive App Selection

Trigger

Automated Actions

Creating Policy

Remediation for Google Drive Exfiltration

MAC/Windows App Selection

In this stage, you select the Integration for which the policy is created. In this case, Google Drive integration must be selected.

  1. Click Policies from the left menu.

  2. Click + New Policy.

  3. Select Exfiltration.

  4. Select Endpoint.

Cloud Sync App Uploads

In this option, you can either choose to monitor uploads done to every cloud sync app or select specific cloud sync apps to which the uploads must be monitored.

  1. Select the Cloud Syncing option.

  2. Select one of the following options.

  • Any Storage Apps: If you select this option, Nightfall monitors the uploads done to every cloud sync storage application.

  • Specific Storage App(s): If you select this option, you must additionally select the storage apps. Nightfall monitors the uploads done to the selected storage apps.

Once you select a cloud storage application from the drop-down menu, the selected option is displayed on the screen and grayed out from the drop-down menu. You can use the drop-down menu to select additional cloud storage apps.

Printer Support

Intercepts documents sent to the print queue before they reach a physical or virtual printer. Nightfall evaluates the document at the OS print subsystem level (CUPS on macOS).

Domain collections are not used for this trigger. Monitoring scope is configured by printer selection directly on the policy.

Platform note: Printer monitoring is supported on macOS only. Windows support is not yet available.

Scope options

  • All printers connected to the endpoint.

  • Specific printers by name or type

Common use cases

  • Prevent printing of customer records, payroll data, or legal documents on unmanaged or shared printers.

  • Block printing to fax-to-email or cloud print services running on the endpoint.

Policy recommendations

  • Always include virtual printers in scope.

  • Scope block actions to all printers except approved print server destinations in environments with dedicated secure print rooms.

  • Deploy alongside Removable Media policies for full physical exfiltration coverage.

  • Note: Native "Save to PDF" or "Print to PDF" bypasses the print monitoring and blocking capability. However, if the PDF is subsequently exfiltrated, Nightfall does monitor and block this.

Advanced Settings

Learn about the advanced setting options present in the Nightfall exfiltration policy for MAC devices.

The advanced settings pages allows you to configure notifications for Nightfall admins and end-users. Additionally, you can also configure automated actions. The various configurations available in the advanced settings pages are described in the following sections.

  • Admin Alerting

  • Automated Actions

  • End-User Notifications

Creating Policy

In this final stage, you assign a name to the policy, verify your configurations, and create the policy.

  1. Enter a name for the policy.

  2. (Optional) Enter a description for the policy.

  3. Click Next.

  4. Verify if all the policy configurations are set up as per your requirements.

  5. (Optional) Click back or click on any specific stage to modify any of the policy configurations.

  6. Click Submit.

Google Drive App Selection

In this stage, you select the Integration for which the policy is created. In this case, Google Drive integration must be selected.

  1. Click Policies from the left menu.

  1. Click + New Policy.

  1. Select Exfiltration.

  1. Select the Google Drive integration.

Creating Policy

In this final stage, you assign a name to the policy, verify your configurations, and create the policy.

  1. Enter a name for the policy.

  2. (Optional) Enter a description for the policy.

  3. Click Next.

  1. Verify if all the policy configurations are set up as per your requirements.

  2. (Optional) Click back or click on any specific stage to modify any of the policy configurations.

  3. Click Submit.

Endpoint Exfiltration Prevention

Nightfall supports exfiltration prevention in endpoint devices. The exfiltration prevention in endpoint devices prevents your organization's employees from exfiltrating data out of your organization. This feature is available for devices running on the macOS and Windows OS.

To monitor each device for exfiltration, you must first install the Nightfall agent on the devices that require monitoring. You can install the Nightfall agent either manually on each device. Alternatively, you can also use an MDM to install the agent. Once you install the Nightfall agent, you must create policies to start the monitoring. Nightfall monitors the devices as per the policy rules set.

You can learn about how to install the Nightfall AI agent for macOS/Windows OS and the process to create policies from the following links.

  • Install Nightfall AI Agent for Mac

Additional Methods to Install Nightfall AI Extension

This explains the other methods of deployment available for the Nightfall AI extension, separate from the Nightfall AI Agent.

The Nightfall AI extension is commonly installed using MDM in one of two ways:

  • macOS: Deployed with the Nightfall profile

  • Windows: Deployed with the MSI

Some, however, utilize other methods of deployment. This section provides options available for those specific use-cases.

Browser Uploads

Ensure that you have configured domain collections before using the browser uploads option.

To monitor browser uploads:

  1. Select the Browser uploads to option.

  1. Select one of the following options.

  • Any Domain: If you select this option, Nightfall monitors your uploads done to any domain on the Internet.

  • Domain in: If you select this option, you must additionally also select the domain collections created in the section. Nightfall monitors the uploads done to all the domains that belong to the selected domain collections.

Once you select a domain collection, it is displayed on the screen and greyed out from the drop-down menu. You can use the drop-down menu to select additional domain collections.

  • Domain Not in: If you select this option, you must additionally also select the domain collections created in the section. Nightfall does not monitor the uploads done to all the domains that belong to the selected domain collections.

Once you select a domain collection from the drop-down menu, it is displayed on the screen and grayed out from the drop-down menu. You can use the drop-down menu to select additional domain collections.

Admin Alerting

Learn how to configure admin alerts in Nightfall exfiltration policies.

This stage allows you to select the notifications channels. If Nightfall detects sensitive data in any of the selected upload channels, the notifications are sent to the recipients configured in this section.

Admin Alerting

This section allows you to send notifications to Nightfall users. The various alert methods are as follows. You must first turn on the toggle switch to use an alert method.

The alert configurations configured in this section describe the process of creating alerts at the policy level. Policy-level alerts apply only to the policy on which they are configured. To configure an alert on all the mac/Windows OS Exfiltration policies, you must configure alerts at the integration level. To learn more about how to configure integration-level alerts, read .

The steps to configure alert channels for policy-level integration are the same as in the case of integration-level alerts. You can refer to this document for steps.

Configuring Salesforce Exfiltration Policies

Exfiltration policies allow you to monitor download events across your Salesforce environment. Through real-time download monitoring, you can identify insider risk and anomalous behaviour before it escalates to large scale security incidents. The following are supported and monitored by Nightfall for exfiltration activities,

  • Attachments & Files

  • Reports

  • Records & Objects

Download of any of the above information containers is an exfiltration activity for Nightfall, and if such activities breach a threshold set in one of the exfiltration policies in Nightfall, then Nightfall will flag it an exfiltration event. You can configure which users should receive notifications and what automatic actions must be taken when an exfiltration event is detected.

The detailed steps to configure the Salesforce Exfiltration policy is explained in the following documents.

Salesforce App Selection

In this stage, you select the Integration for which the policy is created. In this case, Salesforce integration must be selected.

  1. Click Policies from the left menu.

  1. Click + New Policy.

  1. Select Exfiltration.

  1. Select the Salesforce integration.

Nyx – AI-powered DLP Copilot

Learn about Nyx. Nightfall's AI-powered Copilot.

Nyx is Nightfall’s AI-powered DLP Copilot, designed to help you quickly investigate and understand exfiltration risks. She can surface patterns, summarize user activity, and suggest next steps — all through a simple natural-language conversation.

  1. Click the Comet Icon: In the upper right corner of your Nightfall dashboard, click the comet icon to open Nyx.

  2. Start Conversing: Type your question in plain English — no special syntax required.

Trigger

The trigger section further enhances the unwanted noise reduction capabilities. With the trigger section, you can

  • Set what download behavior can be termed as an exfiltration event.

  • Exclude downloads by trusted apps from being termed as exfiltration events.

In the trigger section, you can set the download behavior, the download frequency to be precise, must be termed as an exfiltration event.

To configure the Trigger section:

Manually Install the Nightfall Safari Extension

  • Mac with the Nightfall endpoint agent already installed

  • Permission to install apps from the Mac App Store

1. Install from the Mac App Store. Open this link (the app is not searchable by name in the App Store):

Click through to the Mac App Store and install Nightfall DLP for Browsers.

2. Open Safari extension settings

Nightfall macOS Agent Deployment: PDQ SimpleMDM

Below is a step-by-step guide to deploy the Nightfall Endpoint DLP agent for macOS using PDQ's SimpleMDM.

  1. Enroll devices in PDQ SimpleMDM

  2. Create a Device Group with the respective macOS machines assigned to it

  3. Download and unpack Nightfall's install package from the console:

Install Nightfall AI Agent for Windows OS

Nightfall for Windows OS allows you to detect exfiltration events on your Windows OS devices. The Nightfall exfiltration feature can monitor any files being uploaded through supported cloud storage apps or browsers on Windows OS devices.

To use Nightfall for macOS, you must install the Nightfall AI agent. This agent monitors your Windows OS device continuously. You can install the agent either manually or through a Mobile device management (MDM) tool. You can request the Nightfall deployment bundle which contains the data required for your MDM deployment.

Nightfall supports the following agent installation methods for Windows:

Nightfall Windows Agent Deployment: Rippling MDM

Learn how to install the Nightfall agent on Microsoft Windows OS using the Rippling MDM.

  1. You have the Device Administrator role in Rippling.

  2. Target Windows devices have been onboarded into Rippling MDM.

  3. On your Nightfall console, navigate to and click the Download Package button on the top right corner of the page. Click Download Package for Windows. A

Nightfall Windows Agent Deployment: Workspace ONE UEM

Below is a step-by-step guide to deploy the Nightfall Endpoint DLP agent for Windows using Workspace ONE UEM.

  1. Confirm that the Windows devices are enrolled and managed through Workspace ONE.

  2. Confirm that a device group has been set up for deployment.

    • From UEM, navigate to Groups & Settings > Groups > Assignment Groups > click "+ Add Smart Group" and follow the prompts

Clipboard Paste

In this option, you can choose to monitor the copy/paste actions performed by end-users. If end-users copy some data and paste it to unsanctioned locations.

Apart from text data, Nightfall can also detect non-text clipboard content, including images and screenshots. Clipboard Paste trigger uses the optical character recognition (OCR) technology in combination with Nightfall to prevent the exfiltration of sensitive data present in visuals like copied screenshots, scanned documents, or copied images from web browsers.

Use cases

  • A typical example of this trigger can be a scenario in which an end-user copies an API key and pastes it in a prompt in ChatGPT/Deepseek or any other Gen AI apps while attempting to generate a piece of code.

  • An employee attempting to capture a screenshot of dashboards, reports, or customer data from sensitive SaaS apps into unsanctioned destinations.

Uploads, Paste to Desktop Apps

Intercepts data movement - file transfers, uploads, and paste events - within desktop applications. Nightfall monitors at the application layer, capturing events before they reach the network.

Supported applications

Category
Applications

End-User Notifications

Learn how to configure end user notifications in Nightfall exfiltration policies.

This section allows you to configure notifications to be sent to the end user whose actions triggered the violation.

Enter a custom message to be sent to the end user. This message is sent in an Email or a Slack message. You can modify the default message provided by Nightfall and draft your own. The total character length allowed is 1000 characters. You can also add hyperlinks in the custom message. The syntax is <link | text >. For example, to hyperlink https://www.nightfall.ai with the text Nightfall website, you must write < | Nightfall website>.

You can either select Email, Slack, or both as an automated notification method. You must turn the toggle switch to use this option. Based on the options selected, end-users receive notifications in their Email or Slack, based on the option(s) enabled.

End-User Remediation (also known as Human Firewall) allows you to configure remediation measures that end-users can take when an exfiltration event is triggered due to their actions. You must turn on the toggle switch to use this option. When you configure end-user remediation, the user whose actions triggered the exfiltration event receives a notification from Nightfall. This notification provides details of the user's actions that caused the exfiltration along with your custom message. End-users can take appropriate actions.

Nightfall supports the following remediation actions for end-users.

Nightfall Exfiltration for Salesforce

Nightfall Exfiltration for Salesforce helps you to keep tab of the exfiltration activities in your Salesforce orgs. Nightfall leverages Salesforce Shield Real Time Event Monitoring for exfiltration activities across your Salesforce orgs and identifies activities which are in violation to configured policies.

Download of attachments, files, reports and bulk download of objects are all exfiltration event recognised by Nightfall. You can configure policies to set appropriate thresholds for such events and identify them as unwarranted that may require scrutiny. You may configure the policy to alert the stakeholders who need to be notified and choose one of the available actions to be invoked automatically. You may also choose not to configure automated actions but only act after evaluating the specific exfiltration events.

Nightfall exfiltration leverages Salesforce Shield's Event Monitoring to identify exfiltration events. Salesforce Shield provides multiple security tools to safeguard your Salesforce orgs. Nightfall depends on in Salesforce Shield which is available as an independent module within . You must enable the following Event Monitoring settings for all the Salesforce orgs that you wish to monitor,

  • Generate event log files - Generate an event log file when events occur in your org.

Install Nightfall AI Agent for Windows OS
Configuring Policies
Install Nightfall AI Extension via Google Workspace Admin
Install Nightfall AI Extension via a Common MDM Profile
Manually Install Nightfall AI Extension for Safari
Salesforce App Selection
Scope
Trigger
Advanced Settings
Creating Policy
Remediation for Salesforce Exfiltration
this document

Nightfall Windows Agent Deployment: Microsoft Intune

  • Nightfall Windows Agent Deployment: MSI

  • Nightfall Windows Agent Deployment: Rippling MDM

  • Nightfall Windows Agent Deployment: Workspace ONE UEM

  • Nightfall Windows Agent Deployment: SCCM

  • At this time the Nightfall AI Endpoint Agent does not support the ARM processor architecture. However, ARM compatibility is being prioritized in a future release.

    If you manage Chrome extensions via Google Workspace Admin Console

    See these steps first. Otherwise, the Nightfall extension may not connect properly.

    Not sure if this applies to you? If your IT team uses Google Workspace (Google Admin Console) to manage which Chrome extensions are force-installed on employee machines, this applies to you.

    Manual Installation
    Nightfall Windows Agent Deployment: JumpCloud MDM

    Setup & Installation

    Prerequisites

    Both of the following must be in place before AI Agent Security can function:

    1. Nightfall endpoint agent v1.2.12.11+ installed and running on the endpoint. The hooks call the binary by name, so without the agent the hooks resolve to nothing.

    2. MDM configuration profile v3+ deployed via your MDM provider (Jamf, Mosyle, Kandji, etc.)

    3. MDM scope selected - the device group / Blueprint / Smart Group / assignment that will receive the deployment.

    4. Claude Code is reasonably current on managed devices.

    5. You have the three pieces from this package: the payload (payloads/nightfall-hooks.json) and the scripts for your platform (scripts/macos/ or scripts/windows/).

    If the MDM profile has not been deployed, the agent will show a missing permissions error and you will not see any local or remote MCP servers across installed devices.

    domain collections
    domain collections

    If the event monitoring module is not setup in Salesforce, event monitoring is displayed as "disabled" on the Scope page as shown in the following image.

    “What are my most common exfiltration patterns?”

  • “Summarize Bob’s activity over the last 7 days.”

  • “What are my most frequent upload domains? Put results in a table.”

  • "Write an email to Bob's supervisor for me."

    • Nyx can process up to 100 exfiltration events at a time.

    • Available for endpoint customers only. Support for other event types coming soon.

    Your feedback will directly shape Nyx’s future! After trying her out, let us know what works well and what could be improved.

    • Inside the making of Nyx, our AI Copilot

    • Get a Nyx demo

    Getting Started

    Things You Can Ask Nyx

    Beta Limitations

    Give Us Feedback

    Learn More

    Open Safari

  • Menu bar: Safari > Safari Extensions...

  • Or: Safari > Settings > Extensions

  • 3. Enable the extension

    • Select Nightfall DLP for Browsers in the sidebar

    • Check the box to enable it

    • Approve any macOS authorization prompt

    4. Set permissions

    • Turn on Allow in Private Browsing

    • Click Always Allow on Every Website...

    • In the confirmation dialog, click Always Allow on Every Website

    • Extension is enabled under Safari > Settings > Extensions

    • Private browsing and “every website” permissions are granted

    • Device shows online in the Nightfall console under Endpoint

    Prerequisites

    Steps

    https://apps.apple.com/us/app/nightfall-dlp-for-browsers/id6751912217

    Verify

    Outlook, Apple Mail

    AI assistants

    ChatGPT, Claude, Microsoft Copilot

    Scope options

    • All supported applications.

    • Specific applications selected from the list above.

    Event types monitored

    • File attachments and transfers

    • Uploads within app interfaces

    • Paste events into app input fields

    Domain collections are not used for this trigger. There is no session detection for desktop app events - monitoring applies to all account types within the monitored application.

    Messaging

    Slack, WhatsApp, iMessage, Signal, Telegram, Discord, Microsoft Teams

    Email

    macOS + Windows (both): Slack, WhatsApp, Signal, Telegram, Discord, Outlook, Microsoft Teams, ChatGPT, Claude, Microsoft Copilot

    macOS only: iMessage, Apple Mail

  • Enable Lightning Logger Events - Enable collection of Lightning Logger Events in custom components.

  • Enable the following events for storage and streaming

    • Bulk API Result Event - Track when a user downloads the results of a Bulk API request

    • File Event - Track file activity. For example, track when a user downloads or previews a file

    • Report Event - Track when a user accesses or exports data with reports

    • SessionHijacking Event - Track when an unauthorised user gains ownership of a Salesforce user’s session with a stolen session identifier

  • You can learn more about Salesforce Shield here and once enabled, advance to the next steps with Installing Nightfall DLP for Salesforce

    If you have already onboarded your Salesforce org to Nightfall platform, please ensure you have the latest Nightfall DLP package deployed in your Salesforce org. Follow the steps mentioned in Upgrading Nightfall DLP to upgrade it to the latest version.

    The installation procedure remains the same as in case of Salesforce DLP for sensitive data. The links to the installation and upgradation documents are as follows.

    • Installing Nightfall DLP for Salesforce

    • Upgrading Nightfall DLP for Salesforce

    Prerequisites

    Event Monitoring
    Salesforce Shield

    You must perform the above actions only on those Salesforce orgs in which the Salesforce Shield Event monitoring module is enabled.

    Installation Doc Links

    Set the minimum number of downloads threshold that must be considered as an exfiltration event.

  • Set the required time period (frequency). If the minimum download threshold (set in the previous step) is reached or exceeded, within the set time period, an exfiltration event is generated.

  • In the following image, the configurations are set such that if an asset is downloaded 2 or more times within 10 minutes, an exfiltration event is triggered.

    Depending on your environment, a significant number of downloads may be attributed to applications (i.e. backup apps). You may choose to ignore such download events to reduce the noise and focus your monitoring on unexpected application and user download events.

    The Exclude apps section allows you to exclude specific applications from being monitored by your policy.

    To configure the Exclude apps section, select the applications to exclude from the drop-down menu. Once saved, Nightfall will not alert on download events attributed to the excluded applications.

    Configuring Trigger Section

    You must set the action frequency carefully. For example, consider that you set the download condition as 5 or more files, within 1 hour. In this case, if a user downloads four assets, every 1 hour, the policy does not trigger a violation, since the condition is not met.

    Exclude Apps

    Integrations > Manage (Endpoint Windows) > Download Package > click "Download Package"

    1. From within SimpleMDM, navigate to Scripts > click “Scripts” > click “Create Script”

    2. Name: Nightfall Pre-Installation Script

    3. Click “Choose File”

      1. Select the “mdm_pre_installation_script.sh” from the mdm_scripts folder that was downloaded from the Nightfall Console.

    4. Create a job.

      1. Navigate to Scripts > click “Job” > click “Create Job”

      2. Name: Deploy Nightfall Pre-Install Script

      3. Script: Select the “Nightfall Pre-Installation Script”

    1. Navigate to Configs > click “Profiles” > click “Create Profile”

    2. Select “Custom Configuration Profile”

      1. Name: Nightfall Profile

      2. Uncheck “Install via Declarative Management”

        In testing there were issues with profile deployment unless this was unchecked.

      3. Mobileconfig: Click “Choose File”

      4. From the mac_bundle folder, navigate to “profiles” > select “NightfallAI_Profile_with_Browser_Extensions.mobileconfig”

      5. OS: Only select “macOS”

      6. Navigate to the “Groups” tab

      7. Click “Assign Group”

      8. Select the group > click “Assign”

    3. Navigate back to “Profile” tab > click “Save”

    1. Navigate to Apps & Media > click “Catalog” > click “Add App” > select “Custom App”

    2. From the mac_bundle folder, locate the “nightfall-ai-agent-signed.pkg” > click “Open”

    3. Click the “Groups” tab > click “Assign Groups”

      • Install Method: MDM

      • Install Type: Auto

      • Groups: (select group)

    4. Click “Assign”

    5. Click “Done”

    Pre-Requisites

    PDQ SimpleMDM does not have the ability to run a job to deploy in a specific order. Due to this, follow the steps below explicitly so as to make sure the agent has the appropriate permissions during install.

    Step 1: Deploy the Script

    Step 2: Deploy the Profile

    Step 3: Deploy the Agent

    .msi
    extension file is downloaded.
    1

    Create and Configure the Software Package in Rippling

    1. Navigate to: https://app.rippling.com/hardware/software

    2. Click Upload Software on the right of the pane and provide the following details.

      1. Name: “Nightfall Endpoint DLP Agent <version>”

        • <version> is the version of the package your received from Nightfall.

      2. Operating System: “Windows”

      3. Category: “My Uploads” (Default)

      4. Description: “Nightfall Endpoint DLP Agent”.

      5. Upload Icon: use the .png icon file provided.

      6. Upload Installer File: Drop or select the downloaded NightfallAgent.msi file.

      7. Under Silent arguments add /qn /norestart API_KEY="" COMPANY_ID="" INSTALL_NF_DRIVER="1" where the content of API_KEY and COMPANY_ID are the values provided to you by Nightfall. Note that these values must be enclosed in " double quote characters.

      8. Click Submit.

      9. You will receive an email from Rippling with the subject: “Your recently uploaded custom software is processing”

      10. After a period of time (typically less than 1 hour) You will receive an email from Rippling: “Your recently uploaded custom software has been processed successfully!”

      11. You may now proceed to step 2. to deploy the agent.

    2
    1. Click Add on the newly created Software Item in the Rippling Software Catalog.

    2. Click Finished Selecting.

    3. Search or scroll to the newly added item matching the name you used in the previous step.

    Prerequisites

    https://app.nightfall.ai/endpoint

    1. Configure and Deploy Software Package

    Download "NightfallAgent.msi" from the Nightfall console:

    1. Log into Nightfall > Integrations > Manage (Endpoint Windows) > click "Download Package" > click "Download Package for Windows"

    2. Unpack the file.

  • Additionally, take note of the install command for Windows machines. This will need to be copied later.

  • This step deploys both the agent and the extension via the same MSI file.

    1. Log into Workspace ONE UEM

    2. Navigate to Resources > Native Apps > click "Add" > select "Application File"

    3. Click "Upload" > click "Choose File" > select "NightfallAgent.msi" > click "Save"

    4. Click "Continue"

    5. Under Details tab > Supported Processor Architecture > Select "64-bit"

    6. Navigate to the Deployment Options tab > Locate "Install Command"

    7. Paste the command from the Nightfall console into "Install Command".

    8. Click "Save & Assign"

    9. Set a Name for the Distribution.

    10. Choose an Assignment Group. NOTE: Use the group that was created from the Prerequisites section.

    11. Decide if the App Delivery Method should be Auto or On Demand. For a manual trigger use On Demand.

    12. Click "Create" > click "Save" > click "Publish"

    Pre-Requisites

    Workspace ONE Deployment Video (Windows Agent)

    Deploy Nightfall Agent and Extension

    To enable the Clipboard Paste trigger:

    1. Select the Paste To option.

    2. Select one of the following options.

      1. Any Domain: If you select this option, Nightfall monitors your paste actions performed on any domain on the Internet.

      2. Domain in: If you select this option, you must additionally also select the domain collections created in the section. Nightfall monitors the uploads done to all the domains that belong to the selected domain collections. The process of domain selection remains the same as demonstrated in the case of the section.

      3. Domain Not in: If you select this option, you must additionally also select the domain collections created in the section. Nightfall does not monitor the uploads done to all the domains that belong to the selected domain collections.

    Once you select a domain collection from the drop-down menu, it is displayed on the screen and grayed out from the drop-down menu. You can use the drop-down menu to select additional domain collections.

    detectors

    If end-users attempt to paste content, once you enable the Clipboard Paste trigger, they receive an error message as shown in the following image.

    Provide Business Justification: This option allows end-users to add a descriptive note on the file transfer or exfiltration event. Basically, users can provide a business justification giving you more context into the file transfer or a business justification. The user input is delivered directly to the console for review, saving you time and helping you assess the risk of the data transfer based on the additional user input.

    When an end-user decides to provide a business justification, the following screen is displayed.

    Based on the user response, the Exfiltration Event is updated.

    The other options available to be configured in this section are:

    • When a Violation is Reported as False Positive (justified): You can use this option to set actions to be taken when input has been provided by the end-user. You can automatically ignore violations for which the user has provided input.

    • Remind Every (until Violation expires): You can use this option to adjust the frequency at which Nightfall should remind the user to provide context into their data transfer. You can choose to remind the end user every 24, 48, or 72 hours.

    Custom Message

    Automation

    End-User Remediation

    https://www.nightfall.ai

    Automated Actions

    This stage allows you to select automated notification channels or actions if a policy violation occurs.

    Admin Alerting

    This section allows you to send notifications to Nightfall users. The various alert methods are as follows. You must first turn on the toggle switch to use an alert method.

    The alert configurations configured in this section describe the process of creating alerts at the policy level. Policy-level alerts apply only to the policy on which they are configured. To configure an alert on all the Google Drive Exfiltration policies, you must configure alerts at the integration level. To learn more about how to configure integration-level alerts for the Google Drive integration, read .

    The steps to configure alert channels for policy-level integration are the same as in the case of integration-level alerts. You can refer to this document for steps.

    Automated Actions

    Automated actions allow you to configure automated remediation actions when an exfiltration attempt is detected by Nightfall policy. Nightfall supports the following automated actions for Google Drive. You can choose to implement the automated action immediately after detecting a download attempt or after some time.

    Suspend Account: This action suspends the user's account who tried to download files and triggered the exfiltration event.

    To enable the automated action, you must turn on the respective toggle switch.

    You must now select when exactly after detecting the event, the action must be triggered. if you select the Immediately option, the automated action is triggered immediately after the download attempt is made.

    If you select the After option, you must select the time gap after which the automated action must be implemented.

    This section allows you to configure notifications to be sent to the end user whose actions triggered the violation.

    Enter a custom message to be sent to the end user. This message is sent in an Email. You can modify the default message provided by Nightfall and draft your message. The total character length allowed is 1000 characters. You can also add hyperlinks in the custom message. The syntax is <link | text >. For example, to hyperlink with the text Nightfall website, you must write <www.nightfall.ai|Nightfall website>.

    The automation settings allow you to send notifications to end users. You can select one or both the notification methods. You must first turn on the toggle switch to use the automation option. The automation notification channels are as follows

    • Email: This option sends an Email to the user who attempted the download.

    • Slack: This option sends a Slack message to the user who attempted the download.

    End-user remediation (also known as Human Firewall) allows you to configure remediation measures that end users can take, when a violation is detected on by their download attempt. You must turn on the toggle switch to use this option. End-users receive the remediation actions in an Email as an action item. The various available remediation actions for end-users are as follows.

    • Report as False Positive with Business Justification: This option allows end users to report false positive alerts and provide a business justification as to why the alert is considered to be false positive.

    When end-users report alerts as false positive, you can choose the resolution method to be either Automatic or manual.

    If end-users do not take any remediation action, you can set the frequency at which they must receive the notifications to take action.

    Install Nightfall AI Agent for Mac

    Nightfall for macOS allows you to detect exfiltration events on your macOS devices. The Nightfall exfiltration feature can monitor any files being uploaded through supported cloud storage apps or browsers on macOS devices.

    To use Nightfall on macOS, you’ll need to install the Nightfall AI agent. You can install it manually for testing or evaluation purposes, or automate the install through MDM.

    Apple requires the use of MDM profiles for applications like Nightfall AI to obtain the necessary permissions to function properly. While you can grant these permissions manually, there is no supported or scriptable alternative to an MDM solution for seamless, unattended deployment at scale.

    If managing Chrome extensions via Google Workspace Admin Console

    See these first. Otherwise, the Nightfall extension may not connect properly.

    Not sure if this applies to you? If your IT team uses Google Workspace (Google Admin Console) to manage which Chrome extensions are force-installed on employee machines, this applies to you.

    Nightfall supports the following agent installation methods for macOS:

    • Manual Installation

    • Nightfall macOS Agent Deployment: JAMF MDM

    You can install the Nightfall AI macOS agent in stealth/hidden mode. Installing the agent in stealth mode allows you to hide visible UI elements once the Nightfall agent is installed. When you install the agent in silent mode, the Nightfall status bar icon. Additionally, the Nightfall application will not be visible in the Applications folder when viewed in Finder.

    • Covert Monitoring: If an organization suspects an employee of exfiltrating sensitive data, they can install the agent in stealth mode to monitor the employee's asset without the employee's knowledge.

    • Ensuring Bias-Free Compliance: An organization wishes to confirm if their employees are adhering to HIPAA/PCI compliances; they can install the agent in stealth mode without giving any indication to their employees (which can prompt a change in their behavior).

    • Prevent User Distractions: Organizations that do not wish to distract their users about the agent presence and monitoring can depoy in stealth mode.

    1. In the mdm_pre_installation_script.shfile, find the hide_status_iconflag.

    2. Set the flag to true. By default, the flag is set to false⁣.

    Nightfall employs the automatic endpoint update functionality. With this feature, Nightfall can deliver the majority of endpoint agent bug fixes and feature updates directly to endpoints.

    Features:

    • Stay Secure: Receive the latest security patches and updates promptly, reducing the risk of vulnerabilities being exploited.

    • Remain Compatible: Keep your deployment compatible with the latest operating system updates and other software changes.

    • Receive New Features: You get access to new features and improvements to exfiltration monitoring without manual intervention.

    Manual Installation

    Learn how to install the Nightfall agent on Microsoft Windows OS manually.

    Overview

    This document outlines the steps to manually deploy the Nightfall AI Agent on a Windows device.

    Prerequisites

    • Ensure that Windows endpoint has been enabled on your Nightfall tenant.

      • Download the Nightfall AI Agent NightfallAgent.msi file from Nightfall.

        • Download NightfallAgent.msi from to a local folder on the target machine

          • Integrations -> Endpoint Windows -> Manage -> Download Package -> Download Package For Windows

    • Navigate to > Exfiltration > Endpoint - (optional)

    1. Copy downloaded NightfallAgent.msi to a folder on a target machine.

    2. Run the Installer:

      1. Launch CMD as an Administrator

    b. Navigate to the folder where NightfallAgent.msi is downloaded to.

    i. cd C:\\users\\<username>\\Downloads\\ update the above accordingly.

    c. Copy the installation command from .

    i. Note : this includes the necessary command line parameters for the agent to communicate with Nightfall

    ii. Integrations -> Endpoint Windows -> Manage -> Download Package -> 'To install, run the command as admin.

    d. Paste the msiexec installation command copied from the above step to cmd and press Enter key.

    e. Installation should start in silent mode.

    1. Verify Installation

      1. Once installation is complete, check if the agent is running:

        1. Open Task Manager (Ctrl + Shift + Esc).

    b. Confirm the Nightfall agent is configured to your Nightfall tenant

    i. On the windows machine:

    1. Double-click the Nightfall agent icon in the status bar.

    2. The displayed UUID should match your Nightfall tenant UUID located under

    ii. On the Nightfall console:

    1. The newly configured device should be listed under

    The Nightfall AI Agent should now be successfully installed, running on your Windows machine, and connected to your Nightfall tenant. If you run into any issues, please contact Nightfall AI support.

    Trigger

    A trigger defines the exfiltration medium - the specific channel or application through which data moves off a managed device. Each trigger represents a distinct interception point: a file upload in a browser, a sync client writing to disk, a document sent to the print queue, a file sent with AirDrop. Nightfall intercepts the event at that point, inspects the content against your detection rules if applicable, and applies the configured action.

    You configure one trigger per policy. Each trigger is independently scoped - a browser upload policy and a thick app policy can cover the same domains without conflicting.

    Domain Collections

    A domain collection is a named, reusable set of domains used to scope trigger monitoring. Collections appear in two roles:

    • Source collection - identifies domains associated with corporate account sessions or originating domains. Used to answer: did this data originate from a corporate account? Example: your company's Google Workspace domain (yourcompany.com on Google Drive).

    • Destination collection - identifies domains associated with personal account sessions or destination domains. Used to answer: did this data go to a personal account? Example: gmail.com, dropbox.com, chatgpt.com accessed with a personal login.

    Collections are created and managed separately from policies, then referenced when configuring data lineage and session detection on the Browser Upload and Clipboard Paste triggers. Not all domains in a collection support session detection - the policy UI shows coverage at configuration time (e.g., "3 of 12 domains across 2 collections support session detection"). Domains without session detection support are always monitored for all account types regardless of which collection they belong to.

    You do not need to configure collections for Cloud Syncing, Removable Media, Printer, Thick App (desktop app), Git Push, CLI Transfer, AirDrop, or Bluetooth. Those triggers use application lists, tool lists, or no destination list.


    Once you zero in on the policy to the required devices and originating domains, you must now define the trigger actions that can be termed as exfiltration events. Nightfall provides you with multiple types of triggers that you can set as exfiltration events.

    Browser Uploads: If an asset is uploaded through a web browser or desktop app to any online destination (for example, a file attached to a ChatGPT prompt or uploaded to a personal Google Drive via the browser), you can define such events as file upload exfiltration events.

    Cloud Syncing: If an asset is synced to a cloud storage application running on the endpoint (for example, a file written to a local Dropbox or OneDrive folder and automatically uploaded to the cloud), you can define such events as cloud sync exfiltration events.

    Clipboard Paste: If data is copied from a source application and pasted into an external destination (for example, customer records copied from an internal tool and pasted into a personal email), you can define such events as clipboard paste exfiltration events.

    Git Push: If source code is pushed from a managed endpoint to a non-approved remote repository (for example, a developer pushing proprietary code to a personal GitHub account), you can define such events as git push exfiltration events. This feature is designed to prevent accidental or intentional source-code exfiltration. Detection is based on source and destination metadata.

    Removable Media: If an asset is transferred to a removable storage device connected to the endpoint (for example, a file copied to a USB flash drive or an external hard drive), you can define such events as external media transfer exfiltration events.

    Printer: If a document is sent to the print queue on the endpoint (for example, a confidential report printed to a shared office printer or exported as a PDF using a virtual printer), you can define such events as print exfiltration events.

    Desktop App: If data is transferred, uploaded, or pasted within a desktop application (for example, a file attached in WhatsApp or sensitive content pasted into a ChatGPT desktop app), you can define such events as exfiltration events.

    CLI Transfer: If a file is uploaded or downloaded by a selected command-line tool on the endpoint (for example, scp of an export to a home machine, or curl / aws s3 of a secrets file), you can define that as a CLI Transfer exfiltration event. You choose the tools on the policy. This is not Git Push.

    AirDrop: If a file is sent through Apple AirDrop from a managed Mac (for example, a spreadsheet sent to a personal iPhone), you can define that as an AirDrop exfiltration event. There is no recipient picker. Data Source and Data Destination do not apply.

    Bluetooth: If a file is sent over Bluetooth from a managed endpoint (for example, a document sent to a personal phone), you can define that as a Bluetooth file-transfer exfiltration event. This is not pairing or audio. Nearby device details appear on the event, not as policy filters.

    The steps to use the above triggers are elaborated in the following sections.

    Automated Actions

    Learn more about how automated actions work in a Nightfall exfiltration policy.

    This section describes the various actions that Nightfall takes automatically when an exfiltration attempt is detected. This automated action is triggered when the condition set in the section is violated.

    The automated actions supported by Nightfall are described as follows.

    • Block Transfer

    • Record Before & After (Session Replay)

    Block Transfer

    This action automatically blocks the process of file transfer thus preventing an exfiltration attempt. You can use this action to prevent the upload of files with sensitive data, to web browsers or cloud storage apps. You must enable the toggle switch to activate the automated action.

    You can configure the section and the section such that you can leverage this feature to:

    • Block transfer based on file origin: Block the upload of files downloaded from highly sensitive SaaS applications.

    • Block transfer based on destination: Allow uploads only to sanctioned destinations.

    • Combine origin and destination: Create powerful DLP policies that factor in both where files came from and where they are headed.

    Some use cases scenarios in which you can use the automatic Block action, are as follows.

    Employees access confidential reports from an internal data repository and attempt to upload them to personal iCloud or unsanctioned personal email service.

    Solution

    Configure the filters in the section to scope the policy to include domains to be monitored (for instance your organization *.drive.google.com or *.force.com). Now, any file(s) downloaded from the configured domain(s) are monitored. Configure the section to trigger an exfiltration action when an attempt is made to upload the downloaded file to an unsanctioned destination (for instance to personal iCloud or a non corporate sanctioned domain). Finally, enable the Block automated action.

    In this scenario, if a user downloads a file from an organization's Google Drive or Salesforce and attempts to upload it to their personal iCloud, the action is blocked and user gets the following error message.

    Also, other similar scenarios could be

    • A health department which prevents employees from uploading customer health data, downloaded from organization's domain, to employees' personal Google Drive, OneDrive, or any supported cloud storage app.

    • An employee working on code repository of an organization, attempting to upload a file to developer forums, LLM services, or generative AI apps like ChatGPT.

    An organization allows employees to store work documents only in corporate-managed OneDrive or Google Drive but wants to prevent uploads to personal accounts.

    Solution

    Configure the filters in the section to scope the policy to include domains to be monitored (for instance your organization Google Drive or OneDrive). Now, any file(s) downloaded from the configured domain(s) are monitored. Configure the section to monitor only unsanctioned domains. Finally, enable the Block automated action. Now any attempt to upload a file to sanctioned domains is allowed.

    This action captures a session recording before and after an endpoint exfiltration event and stores it in the destination you select. Use it to review what happened around the event.

    To enable recordings, store them in your own bucket, and play them back from an event, see .

    Scope

    The Scope section determines which areas of Nightfall needs to be monitored by Nightfall for Exfiltration. You can choose one or all of the following data types to be monitored.

    • Attachments & Files

    • Reports

    • Records & Objects

    After you make the required selection, you can also add filters to monitor specific Salesforce users or Salesforce profiles.

    If you have connected multiple Salesforce org, the scope page allows you to select one and only one Salesforce org for the policy.

    Nightfall can detect download actions done only from the Salesforce lightning version. Any download action done on the Salesforce Classic version cannot be detected by Nightfall.

    Data Types

    In the Data Types section, you must select the Salesforce data types to be monitored. By default, all the three data types are selected. You can choose to either retain all the three data types or clear any of the data types.

    The Filters section allows you to add additional filters, on top of the selected data types, to narrow down the monitoring scope. Nightfall provides the following two types of filters.

    You can choose specific Salesforce users whose activities need to be monitored or excluded from being monitored. Nightfall populates the list of all your users from Salesforce. You need to select either the users whose activities need to be monitored or the users whose activities need to be excluded from monitoring.

    To add Users filter, click Add Filter and select Internal Users.

    To monitor specific users, select the Monitor specific option. To exclude specific users from being monitored, select the Monitor all, except option.

    Nightfall populates the list of Salesforce users in the Search users field. You can select the all the required users.

    You can choose specific Salesforce profiles whose activities need to be monitored or excluded from being monitored. Nightfall populates the list of all your Salesforce profiles. You need to select either the profiles whose activities need to be monitored or the profiles whose activities need to be excluded from monitoring.

    To monitor specific Salesforce profiles, select the Monitor specific option. To exclude specific Salesforce profiles from being monitored, select the Monitor all, except option.

    Nightfall populates the list of Salesforce profiles in the Search profiles field. You can select the all the required users.

    Contoso Ltd. uses Salesforce to host their applications. They have three users Steve, Rick, and Matt in their Salesforce org. These users are not Contoso employees. They are employees of Acme corp. which is a prospective customer of Contoso Ltd. Steve, Rick, and Matt are evaluating Constoso's app so that they can check if it meets Acme corp's requirements. Contoso has created a Salesforce profile called Prospective customers and added these three users to this profile

    Contoso Ltd. uses Nightfall Salesforce exfiltration and wishes to check if any files with sensitive data is downloaded by any of these three users. They create a Salesforce exfiltration policy to monitor all the data types. They can choose one of the following filter.

    • They can use the filter and add these three users.

    • They can select the filter and add the Prospective customers profile to it. So, in future if any other prospective customers added, they are also automatically monitored.

    Creating Policy

    In this final stage, you assign a name to the policy, verify your configurations, and create the policy.

    1. Enter a name for the policy.

    2. (Optional) Enter a description for the policy.

    3. Click Next.

    1. Verify if all the policy configurations are set up as per your requirements.

    2. (Optional) Click back or click on any specific stage to modify any of the policy configurations.

    3. Click Submit.

    Installing Nightfall for Google Drive

    This document explains the steps to install the Nightfall for Google Drive.

    To install the Nightfall DLP for Google Drive integration, you must have the following:

    • A Google Workspace account, preferably a service account.

    • An admin user account of your organization's Google Workspace account (or any other Google Workspace account) on which you wish to install the integration.

    To install Nightfall for Google Drive:

    Install Nightfall AI Extension via a Common MDM Profile

    This walkthrough adds the Nightfall Profile Chrome ExtensionSettings to an existing custom macOS profile.

    When a company has deployed another profile that controls the Chrome browser ExtensionSettings and it clashes with Nightfall's Profile, the administrator can add the Nightfall ExtensionSettings within the currently present profile to allow the Nightfall extension to connect.

    Simply add this code block to the custom, common MDM profile within the <array> brackets:

    An example of it is found below:

    Nightfall macOS Agent Deployment: Mosyle MDM

    Below is a step-by-step guide to deploy the Nightfall Endpoint DLP agent for macOS using Mosyle MDM.

    Before you begin, ensure you have:

    • Mosyle Business or Mosyle Manager with admin access

    • Nightfall API Key and Company ID - available at app.nightfall.ai/endpoint under Agent Configuration

    Nightfall macOS Agent Deployment: Workspace ONE UEM

    Below is a step-by-step guide to deploy the Nightfall Endpoint agent for macOS using Workspace ONE UEM.

    1. Confirm that the macOS devices are enrolled and managed through your MDM.

    2. Confirm that a device group has been set up for deployment.

      • From UEM, navigate to Groups & Settings > Groups > Assignment Groups > click "+ Add Smart Group" and follow the prompts

    Git Push Monitoring

    Nightfall monitors the following signals during a Git push operation:

    • The endpoint where the push originates

    • The user performing the push

    • The Git protocol (HTTPS / SSH)

    AirDrop

    AirDrop watches files sent through Apple AirDrop on a managed Mac. Nightfall records the transfer as an AirDrop / AirDrop Transfer event and can monitor or block it when the file matches the policy.

    This is a file-transfer trigger. It is not the same as Removable Media (USB) or Bluetooth. The wizard label is AirDrop.

    Domain collections are not used. Data Source and Data Destination are shown as disabled placeholders: Not applicable for AirDrop action. There is no recipient or nearby-device picker. The policy applies to AirDrop file transfers on devices in the policy scope.

    If you do not see AirDrop in the For dropdown, ask your Nightfall account team to enable it.

    What you configure

    Bluetooth

    Bluetooth watches file transfers over Bluetooth on a managed endpoint. Nightfall records the transfer as a Bluetooth / Bluetooth Transfer event and can monitor or block it when the file matches the policy.

    This is not all Bluetooth activity. Pairing, audio, keyboards, and mice are not this trigger. The wizard label is Bluetooth.

    Domain collections are not used. Data Source and Data Destination are disabled placeholders: Not applicable for Bluetooth action. There is no device-type picker on the policy. The policy applies to Bluetooth file transfers on devices in the policy scope. Device type and name show up on the event, not as policy filters.

    If you do not see Bluetooth in the For dropdown, ask your Nightfall account team to enable it.

    What you configure

    Investigating AI Agent Security Incidents

    All AI agent violations appear in the unified Incidents > Exfiltration Prevention view - there is no separate incident queue. This page explains how to identify, review, and respond to AI agent incidents.


    Navigate to Incidents > Exfiltration Prevention. AI agent incidents are identified by the "AI Prompt" event type label in the incident list.

    Trigger

    The Trigger section in Salesforce policies allows you to define the frequency of action that must be considered as an exfiltration event. In case of Salesforce policies, the download frequency is the trigger.

    The download frequency can be defined as the number of downloads over a period to time. This allows you to set custom thresholds in terms of number of downloads over a specific period of time and can be useful to identify anomalous download patterns for specific locations, users or content type. This can be set in combination to other scoping capabilities.

    In the Actions section, you can define the download action that must be considered as a potential exfiltration attempt by Nightfall. Nightfall allows you to set the frequency of downloads as the action.

    To configure Actions:

    1. Click the minimum number of files that must be the download threshold.

    AI Governance

    As employees adopt AI coding assistants like Claude Code, Cursor, and GitHub Copilot, those assistants increasingly reach beyond the editor, connecting to external tools and data sources through the Model Context Protocol (MCP), running shell commands, and reading from your codebase and filesystem. Each of these actions is a potential path for sensitive data to leave your environment, often invisibly to traditional DLP. Nightfall's AI Agent Governance gives security teams visibility into what AI agents are doing and the ability to apply data protection policies to that activity in real time.

    This section covers three surfaces in the Nightfall console under AI Governance:

    • MCP Server Visibility (Inventory, Collections, Users & Devices, Settings): what is already running on endpoints

    Auditability and Control

    Nightfall uses two complementary mechanisms to protect AI agent activity:

    Hooks intercept AI agent actions before they execute. When a developer submits a prompt, calls a tool, or runs a shell command, Nightfall scans the content against your policies and can block the action if a violation is detected.

    • Supported agents: Claude Code, Cursor, VS Code

    • Enforcement: Block or Monitor

    OpenTelemetry (OTel) captures a complete telemetry stream of AI agent activity after actions complete. This provides full session audit trails including cost tracking, model information, and tool activity.

    Run on: Select the Group
  • Run Options: Select “Run ASAP”

  • Click “Create”

  • Removable Media
  • Git Push Monitoring

  • Printer

  • CLI Transfer

  • AirDrop

  • Bluetooth

  • Browser Uploads
    Uploads, Paste to Desktop Apps
    Cloud Sync App Uploads
    Clipboard Paste
    Minimize Administrative Overhead:
    IT administrators don't need to manually deploy updates to each endpoint, saving time and resources.

    Stealth Mode Installation

    Use cases

    Stealth Mode Installation Process

    Stealth mode installation hides the agent only from UI. Employees can find Nightfall if they navigate to the Application folder via Terminal.

    Nightfall Agent Auto Update

    Nightfall macOS Agent Deployment: JumpCloud MDM
    Nightfall macOS Agent Deployment: Iru (Kandji) MDM
    Nightfall macOS Agent Deployment: Mosyle MDM
    Nightfall macOS Agent Deployment: PDQ SimpleMDM
    Nightfall macOS Agent Deployment: Rippling MDM
    Nightfall macOS Agent Deployment: Workspace ONE UEM
    steps
    Look for the Nightfall Agent & NightfallUI processes under the Processes tab.

    Deployment Steps

    Conclusion

    Nightfall portal
    https://app.nightfall.ai/policies/setup
    Nightfall Portal
    https://app.nightfall.ai/settings/
    https://app.nightfall.ai/endpoint

    It is mandatory to select at least one data type for monitoring.

    Filters

    Internal Users

    Salesforce Profiles

    Example Scenario

    Internal Users
    Salesforce Profiles
    domain collections
    domain collections
    Clipboard Paste

    End-User Notification

    Custom Message

    Automation

    End-User Remediation

    www.nightfall.ai
    this document

    When

    Relative time (e.g., "2 hours ago")

    Actor

    Machine name and device ID

    Policy

    Policy name that triggered the violation

    Status

    Active, Blocked, Ignored, Resolved or Acknowledged

    Column

    Content

    Event Label

    Finding AI Agent Incidents

    Incident List Columns

    "AI Agent Hooks" label for Hooks and AI Agent Telemetry for OTEL

    Click Edit

    1. Select all employees or specific target devices.

    2. Click Save.

    Deploy the Nightfall Endpoint DLP Agent

    The Nightfall Endpoint DLP Agent will now deploy to all selected target devices. This may take up to 72 hours and is dependent on the endpoint devices being turned on, connected.

    Download the bundle:
    • Script: mdm_pre_installation_script.sh

    • Profile: NightfallAI_Profile_with_Browser_Extensions.mobileconfig

    • Agent: nightfall-ai-agent-signed.pkg

  • A target device group scoped to the macOS devices you want to monitor

  • (Optional) If the ability to upload a .PKG to Mosyle is not available, make sure the .PKG file is stored/hosted somewhere.


    1. Log in to app.nightfall.ai and navigate to Settings → MDM Profile.

    2. Select Mosyle from the list of supported MDM providers.

    3. Follow the OAuth prompts to grant Nightfall read-only access to your Mosyle device inventory and user identity data. This allows Nightfall to map usernames to devices automatically.


    1. Unpack the zip file provided and locate the mdm_pre_installation_script.sh file in the mdm_scripts folder.

    2. On Mosyle, navigate to Management → Custom Commands.

    3. Paste the content of mdm_pre_installation_script.sh into the script editor.

    4. Target the command to desired devices group

    5. Click Save.

    6. Run immediately.

    1. Unpack the zip file provided and locate the NightfallAI_Profile.mobileconfig file in the Profiles folder.

    2. Navigate to Management → Configuration Profiles.

    3. Click the Upload button and upload NightfallAI_Profile.mobileconfig.

    4. Configure the settings for your configuration profile.

    5. In the Scope tab, add the target devices or device groups to which this profile should be deployed.

    6. Click Save.

    Once assigned, the profile will be automatically deployed to target machines.

    1. On Mosyle, navigate to Management → Install PKG → CDN.

    2. Upload the nightfall-ai-agent-signed.pkg.

    3. This creates a unique CDN reference, e.g.: %MosyleCDNFile:d4d8f767-3f99-4747-8041-253ea90c462d%

    • The Nightfall Agent updates automatically.

    • The Nightfall Profile will need updated from Mosyle if a new one is released.

    • The Nightfall Extension updates automatically.

    1. Unpack the zip file provided and locate the mdm_nightfall_ai_agent_uninstall.sh file in the mdm_scripts folder.

    2. On Mosyle, navigate to Management → Custom Commands.

    3. Paste the content of mdm_nightfall_ai_agent_uninstall.sh into the script editor.

    4. Choose the device scope to deploy the command to.

    5. Click Save.

    6. Run immediately.

    Prerequisites

    Step 1: Connect Mosyle to Nightfall

    Step 2: Deploy the Script

    Step 3: Deploy the Profile

    Step 4: Deploy the Agent (.PKG)

    How to Perform an Upgrade

    How to Uninstall the Agent

    NOTE: The agent requires an uninstall command, but the profile is maintained through the MDM. To remove the profile simply change the scope of devices the profile is deployed to or remove the profile to completely remove it from all of the targeted devices. The extension will remove after closing the browser.

    MCP Gateway: the governed endpoint for servers you enable, with credentials and an audit log
  • Auditability and Control: hooks, OpenTelemetry, and AI agent security policies

  • The Model Context Protocol lets AI assistants connect to external servers that provide tools and data, for example a GitHub server, a database connector, or an internal knowledge base. Because these connections can move data in and out of the assistant, knowing which servers are in use is the foundation of governing them.

    Nightfall automatically discovers and reports MCP activity across your monitored endpoints:

    • Connected servers and clients - Nightfall detects the MCP servers each AI client connects to and surfaces these as connection events in the AI Governance dashboard.

    • Configuration discovery - MCP server configurations are discovered from the agent's settings on the endpoint, including assistants installed through managed channels such as the Microsoft Store.

    • Accurate client attribution - Each event is attributed to the specific assistant that generated it (for example, Claude Code or Claude Desktop).

    Note: Some AI clients label MCP tool activity differently, and a few do not include the server name in the activity they report. Where the server can be identified, you can scope policies to specific servers; where it cannot, that activity is governed under your broader "all servers" policies.

    MCP Gateway is a separate tab next to Inventory. Clients such as Cursor, Claude Code, Windsurf, and VS Code connect to one Nightfall endpoint. Admins enable servers from a catalog or by URL. Users bring their own OAuth or PAT. Every tool call is written to the gateway Audit log.

    The gateway tab is enabled per organization. If you do not see it, contact your Nightfall account team.

    Beyond seeing which servers are connected, Nightfall can inspect and act on what AI agents actually do: the prompts, tool calls, and responses flowing through them.

    • Hooks - lifecycle hooks that fire as the agent works. Nightfall uses them to inspect activity and enforce policy.

    • OpenTelemetry (OTel) - structured agent telemetry that feeds the same dashboards and detection policies you use across Nightfall.

    AI Governance

    MCP Server Visibility

    MCP Gateway

    New capabilities via Hooks and OpenTelemetry

    MCP Server Visibility

    MCP Gateway

    Auditability and Control

    Supported agents: Claude Cowork

  • Enforcement: Monitor only (no real-time blocking)

  • Additional data: Token usage, cost per prompt, model name, API errors


  • Before AI Agent Security can function on your endpoints, ensure the following requirements are met:

    • Version 1.2.12.11 or later is required.

    • The agent must be installed and running on each endpoint where AI agents are used.

    At least one AI Agent Security policy must be active in your Nightfall console. SecOps or IT administrators must install hooks using an MDM script or the IDE console for Cursor, Claude Code or VS Code.


    • Setup & Installation - Verify your deployment and understand how hooks are installed

    • Hooks vs. Open Telemetry - Compare the two enforcement mechanisms

    • Policy management - Step-by-step policy creation guide

    • Policy incidents - How to review and respond to AI agent violations

    • MCP server collections - Discover and manage MCP servers across your fleet

    Hooks - Real-Time Enforcement

    OpenTelemetry - Async Monitoring

    Prerequisites

    Nightfall Endpoint Agent

    MDM Configuration Profile

    Required: You must deploy the Nightfall MDM configuration profile (v3 or later) via your MDM provider (Jamf, Mosyle, Kandji, etc.). This profile grants the necessary system permissions for the Nightfall agent to monitor AI agent activity.

    AI Agent Policy

    Next Steps

    	<dict>
    			<key>ExtensionSettings</key>
    			<dict>
    				<key>jgmgecncmjklkabkejnjfgfkglapfgek</key>
    				<dict>
    					<key>installation_mode</key>
    					<string>force_installed</string>
    					<key>update_url</key>
    					<string>https://clients2.google.com/service/update2/crx</string>
    				</dict>
    			</dict>
    			<key>PayloadDisplayName</key>
    			<string>Google Chrome - Nightfall Extension</string>
    			<key>PayloadIdentifier</key>
    			<string>com.google.Chrome.8370900F-6579-4703-8FEF-1DE3DD384618</string>
    			<key>PayloadType</key>
    			<string>com.google.Chrome</string>
    			<key>PayloadUUID</key>
    			<string>8370900F-6579-4703-8FEF-1DE3DD384618</string>
    			<key>PayloadVersion</key>
    			<integer>1</integer>
    		</dict>
    		<dict>
    			<key>ExtensionSettings</key>
    			<dict>
    				<key>jgmgecncmjklkabkejnjfgfkglapfgek</key>
    				<dict>
    					<key>installation_mode</key>
    					<string>force_installed</string>
    					<key>update_url</key>
    					<string>https://clients2.google.com/service/update2/crx</string>
    				</dict>
    			</dict>
    			<key>PayloadDisplayName</key>
    			<string>Google Chrome Beta - Nightfall Extension</string>
    			<key>PayloadIdentifier</key>
    			<string>com.google.Chrome.beta.A6E44352-4604-4968-8F35-F74BA0FE5C48</string>
    			<key>PayloadType</key>
    			<string>com.google.Chrome.beta</string>
    			<key>PayloadUUID</key>
    			<string>A6E44352-4604-4968-8F35-F74BA0FE5C48</string>
    			<key>PayloadVersion</key>
    			<integer>1</integer>
    		</dict>
    <?xml version="1.0" encoding="UTF-8"?>
    <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
    <plist version="1.0">
    <dict>
    	<key>PayloadContent</key>
        <array>
            ...
            ...
    		<dict>
    			<key>ExtensionSettings</key>
    			<dict>
    				<key>jgmgecncmjklkabkejnjfgfkglapfgek</key>
    				<dict>
    					<key>installation_mode</key>
    					<string>force_installed</string>
    					<key>update_url</key>
    					<string>https://clients2.google.com/service/update2/crx</string>
    				</dict>
    			</dict>
    			<key>PayloadDisplayName</key>
    			<string>Google Chrome - Nightfall Extension</string>
    			<key>PayloadIdentifier</key>
    			<string>com.google.Chrome.8370900F-6579-4703-8FEF-1DE3DD384618</string>
    			<key>PayloadType</key>
    			<string>com.google.Chrome</string>
    			<key>PayloadUUID</key>
    			<string>8370900F-6579-4703-8FEF-1DE3DD384618</string>
    			<key>PayloadVersion</key>
    			<integer>1</integer>
    		</dict>
    		<dict>
    			<key>ExtensionSettings</key>
    			<dict>
    				<key>jgmgecncmjklkabkejnjfgfkglapfgek</key>
    				<dict>
    					<key>installation_mode</key>
    					<string>force_installed</string>
    					<key>update_url</key>
    					<string>https://clients2.google.com/service/update2/crx</string>
    				</dict>
    			</dict>
    			<key>PayloadDisplayName</key>
    			<string>Google Chrome Beta - Nightfall Extension</string>
    			<key>PayloadIdentifier</key>
    			<string>com.google.Chrome.beta.A6E44352-4604-4968-8F35-F74BA0FE5C48</string>
    			<key>PayloadType</key>
    			<string>com.google.Chrome.beta</string>
    			<key>PayloadUUID</key>
    			<string>A6E44352-4604-4968-8F35-F74BA0FE5C48</string>
    			<key>PayloadVersion</key>
    			<integer>1</integer>
    		</dict>
            ...
            ...
        </array>
    </dict>
    </plist>

    Log in to Nightfall.

  • Click Google Drive under the MY INTEGRATIONS section (click Show more if you are unable to view Google Drive)

  • Click Begin Setup. 

  • The access permission page is displayed as follows. Copy the client ID and Scopes ID generated.

    1. Login to your Google Workspace with an admin account.

    2. Click the menu icon.

    3. Select Admin.

    1. In the Admin console left pane, expand Security and then expand Access and data control.

    2. Click API controls.

    1. Click MANAGE DOMAIN WIDE DELEGATION under Domain wide delegation.

    1. Click Add New.

    1. Paste the Client ID copied from the Nightfall app, in the Client ID field.

    2. Paste the Scopes ID copied from the Nightfall app, under OAuth Scope field. Use comma to add multiple scope IDs.

    3. Click AUTHORIZE.

    1. Return to the Nightfall app and click Next Step.

    1. Click Connect.

    Once the installation is completed, you can view the details of your Google Drive in the Nightfall app.

    Requirements

    Installation

    Once the installation is completed, Nightfall connects to your Google Workspace account and fetches all the domains. In the above image, you can see that 3 domains are fetched. These three domains were already present in your Google Workspace and are considered to be internal. You can add additional domains by clicking the ellipsis menu at the right end and selecting Manage Domains.

    Download "mac_bundle.zip" from the Nightfall console:

    1. Log into Nightfall > Integrations > Manage (Endpoint macOS) > click "Download Package" > click "Download Package for macOS"

    2. Unpack the file.

    This step deploys one script - the pre_installation_script. The "pre installation script" ensures the machine is in a clean state for the Nightfall install and wipes any preexisting Nightfall installations.

    1. From UEM, navigate to Resources > Scripting > Scripts > click "Add" > select "macOS"

    2. Add the Nightfall Pre-Installation Script:

      1. Name the script "Nightfall Pre-Installation Script" and add a description.

      2. Confirm the language is "Bash".

      3. Click "Upload" > navigate to "mac_bundle" > "mdm_scripts" > and select the mdm_pre_installation_script.sh > click "Open" > click "Next"

      4. Click "Save".

    3. Assign the Pre-Installation Script to the smart group.

      1. From the Scripts page > select the "Nightfall Pre-Installation Script" > click "Assign"

      2. Click "New Assignment" at the top-left.

      3. Name the assignment and select a smart group. NOTE: This should be the same group as the previous script step.

    This step deploys the mobileconfig profile to push the browser extension and to give permissions to the agent. Always make sure this step takes place before Step 3 - deploying the PKG.

    1. From Workspace ONE UEM, navigate to Resources > Profiles & Baselines > Profiles

    2. Click the "Add" dropdown > select "Upload Profile" > Select platform: "Apple macOS"

    3. Select "Device Profile" (if desired)

    4. Click "Upload" > "Choose File" > navigate to mac_bundle > profiles

    5. Select the mobileconfig entitled, NightfallAI_Profile_with_Browser_Extensions.mobileconfig NOTE: If the "with_browser_extensions" file is not selected it will not deploy the Nightfall extension within the browser and key functionality of Nightfall could be lost.

    6. Click "Save" > click "Continue".

    7. Under "Smart Groups", assign target devices by adding the group previously created from the Prerequisite steps. NOTE: All other settings are optional and depend upon your organization's preference.

    8. Click "Save and Publish"

    9. Review to confirm that the device assignment is correct.

    10. Click "Publish"

    Once published, the profile will be automatically deployed to target machines.

    This step deploys the PKG, which pushes out the agent to the targeted devices.

    1. From UEM, navigate to Resources > Apps > Native Apps

    2. Click "Add" dropdown > select "Application File"

    3. Click "Upload" > tick "Local File" > Click "Choose File" > select nightfall-ai-agent-signed.pkg > click "Open" > click "Save" > click "Continue"

    4. Select the preferred Deployment Type as "Full Software Management"

    5. Download and run the Workspace One Admin Assistant and follow the steps to generate a .plist for the Nightfall PKG.

    6. Click "Upload" > click "Choose File" > navigate to the plist file > click "Open" > click "Save"

    7. Click "Continue" > navigate to the "Images" tab > drag over the Nightfall icon generated

    8. Click "Save & Assign"

    9. Name the Distribution and add a description.

    10. Choose the same "Assignment Group" as in Step 2.

    11. Adjust the "App Delivery Method" accordingly > click "Create"

    12. Click "Save"

    13. Review the devices being deployed to, and if correct click "Publish".

    Nightfall upgrades the agents automatically when the latest version is available from the console. To push a newer version from Workspace One UEM out-of-band simply perform Step 3 again by uploading a new package.

    Pre-Requisites

    The steps below will immediately push to the Assignment Group what is being published at that time. To deploy everything at once and in a specific flow, use the Freestyle Orchestrator feature.

    This guide does not cover the Freestyle Orchestrator Workflow.

    Workspace ONE Deployment Video (macOS Agent)

    Step 1: Deploy Nightfall Scripts

    Step 2: Deploy Nightfall’s Custom Profile

    The Profiles page needs refreshed to see the new profile. Come back to this page and click "View" to see the status of the deployment.

    Step 3: Deploy Nightfall's .PKG

    How to Perform an Upgrade

    Once a managed package is uploaded, as in Step 3, it is not possible to upload another package within the already created app. A newly created Native App will be required.

    The remote destination URL
  • The repository name and configured remotes

  • A Git Push Monitoring policy evaluates where code is being pushed, not what is being pushed. If the destination does not match your approved Git domains, Nightfall generates an exfiltration event.

    Supported Git Destinations

    Git Push Monitoring supports:

    • GitHub Cloud

    • GitLab Cloud

    • Bitbucket

    • Any Git server accessible via HTTPS or SSH

    Policy Configuration

    1. Step 1: Define Approved Git Destinations

    Customers define approved Git hosting locations using Domain Collections.

    Examples:

    • github.com/my‑company‑org/*

    • gitlab.company.com/*

    • bitbucket.org/company/*

    These domains represent where source code is allowed to be pushed.

    1. Step 2: Configure Git Push Monitoring Policy

    Policy Type: Endpoint Exfiltration Action: Git Push

    Destination Condition Options:

    • Any domain

    • Domain in approved list

    • Domain not in approved list (recommended)

    Recommended Configuration:

    This configuration alerts when developers push code outside approved repositories.

    Example Use Cases

    1. Prevent Personal GitHub Usage

      1. Approved: github.com/company‑org/*

      2. Detected: github.com/john‑doe/test‑repo

    2. Monitor Scratch or Temporary Repositories

      1. Even if the repository is newly created or unnamed, Nightfall detects the push if the destination domain is not approved.

    3. Enforce Corporate GitHub & GitLab Usage

      1. Ensure all production code stays within:

        1. Corporate GitHub organizations

        2. Internal GitLab instances

    Event Details

    When a Git push violates policy, Nightfall generates an event with metadata‑only context.

    Event Summary Fields

    Field

    Description

    Event Type

    Git Push

    Repository

    Repository name

    Actor

    Example Scenarios

    The following scenarios illustrate the support matrix for this capability.

    1. Push to Approved Repository

      1. Git operation succeeds

      2. No alert generated

    2. Push to Non‑Approved Repository

      1. Git operation succeeds (no blocking)

      2. Exfiltration event generated

    3. HTTPS and SSH Both Supported

      1. Detection works for both authentication methods

    4. Multiple Remotes Supported

      1. Events reflect the actual remote used for the push

    5. Unmanaged Devices

      1. No detection occurs without an endpoint agent

    Git Push Monitoring provides organizations with a simple and effective control to:

    • Detect source code exfiltration

    • Enforce approved Git destinations

    • Gain visibility into developer Git activity

    Managed Endpoint with Nightfall agent
       └── git push
            ├── Action: Git Push
            ├── Source: Managed device
            └── Destination:
                 ├── Approved domain → Allowed
                 └── Non‑approved domain → Exfiltration Event generated
    Action: Git Push
    For: Domain not in <Approved Git Domains>
    Set
    For
    to
    AirDrop
    .
  • Leave Data Source and Data Destination as shown. They are not configurable for this trigger. Switching to AirDrop clears any asset-origin filters that were set on another trigger.

  • Content scanning and detection rules apply.

  • You can Monitor or Block.

  • End-user notification, when enabled, uses the title Assets transferred via AirDrop. Destination on that notice is empty because the product does not store an AirDrop recipient.

  • Platform note

    AirDrop is a macOS capability. The policy wizard does not currently lock the OS checkboxes to Mac only. Put macOS in the policy scope. Windows devices will not produce AirDrop events.

    What shows up on an event

    • Event type: AirDrop file transfer (list views may say Airdrop File Transfer; Forensic Search shortens the action to AirDrop).

    • File name, file hash, file size, start time.

    • No recipient device list (unlike Bluetooth).

    Common use cases

    • Stop a laptop from AirDropping a payroll sheet to a personal phone in a cafe.

    • Log AirDrop of design files from a studio Mac to an unmanaged iPad.

    • Cover the wireless hop that Removable Media and Browser Upload miss.

    Policy recommendations

    • Pair with To removable media and Bluetooth if you care about every off-device copy that never hits a browser.

    • Use content detection if you only want to fire on sensitive files. You can also run a lineage-only policy if your tenant supports that pattern on other file-transfer triggers.

    • Do not expect to allowlist a specific friend's iPhone. That control is not in the wizard.

    How this differs from nearby triggers

    Need
    Use

    USB / external disk

    To removable media

    Bluetooth file send, with device names

    Bluetooth

    scp / curl

    Can I limit AirDrop to certain people or devices?

    No. The AirDrop scope has no recipient filter. The policy applies to matching transfers on in-scope endpoints.

    Why are Data Source and Data Destination greyed out?

    AirDrop does not take those filters. The placeholders say they are not applicable.

    Does this cover AirPlay, Continuity, or iCloud?

    No. This trigger is AirDrop file transfer only.

    Will a Windows policy do anything?

    You will not get AirDrop events from Windows. Scope the policy to macOS.

    Can I block AirDrop?

    Yes. Enable the block action on the policy. Monitor-only still writes an event.

    Where do I see the file that was sent?

    On the event: file name, size, hash, and start time, plus the usual user and device context.

    FAQ

    Set For to Bluetooth.
  • Leave Data Source and Data Destination as shown. Switching to Bluetooth clears any asset-origin filters that were set on another trigger.

  • Content scanning and detection rules apply.

  • You can Monitor or Block.

  • End-user notification, when enabled, uses the title Assets transferred via Bluetooth. Destination is the comma-separated device names from the transfer, when Nightfall has them.

  • What shows up on an event

    • Event type: Bluetooth file transfer (list views may say Bluetooth File Transfer; Forensic Search shortens the action to Bluetooth).

    • File name, file hash, file size, start time.

    • Bluetooth Devices on the event (when the feature is on): device name, type, vendor, MAC address, product id and name.

    Device types you may see: Phone, Computer, Audio, HID, Wearable, Other.

    Common use cases

    • Catch a file sent from a laptop to a personal phone over Bluetooth.

    • Investigate which nearby device received a transfer (name, type, MAC).

    • Cover the path that is not USB and not AirDrop.

    Policy recommendations

    • Pair with AirDrop on Mac fleets and To removable media for physical drives.

    • Use the event device list for investigation. You cannot allowlist a MAC address in the trigger today.

    • HID or Audio in the device list on an event does not mean the policy watches keyboards or headsets. It means a file transfer involved a device Nightfall classified that way.

    How this differs from nearby triggers

    Need
    Use

    AirDrop to an iPhone

    AirDrop

    USB stick

    To removable media

    scp to another host

    Does this monitor every Bluetooth connection?

    No. Only file transfers. Pairing and audio are out of scope.

    Can I allow corporate Bluetooth devices and block everything else?

    Not in the policy wizard. There is no include/exclude list for Bluetooth devices. Removable Media has vendor and serial filters; Bluetooth does not.

    Why are Data Source and Data Destination greyed out?

    Bluetooth file transfer does not take those filters.

    What device details will I see?

    When present: name, type (Phone, Computer, Audio, HID, Wearable, Other), vendor, MAC, product id, product name. Search the devices list on the event.

    Can I block the transfer?

    Yes. Enable the block action. Monitor-only still writes an event.

    Is this the same as AirDrop?

    No. AirDrop is Apple's peer transfer. Bluetooth is Bluetooth file send, and the event can list the other device.

    FAQ

    Set the time period within which the minimum no. of downloads must be considered as exfiltration event.

    In the following case, an exfiltration event is created if, there are 2 or more downloads within a minute.

    Configuring Triggers

    You must set the action frequency carefully. For example, consider that you set the action condition as 5 or more files, within 1 hour as shown in the following image. In this case, if a user downloads four assets, every 1 hour, the policy does not trigger a violation, since the Action condition does not match. So, a user can keep downloading four files every hour and get away with it.

    Currently, this action is supported only for MAC devices.

    Scenario 1: Prevent Exfiltration of sensitive data to unsanctioned destinations

    Scenario 2: Allowing upload action only to approved destinations

    Record Before & After

    Session Replay and Bring Your Own Bucket

    Configuring Integration Alerts

    Nightfall for Google Drive allows you to configure alerts at the policy level and also at the integration level. Alerts can be sent in Google drive by using the following alert channels.

    • Slack

    • Email

    • Webhook

    • Jira Tickets

    When you configure alert settings at the integration level, the alert settings apply to all the policies, created for the Google Drive integration. However, when you configure alert settings specifically for a policy, which is created in the Google Drive integration, the alert settings are applicable only for that specific policy.

    This document explains how to configure alerts at the integration level. To learn about how to configure alerts at the policy level, read .

    • To use Slack as an alert platform, you must first perform the required Slack configurations. You can refer to to learn more about how to configure Slack as an Alert platform.

    • To use Webhook as an alert platform, you must first perform the required Webhook configurations. You can refer to to learn more about how to configure Webhook as an Alert platform.

    • To use JIRA as an alert platform, you must have the DLP for the JIRA app installed from the . You can read more about the DLP for JIRA integration .

    You can configure alerts at the integration level once you have installed the Nightfall for Google Drive integration.

    To configure alerts at the integration level:

    1. Navigate to the Google Drive integration

    2. Scroll down to the Alerting section.

    3. You can configure one or multiple alert channels.

    1. To configure Slack as an alert channel, click + Slack channel.

    1. In the Slack alert channel field, enter the name of the Slack channel in which you wish to receive the alerts.

    2. Click Save.

    A confirmation pop-up box is displayed to confirm if the Slack channel (entered in the second step) must be used only for Google Drive integration or all the Nightfall integrations.

    1. Select No, only integration level to use the Slack channel only for Google Drive, or select Yes, please to use the selected Slack channel for all the Nightfall integrations.

    1. Click + Email.

    1. Enter the Email ID of the recipient who should receive the notifications.

    2. Click Save.

    A confirmation pop-up box is displayed to confirm if the Email ID (entered in the second step) must be used only for Google Drive integration or all the Nightfall integrations.

    1. Select No, only integration level to use the Slack channel only for Google Drive, or select Yes, please to use the selected Slack channel for all the Nightfall integrations.

    1. Click + Webhook.

    2. Enter the Webhook URL.

    3. Click Test. If the test result is not successful, check the Webhook URL.

    4. (Optional) Click Add Header to add headers.

    1. Click + Jira Ticket.

    2. Select a JIRA project from the Jira Project drop-down menu.

    3. Select an issue type from the Issue Type drop-down menu.

    4. (Optional) Add comments to be added in the JIRA ticket.

    A confirmation pop-up box is displayed to confirm if the JIRA settings configured for the Google Drive integration must be applied to all the other Nightfall integrations too.

    1. Select No, only integration level to use the configurations only for Google Drive, or select Yes, please to use the selected JIRA configurations for all the Nightfall integrations.

    When a Violation occurs, Nightfall sends a notification to the end-user whose actions triggered the violation. While notifying the end-user, Nightfall also sends a text message. You can draft the text message to be sent to the end-user. This message applies to all the policies. Click Save changes once done.

    Remediation for Google Drive Exfiltration

    This document explains what admins and end-users can do once a policy is violated.

    Admin Notification and Remediation

    When end-users violate a policy, the Nightfall admin is notified about the incident. The notification channel used to notify the Nightfall admin depends on the settings configured in the Admin Alerting section. If you have not enabled any notification channels in the Admin alerting section, Nightfall admins are not notified.

    If you have enabled the email notification in the Admin alerts section, Nightfall admins receive an email. The email is as shown in the following image.

    The Email consists of the following data.

    • Event: The event that caused the violation. For Google Drive, the event is always a download of assets.

    • Actor: The Email ID of the user who downloaded the file.

    • When: The date and time when the email was downloaded.

    • Where: The name of the file that was downloaded.

    • Policies Violated: The name of the policy that was violated.

    • Violation Dashboard: The link to the Events screen to view the violation in detail.

    • Actions: The list of actions that the Nightfall admin can take.

    Also, a Slack message is sent if you have enabled the Slack alerts for the Nightfall admin. The Slack message looks as shown in the following image.

    End-users receive notifications and remediation actions if the Nightfall admin has enabled these settings. The notifications are based on the settings configured in the section. The end-user remediation actions are based on the settings configured in the section.

    If you have configured the Email notification for end-users and enabled the end-user remediation, end-users can take remediation actions from the Email itself.

    If you have configured Slack notifications for end-user and enabled end-user remediation, end-users can view the Slack message.

    Nightfall admins can manage violations from within the Nightfall console. The Events page in Nightfall lists all the violations under the Exfiltration tab. End-users can get a detailed view of each exfiltration Event triggered.

    To view violations in Nightfall navigate to the Exfiltration Prevention page from the left menu.

    The Exfiltration Events page lists all the exfiltration events. To view events with specific statuses, you can click the respective tabs.

    To view the past events, click the Time filter and select the required time period. By default, the time period displays Events for the Last 7 Days.

    The Event list view consists of the following columns.

    Column Name
    Description

    You can click an event to view the details. The detail view window consists of the following tabs.

    • Summary: The Summary tab displays highlights of the event like the name of the downloaded asset, the name of the violated policy, the email ID of the user who violated the policy, and so on.

    • Asset: The asset window displays the details of the asset and the history of the asset. You can also choose to view historic asset data. If there are multiple assets in a single violation, you can choose which asset's details must be displayed.

    • Actor: The actor tab displays the details and history of the user who downloaded the asset. You can choose to view historical data of the user. You can also add which can serve as metadata for the violation.

    The events list view displays an ellipsis menu at the extreme right corner. Admins can click this menu to take appropriate action on an exfiltration event.

    The various available actions are explained as follows.

    • Acknowledge: This action can be taken when you just wish to acknowledge that you have viewed the violation.

    • Notify Email: This action sends an email notification to the end-user who caused the violation.

    • Notify Slack: This action sends a Slack notification to the end-user who caused the violation.

    • Suspend Account: This action suspends the account of the user who caused the violation.

    Once the action is implemented, the status of the event changes respectively. By default, an event can have one of the following two statuses.

    • Active: The event has been generated but no action has been taken.

    • Input Requested: A notification has been sent to the end-user requesting their response.

    Nightfall Windows Agent Deployment: SCCM

    A step-by-step guide to deploy the Nightfall endpoint agent and the AI-coding-assistant hooks (Claude Code, Cursor, VS Code + GitHub Copilot) to Windows devices using SCCM/MECM.

    1. Prerequisites

    • Client: SCCM Current Branch; SCCM client installed and healthy on target devices; a reachable Distribution Point (DP).

    • Operating System: Windows 10(22H2 and above)/11 x64 targets (ARM not supported).

    • Package: From the Endpoint page → navigate to Download package button →

      • Download NightfallAgent.msi

      • Copy API Key and Company ID

    • The agent self-updates (every few hours) — SCCM’s job is a one-time install; don’t manage the version in SCCM (hence the version-agnostic detection in §3).

    • Claude Code shows a one-time security-consent dialog the first time it loads managed hooks — communicate this to developers. (On some 2.1.x builds /hooks may show “0” even when hooks are active — verify via the Nightfall console or claude --debug, not that count.)

    • Always "Run as Administrator".

    Put the installers on a UNC share the site server and DP can read.

    ⚠️ Share permissions matter. SCCM’s distribution service reads the source as the site server’s computer account, not your user. Grant Read to Domain Computers (or the site server’s machine account) on both the share and NTFS — otherwise Distribute Content fails with “cannot access … Win32 error 5 (Access Denied).”

    1. Within SCCM, navigate to: Software Library → Application Management → Applications → Create Application → Manually specify → add a Script Installer deployment type.

    • Content location: \\<fileserver>\NightfallDeploy\Agent

    • Installation program:

    • Install behavior: Install for system · Whether or not a user is logged on · Hidden

    • Detection method — use a

    1. Then Distribute Content → your DP

    2. Deploy the app Required to your target device collection.

    • Create one Script Installer application per IDE (VS Code needs two — see below).

      • Common settings: Install for system · Whether or not a user is logged on · Hidden · Required.

    • Content location: \\<fileserver>\NightfallDeploy\ClaudeCode

    • Installation program:

    • Detection — File System: C:\Program Files\ClaudeCode\managed-settings.d\nightfall-hooks.json exists

    • Content location: \\<fileserver>\NightfallDeploy\Cursor

    • Installation program:

    • Detection — custom PowerShell (Cursor’s hooks.json is shared with other vendors, so existence isn’t enough):

    App 1 — hook file:

    • Content: \\<fileserver>\NightfallDeploy\VSCode

    • Install:

    • Detection — File System: C:\ProgramData\Copilot\hooks\nightfall.json exists

    App 2 — enterprise policy (Copilot ignores hook files at paths not registered in policy):

    • Content: \\<fileserver>\NightfallDeploy\VSCode

    • Install: powershell.exe -NoProfile -ExecutionPolicy Bypass -File .\scripts\windows\install-policy.ps1

    • Detection — Registry: HKLM\SOFTWARE\Policies\Microsoft\VSCode value chat.hookFilesLocations

    On a target device:

    1. Run Machine Policy Retrieval

    2. Navigate to Application Deployment Evaluation (Control Panel → Configuration Manager → Actions), then check:

    1. Confirm the device and per-IDE hook status appear healthy on the Devices page in the Nightfall console.

    Configuring Integration Alerts

    Nightfall for macOS and Nightfall for Windows OS allow you to configure alerts at the policy level and also at the integration level.

    You can navigate to the alerts page by executing the following steps:

    1. Click Integrations in the left pane.

    2. Click Manage for either Endpoint macOS or Endpoint Windows widget.

    Configuring Policies

    The Exfiltration policies for MAC and Windows OS allow you to monitor if there are any uploads via browser or cloud storage apps. You can configure the domains in Internet that needs to be monitored and also the cloud storage apps which need to be monitored.

    When there are any uploads to the configured domain or cloud storage apps, the Nightfall AI agent notifies this action. You can configure the notification channels through which you wish to receive notifications when there is an attempt to upload files/folders.

    Once you have completed the installation of the Nightfall agent, you must ensure that the connection is live. If the Nightfall agent cannot connect to the macOS or the Windows OS device for more than 6 hours, the connection is lost. When the connection is live, a Connected message is displayed. If the connection is lost, a Disconnected message is displayed under the Agent Status column.

    When a macOS or Windows OS device is disconnected, you can remove the device from the monitored list (Devices tab). To remove a disconnected device from the monitored list, click the delete icon for the respective device.

    Clicking the delete icon displays a warning pop-up window as shown in the following image. Click

    Removable Media

    Nightfall’s removable media controls allow you to monitor or block sensitive data exfiltration to external storage devices such as USB drives and external HDD/SSD. Policies are evaluated at the endpoint and can be scoped with device type, vendor, and serial number filters for precise enforcement.

    Out of the box, Nightfall supports ~1,200 removable media vendors, enabling immediate coverage without manual vendor onboarding.

    Nightfall detects and can block the following removable media categories:

    • USB storage devices (thumb drives, external HDD/SSD)

    These are internally represented as removable media types and can be included or excluded in the policy configuration.

    How Removable Media Policies Work

    A removable media policy is evaluated using three layers of filters:

    CLI Transfer

    CLI Transfer watches file movement started by selected command-line tools on a managed endpoint. The agent intercepts the process (for example scp or curl) when it uploads or downloads a file. You pick the tools on the policy. Nightfall does not treat every shell command as this trigger.

    This is not Git Push. git push is a separate trigger (Git Push to). CLI Transfer is for the tools listed below.

    Domain collections are not used as a destination list for this trigger. You do not pick domains or apps. You pick CLI tools. Data Source (asset origin) is still available, the same as on Browser Upload.

    If you do not see CLI Transfer in the For dropdown, ask your Nightfall account team to enable it.

    What you configure

    Advanced Settings

    This stage allows you to select automated notification channels or actions if a policy violation occurs.

    This section allows you to send notifications to Nightfall users. The various alert methods are as follows. You must first turn on the toggle switch to use an alert method.

    The steps to configure alert channels for policy-level integration are the same as in the case of integration-level alerts. You can refer to the document.

    Automated actions allow you to configure automated remediation actions when an exfiltration attempt is detected by Nightfall policy. Nightfall supports the following automated actions for Salesforce. You can choose to implement the automated action immediately after detecting a download attempt or after some time.

    To enable the automated action, you must turn on the respective toggle switch.

    This action logs out the user from the Salesforce account. They cannot login until a Salesforce admin revokes the freeze on the account.

    You must now select when exactly after detecting the event, the action must be triggered. if you select the Immediately option, the automated action is triggered immediately after the download attempt is made.

    Claude Cowork (OpenTelemetry)

    Claude Cowork can't run Nightfall hooks, so it's monitored through Anthropic's built-in OpenTelemetry (OTel) integration instead. You configure it once from the Anthropic admin console — not per device or per user — and it captures prompts, tool calls, file access, and session metadata across every Team / Enterprise seat.

    OTel is monitor-only: it reports on activity after it happens and cannot block. For how it compares to hooks, see Hooks vs. OpenTelemetry.

    1. Copy your OTLP values from Nightfall

    In the Nightfall console, open AI Agent Security → AI Agent Security Setup and select the OpenTelemetry tab. Nightfall generates three values scoped to your organization — use Copy all values to grab them together:

    Field
    Value

    User performing the push

    Device

    Endpoint hostname

    Destination URL

    Git remote URL

    Git Remotes

    origin, personal, etc.

    Risk

    Critical, High, Medium, Low

    CLI Transfer

    Browser attach

    Browser uploads to

    CLI Transfer

    All Bluetooth pairing

    Not available as a trigger

    OTLP Endpoint

    An HTTPS URL for your environment, e.g. https://<your-nightfall-otel-host>/es/otel/…

    OTLP Protocol

    http/json

    OTLP Headers

    X-Nightfall-Company-Identifier=<company-id>,Authorization=Bearer <token>

    Copy each value exactly as shown — the endpoint host and the headers are specific to your organization and environment.

    2. Paste them into the Anthropic console

    1. Sign in to console.anthropic.com as an organization owner. (You can use Open Anthropic console on the OpenTelemetry tab to jump straight there.)

    2. Open Organization Settings → Cowork → Observability.

    3. Paste the endpoint, protocol, and headers you copied from Nightfall.

    4. Save.

    3. Verify the connection

    Back on the OpenTelemetry tab in Nightfall, the collector status card starts as "OTEL collector not yet connected · Not configured." Once Cowork sends its first telemetry — usually after the next Cowork session — the status flips to connected, and Claude Cowork appears as an active client on the Devices page.

    What Cowork OTel captures

    Across every Team / Enterprise seat, with no per-device install:

    • Prompts and session metadata

    • Tool calls and file access

    • Model name, token usage, and cost

    • API errors and retries

    Capturing full prompt text and tool input/output (rather than metadata only) depends on Anthropic's OTel logging options being enabled for your organization — see Hooks vs. OpenTelemetry and Anthropic's Cowork monitoring docs.

    Availability: Requires a Claude Team or Enterprise plan, and the integration must be configured by an Anthropic organization owner.

    The OTLP Headers value contains a bearer token that authenticates your organization's telemetry. Treat it like a secret — copy it directly from the console into Anthropic, and don't paste it into tickets, chat, or screenshots.

    Connection status reflects a rolling 72-hour activity window. If no Cowork telemetry is received for 72 hours, the collector shows as inactive again until the next session.

    Deployment runs in System context (SCCM default).

    version-agnostic
    script (important):
    On the Detection tab choose
    Use a custom script → PowerShell
    and paste:
    exists

    2. Reminders

    3. Stage the Content

    4. Deploy the Nightfall Agent

    Do NOT use a fixed MSI product code for detection.

    The agent auto-updates itself, and its MSI product code changes with every version — a product-code detection would break after the first auto-update and cause an endless reinstall/1603 loop. The script above detects any installed version (SCCM installs once; the agent’s auto-updater keeps it current).

    5. Deploy the Hooks (per IDE)

    The install command stages the payload to the path the script expects, then runs the package’s install.ps1:

    Claude Code

    Cursor

    VS Code + GitHub Copilot (two applications)

    Order: deploy the agent first — it installs nightfall-hook-relay (which the hooks call) onto the system PATH. Hook files install without it, but only fire once the agent is present.

    6. Verify

    \\<fileserver>\NightfallDeploy\
    ├── Agent\NightfallAgent.msi
    ├── ClaudeCode\   (payloads\ + scripts\windows\ from the Claude Code package)
    ├── Cursor\       (payloads\ + scripts\windows\ from the Cursor package)
    └── VSCode\       (payloads\ + scripts\windows\ from the VS Code package)
    msiexec /i "NightfallAgent.msi" API_KEY="<YOUR_API_KEY>" COMPANY_ID="<YOUR_COMPANY_ID>" INSTALL_NF_DRIVER="1" /qn
    powershell.exe -NoProfile -ExecutionPolicy Bypass -Command "New-Item -ItemType Directory -Force 'C:\Nightfall\Hooks\claude-code' | Out-Null; Copy-Item -Force '.\payloads\nightfall-hooks.json' 'C:\Nightfall\Hooks\claude-code\'; & '.\scripts\windows\install.ps1'"
    powershell.exe -NoProfile -ExecutionPolicy Bypass -Command "New-Item -ItemType Directory -Force 'C:\Nightfall\Hooks\cursor' | Out-Null; Copy-Item -Force '.\payloads\hooks.json' 'C:\Nightfall\Hooks\cursor\'; & '.\scripts\windows\install.ps1'"
    $f = 'C:\ProgramData\Cursor\hooks.json'
    if ((Test-Path $f) -and (Select-String -Path $f -Pattern 'nightfall-hook-relay --source cursor' -Quiet)) { Write-Output 'Installed' }
    powershell.exe -NoProfile -ExecutionPolicy Bypass -Command "New-Item -ItemType Directory -Force 'C:\Nightfall\Hooks\vscode' | Out-Null; Copy-Item -Force '.\payloads\nightfall.json' 'C:\Nightfall\Hooks\vscode\'; & '.\scripts\windows\install.ps1'"
    Get-Service NightfallAgent                                   # Running
    where.exe nightfall-hook-relay                               # relay on PATH
    Test-Path 'C:\Program Files\ClaudeCode\managed-settings.d\nightfall-hooks.json'
    Test-Path 'C:\ProgramData\Cursor\hooks.json'
    Test-Path 'C:\ProgramData\Copilot\hooks\nightfall.json'
    Get-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\VSCode' -Name 'chat.hookFilesLocations' -EA SilentlyContinue
    if ((Test-Path 'HKLM:\SOFTWARE\NightfallAI\NightfallAgent') -and (Get-Service 'NightfallAgent' -ErrorAction SilentlyContinue)) {
        Write-Output 'Installed'
    }

    Click "Next"

  • Select "Run Once Immediately" > Click "Add"

  • Click "Save and Publish"

  • Click Save.

    Click Save changes.

    Prerequisites

    Configure Alerts at the Integration Level

    Configuring Slack as an Alert Channel

    Configuring Email as an Alert Channel

    Configuring Webhook as an Alert Channel

    When you configure alerts to a Webhook, Nightfall AI sends occasional posts to:

    • To validate that the Webhook is properly configured before the policy is saved.

    • Periodically thereafter to ensure that the Webhook is still valid.

    The response to the test Webhooks is 200 status code if successful.

    An example of Webhook request is as follows.

    This is part of alert event consumption and can be ignored.

    Configuring JIRA as an Alert Channel

    Configure End-User Notification

    this document
    this document
    this document
    Atlassian Marketplace
    here

    Actor

    The email ID of the user who downloaded the asset. In some cases, you can also find the name of an app in brackets. This indicates that the app present in your Google Workspace downloaded the asset on behalf of the user. You can find more info in this .

    Policy

    The name of the policy violated by the event.

    Status

    THe current status of the event.

  • Ignore: This action ignored the violation. You can take this action when an event is false positive.

  • Copy Link: This action is only available on the Asset detail view. You can copy the direct link to the Event with this action.

  • Event type and asset(s)

    The nature of the event (asset download) and the name of the asset that is either downloaded or uploaded.

    Location

    The location of the asset (Google Drive in this case)

    When

    End-User Notification and Remediation

    Managing Events in Nightfall

    Event List View

    Event Detail View

    Taking Actions on the Events Page

    You can also take action from the event detail view page. The actions are available at the bottom of the detail view page.

    Automation
    End-User Remediation

    Number of days/months since the event occured.

    Click the Alerting tab.

    Alerts can be sent in macOS and windows OS policies by using the following alert channels.

    • Slack

    • Email

    • Webhook

    • Jira Tickets

    When you configure alert settings at the integration level, the alert settings apply to all the policies, created for the macOS/Windows OS integration. However, when you configure alert settings specifically for a policy, which is created in the macOS/Windows OS integration, the alert settings are applicable only for that specific policy.

    This document explains how to configure alerts at the integration level. To learn about how to configure alerts at the policy level, read this document.

    • To use Slack as an alert platform, you must first perform the required Slack configurations. You can refer to this document to learn more about how to configure Slack as an Alert platform.

    • To use Webhook as an alert platform, you must first perform the required Webhook configurations. You can refer to this document to learn more about how to configure Webhook as an Alert platform.

    • To use JIRA as an alert platform, you must have the DLP for the JIRA app installed from the Atlassian Marketplace. You can read more about the DLP for JIRA integration here.

    You can configure alerts at the integration level once you have installed the Nightfall for macOS/ Nightfall for Windows OS integration.

    To configure alerts at the integration level:

    1. Navigate to the macOS integration

    2. Scroll down to the Alerting section.

    3. You can configure one or multiple alert channels.

    1. To configure Slack as an alert channel, click + Slack channel.

    1. In the Slack alert channel field, enter the name of the Slack channel in which you wish to receive the alerts.

    2. Click Save.

    A confirmation pop-up box is displayed to confirm if the Slack channel (entered in the second step) must be used only for macOS integration or all the Nightfall integrations.

    1. Select No, only integration level to use the Slack channel only for macOS, or select Yes, please to use the selected Slack channel for all the Nightfall integrations.

    1. Click + Email.

    1. Enter the Email ID of the recipient who should receive the notifications.

    2. Click Save.

    A confirmation pop-up box is displayed to confirm if the Email ID (entered in the second step) must be used only for macOS integration or all the Nightfall integrations.

    1. Select No, only integration level to use the Slack channel only for macOS, or select Yes, please to use the selected email address for all the Nightfall integrations.

    1. Click + Webhook.

    2. Enter the Webhook URL.

    3. Click Test. If the test result is not successful, check the Webhook URL.

    4. (Optional) Click Add Header to add headers.

    5. Click Save.

    1. Click + Jira Ticket.

    2. Select a JIRA project from the Jira Project drop-down menu.

    3. Select an issue type from the Issue Type drop-down menu.

    4. (Optional) Add comments to be added in the JIRA ticket.

    5. Click Save changes.

    A confirmation pop-up box is displayed to confirm if the JIRA settings configured for the macOS integration must be applied to all the other Nightfall integrations too.

    1. Select No, only integration level to use the configurations only for macOS, or select Yes, please to use the selected JIRA configurations for all the Nightfall integrations.

    When a Violation occurs, Nightfall sends a notification to the end-user whose actions triggered the violation. While notifying the end-user, Nightfall also sends a text message. You can draft the text message to be sent to the end-user. This message applies to all the policies. Click Save changes once done.

    Prerequisites

    Configure Alerts at the Integration Level

    Configuring Slack as an Alert Channel

    Configuring Email as an Alert Channel

    Configuring Webhook as an Alert Channel

    When you configure alerts to a Webhook, Nightfall AI sends occasional posts to:

    • To validate that the Webhook is properly configured before the policy is saved.

    • Periodically thereafter to ensure that the Webhook is still valid.

    The response to the test Webhooks is 200

    Configuring JIRA as an Alert Channel

    Configure End-User Notifications

    Remove Device
    to confirm the removal of the device.

    If a removed device reconnects, it is automatically added to the monitored list. To permanently prevent the monitoring of a device, you must de-provision the device through MDM (uninstall the Nightfall Agents and remove it from future targeting).

    This feature declutters your monitoring list and ensures that only active devices that are being monitored are displayed.

    You can leverage this feature efficiently with loaner laptops. When a former employee returns a device, the connection is lost and the status is displayed as disconnected. Security teams can be concerned about the device displaying the Disconnected status for a prolonged period and can initiate an investigation. Instead, you can use this feature and remove the device from the monitored list. When the device is reassigned to another employee, it connects back automatically, and the monitoring resumes.

    Similarly, you can use this feature for seasonal and dormant devices; remove them once they are not in use. They will connect back automatically once they are in use again.

    Collections help you refine your monitoring to reduce noise from sanctioned upload destinations as well as closely monitor exfiltration of files originating from high-value SaaS applications accessed through the browser. You can also define specific domain collections to closely monitor upload activity to specific categories of upload destinations. For instance, to track files uploaded to social media, you can create a domain collection called social media and add domains like Facebook, Instagram, Twitter, and so on. Similarly, you create a collection for known and sanctioned upload destinations that are safe to upload to so you can ignore them from your monitoring policies or monitor the upload of items originating from such domains. While creating a policy, you can directly add the collection to be monitored. All the domains in the collection will be monitored.

    You can create a domain by either manually entering all the domain URLs manually or by uploading a comma-delimited list of domains in a text file.

    To group domains:

    1. Log in to the Nightfall app.

    2. Navigate to Integrations from the left menu.

    3. Click Manage on the macOS/Windows OS integration.

    1. Click the Domains tab.

    2. Click + New Collection.

    You can either add the domains manually or upload a text file containing the list of domains. The following section has two tabs. The first explains the process of manually adding domains, and the second tab explains adding domains by uploading a file.

    1. Click + Add Domain.

    1. Enter a name for the Collection in the Collection Name field (Social Media in the following image)

    2. Enter a domain and hit the enter key (facebook.com in the following image).

    Important

    When you add a domain, the sub domain is not included automatically. For instance, if you add abcd.com, docs.abcd.com is not included. To include subdomains, you must enter the full URL containing the subdomain. If you have multiple subdomains, you can use the asterisk wildcard (*) and enter the domain as *.abcd.com

    1. (Optional) Click + Add Domain to add multiple domains to the collection.

    2. (Optional) Click the delete icon to delete a domain.

    3. Click Save Changes.

    1. Enter a name for the Collection in the Collection Name field.

    2. Click Upload.

    1. Browse and upload the text file containing the list of domains.

    Once you upload the file, the list of domains present in the file are displayed as follows.

    The detailed steps to configure the MAC OS/Windows OS device exfiltration policy are explained in the following documents.

    • MAC/Windows App Selection

    • Scope

    • Trigger

    • Advanced Settings

    Verify Connection

    Removing Disconnected Devices

    Create Domain Collections

    Creating Policy

  • Origin - Where the content originated from

  • Destination Removable Media Filters - Which removable devices the rule applies to

  • Content Detection - Whether sensitive data is present

  • Endpoint Device - Which devices are included or excluded in the policy

  • If all conditions match, the configured enforcement (Monitor or Block) is applied.

    Policy configuration:

    1. Step 1 - To apply a policy to removable devices:

      • Set Action to “To removable media”

      This ensures the rule only evaluates file transfers where data is being written to an external device.

    2. Step 2 - Removable media filters

      1. Removable media filters allow you to precisely control which removable devices are included in enforcement.

        1. Device Type

          1. Monitor all – Applies to all removable media types

            1. Specific types – Limit enforcement to selected media types (USB, HDD/SSD)

    Once a removable media action and device match, Nightfall evaluates the content being transferred:

    • Sensitive data types (PII, credentials, secrets, etc.), file classifiers or any other applicable detectors in the configured detection rules

    If sensitive content is detected, enforcement is applied. Each policy can be configured to:

    • Monitor – Log the event for visibility and auditing

    • Block – Prevent the transfer to removable media

    Both modes can be enabled simultaneously to provide audit visibility even when blocking.

    Common Configuration Examples

    1. Example 1: Block All USB Devices

      1. Action: To removable media

      2. Device Type: USB

      3. Vendor: Monitor all

      4. Serial Number: Monitor all

      5. Enforcement: Block

    2. Example 2: Allow Only Approved Vendors

      1. Action: To removable media

      2. Vendor: Specific vendor(s)

      3. Enforcement: Block

    3. Example 3: Allow Only Specific Devices

      1. Action: To removable media

      2. Serial Number: Specific serial numbers

      3. Enforcement: Block

    4. Example 4: Exclude Corporate USB Drives

      1. Action: To removable media

      2. Vendor: All vendors

      3. Serial Number: All serial numbers except

    For exfiltration events involving removable media, Nightfall surfaces additional asset-level metadata to help security teams understand where data was written and which physical device was involved.

    In the Asset details panel, you can expect the following removable media–specific fields:

    • Medium – Indicates the destination medium as Removable Media

    • Mount Path – The local mount location of the device on the endpoint (for example, /Volumes/My USB Device on macOS)

    • Volume Label – The human-readable label assigned to the removable device

    • Media Type – The category of removable media (for example, USB, HDD/SSD)

    • Vendor ID – The hardware vendor identifier reported by the operating system

    • Serial Number – The device’s unique serial number, when available

    These fields are available only for removable media events and enable precise investigations, device allowlisting, and policy tuning.

    All other event information - including user identity, endpoint details, timestamps, policy action, file preview, activity log and risk context, manual actions - is consistent with other Endpoint Exfiltration events and is available in the Summary and Device tabs.

    In the policy wizard, set For to CLI Transfer.

  • Under CLI Tools, select at least one tool. Next stays disabled until you do.

  • Optional: set Data Source / asset origin if you only care about files that came from certain apps or domains.

  • Content scanning and detection rules apply. You can Monitor or Block. Block copy in the product: This will block file transfers that match this policy.

  • End-user notification and screen replay follow the same endpoint rules as other triggers, when those options are on for your tenant.

  • CLI tools you can select

    Tool
    Typical use

    scp

    Copy files over SSH

    curl

    HTTP(S) upload or download

    wget

    sftp and ssh are not available in the CLI Tools picker.

    Windows notes for wget and rsync

    These two cannot be enforced on Windows:

    • rsync has no native Windows binary the agent can intercept.

    • PowerShell wget is an alias for in-process Invoke-WebRequest, so the agent never sees a process-create event.

    Behavior in the picker:

    • Windows-only policy: wget and rsync are disabled. Tooltip: {tool} cannot be enforced on Windows endpoints, so it is unavailable for Windows-only policies. If an older policy still had them saved, Nightfall strips them on edit.

    • macOS and Windows together: wget and rsync stay selectable, with an amber warning. Tooltip: {tool} applies to macOS endpoints only. It cannot be enforced on the Windows endpoints in this policy's scope.

    • macOS only: all six tools are available.

    scp, curl, aws s3, and npm have no Windows restriction in the wizard.

    What shows up on an event

    Events are labeled CLI Transfer. The agent records both file upload and file download through the selected tools.

    Typical fields: tool, command, remote host, remote path, parent process, execution source, file name, local path, size, and hash when available.

    Execution source values you may see:

    • User Terminal

    • AI Agent Subprocess

    • Other

    Common use cases

    • Stop engineers from scp or rsync of customer exports to a home machine.

    • Catch curl or aws s3 of a secrets file to an unmanaged bucket.

    • Watch npm publish from a laptop that is not supposed to ship internal packages.

    • Pair with Git Push if you care about both git push and raw file copy over SSH.

    Policy recommendations

    • Start with scp, curl, and aws s3. Add wget/rsync only if you have macOS in scope.

    • Do not rely on CLI Transfer for git push. Use Git Push to.

    • If you also run AI agents that shell out to curl, look at Execution Source AI Agent Subprocess on the event.

    How this differs from nearby triggers

    Need
    Use

    git push to a personal remote

    Git Push to

    File copied to a USB stick

    To removable media

    File attached in Chrome

    Which tools does CLI Transfer cover?

    Only the tools you check: scp, curl, wget, rsync, aws s3, npm. Other binaries are out of scope, even if they move files.

    Why are wget and rsync greyed out?

    The policy is Windows-only. Those tools cannot be enforced on Windows. Use a macOS (or mixed) OS scope, or drop those two tools.

    Why is there an amber warning on wget or rsync?

    The policy includes Windows and macOS. Those tools still apply on Mac. They will not apply on the Windows devices in the same policy.

    Why can't I click Next?

    You have not selected a CLI tool. Select at least one.

    Does this monitor every command in Terminal?

    No. Only the selected tools, when they transfer a file.

    Is this the same as Git Push?

    No. Git Push evaluates git remotes and is monitor-only. CLI Transfer evaluates scp/curl/and the rest, and can block.

    Can I limit destinations (only certain hosts)?

    Not in this trigger. There is no domain or host allowlist on CLI Transfer. Scope by OS, users, devices, optional asset origin, and tool list.

    Does Block actually stop the transfer?

    Yes, when you enable the block action on this trigger. The confirm text is about blocking file transfers that match the policy.

    Do I need a browser extension?

    No. This is endpoint-agent interception of the CLI process.

    FAQ

    If you select the After option, you must select the time gap after which the automated action must be implemented.

    This action revokes the permissions of the user. The user can now only view data across al Salesforce pages. They cannot download any data. This action assigns the user Salesforce's minimum access profile. You can learn more about this profile from this Salesforce document.

    You must now select when exactly after detecting the event, the action must be triggered. if you select the Immediately option, the automated action is triggered immediately after the download attempt is made.

    If you select the After option, you must select the time gap after which the automated action must be implemented.

    This section allows you to configure notifications to be sent to the end user whose actions triggered the violation.

    Enter a custom message to be sent to the end user. This message is sent in an Email. You can modify the default message provided by Nightfall and draft your message. The total character length allowed is 1000 characters. You can also add hyperlinks in the custom message. The syntax is <link | text >. For example, to hyperlink www.nightfall.ai with the text Nightfall website, you must write <www.nightfall.ai|Nightfall website>.

    The automation settings allow you to send notifications to end users. You can select one or both the notification methods. You must first turn on the toggle switch to use the automation option. The automation notification channels are as follows

    • Email: This option sends an Email to the user who attempted the download.

    • Slack: This option sends a Slack message to the user who attempted the download.

    End-user remediation (also known as Human Firewall) allows you to configure remediation measures that end users can take, when a violation is detected on by their download attempt. You must turn on the toggle switch to use this option. End-users receive the remediation actions in an Email as an action item. The various available remediation actions for end-users are as follows.

    • Report as False Positive with Business Justification: This option allows end users to report false positive alerts and provide a business justification as to why the alert is considered to be false positive.

    When end-users report alerts as false positive, you can choose the resolution method to be either Automatic or manual.

    If end-users do not take any remediation action, you can set the frequency at which they must receive the notifications to take action.

    Admin Alerting

    The alert configurations configured in this section describe the process of creating alerts at the policy level. Policy-level alerts apply only to the policy on which they are configured. To configure an alert on all the Salesforce Exfiltration policies, you must configure alerts at the integration level. To learn more about how to configure integration-level policies for the Salesforce integration, read Configuring Integration Alerts

    Automated Actions

    Freeze Salesforce User Account

    Configure Alerts at the Integration Level

    Revoke User Permissions

    End-User Notification

    Custom Message

    Automation

    End-User Remediation

    Manual Installation

    This document explains the process of installing the Nightfall agent manually.

    Prerequisites

    1. Ensure that you have root level access to the target macOS device.

    2. On your Nightfall console, navigate to https://app.nightfall.ai/endpoint and click the Download Package button on the top right corner of the page. Click Download Package for macOS and unpack the contents of the downloaded file.

    3. Create a default policy for web browser uploads and cloud storage application sync.

    To install the Nightfall agent in stealth mode (to hide UI elements), see .

    Installing the Package

    1. Locate the mdm_pre_installation_script.sh in the payload downloaded from Nightfall.

    2. Open a Terminal window.

    3. Run the mdm_pre_installation_script.shscript on your local machine as a root user, by executing the following command.

    1. Double click the provided nightfall-ai-agent_<version>.pkg.

    2. Click Continue.

    1. Click Install.

    1. Click Use Password to enter your device password and start the installation process.

    Once the installation is completed, you get a completion message as shown in the following image.

    1. Click Close.

    At the top right corner of your screen, you can view the Nightfall AI agent icon which looks as follows.

    When you click this icon, you can view the details of the agent.

    These system permissions and handled automatically through MDM profiles. For manual install, enabling these permissions manually is required.

    To monitor your MAC device, you must grant access to the hard disk. This section explains the process of granting disk access.

    1. Navigate to System Settings > Privacy & Security > Full Disk Access.

    1. If Nightfall is listed, make sure to toggle the permission to ON

    2. [Optional] Should Nightfall not be listed in the primary list

      1. Click the + icon at the bottom of the list (you may be prompted to enter your macOS password)

    1. Select NightfallAIAgent (under Applications) and click Open.

    1. Click Quit & Reopen.

    On the Full Disk Access page, ensure that the toggle switch is turned on for the NightfallAIAgent. This ensures that the full disk access is granted.

    For clipboard monitoring, you must grant the Nightfall agent accessibility permissions. This section explains the process.

    1. Navigate to System Settings > Privacy & Security > Accessibility.

    1. If Nightfall is listed, make sure to toggle the permission to ON

    1. [Optional] If Nightfall is not listed in the primary list

      1. Click the + icon at the bottom of the list (you may be prompted to enter your macOS password)

    b. Select NightfallAIAgent (under Applications) and click Open.

    c. On the Accessibility settings page, ensure that the toggle switch is turned on for the NightfallAIAgent. This ensures that the full disk access is granted.

    To ensure changes are picked up by the agent:

    1. Open Activity Monitor > Search of Nightfall > you should see two Nightfall processes running

      1. If you do not see two Nightfall processes, make sure to expand your view to all processes

    2. Select both process and click Quit, the agent will restart instantly.

    Apart from the disk access and accessibility permissions, you must also grant permission to the Nightfall AI agent to monitor browser uploads. This section explains the process.

    To grant access to browser uploads:

    1. Open a browser instance and upload a test file to any destination.

    2. When prompted, grant the Nightfall AI agent permissions.

    Nightfall delivers broad browser coverage with full data exfiltration protection across modern AI browsers and traditional browsers. Customers can confidently deploy Nightfall across supported environments without compromising on security or feature depth.

    AI Browsers

    • Perplexity Comet (macOS only)

    • ChatGPT Atlas (macOS only)

    Chromium-Based Browsers

    • Google Chrome

    • Microsoft Edge

    • Arc

    • Brave

    Other Browsers

    • Firefox

    Operating System Support

    1. macOS - The following browsers are supported on macOS:

      1. Chrome

      2. Edge

      3. Firefox

    To uninstall the Nightfall AI agent, locate the uninstallation script provided as part of the deployment bundle. You must execute the following command on your MAC device, as a root user.

    Nightfall macOS Agent Deployment: JumpCloud MDM

    Overview

    This guide provides instructions for deploying the Nightfall AI Endpoint Agent to macOS devices via JumpCloud MDM using the mdm_jumpcloud_deploy.sh script.

    The script is an all-in-one solution that handles config provisioning, installation, and ongoing health monitoring. When scheduled as a recurring JumpCloud command, it ensures the agent stays installed and running without manual intervention.

    Prerequisites

    Before you begin, ensure you have:

    • JumpCloud admin access with macOS devices enrolled

    • A JumpCloud device group scoped to the macOS devices you want to monitor

    • Deployment assets:

      • Configuration Profile: NightfallAI_Profile_with_Browser_Extensions.mobileconfig

      • Deployment script: mdm_jumpcloud_deploy.sh

      • Installer package: nightfall-ai-agent-signed.pkg

    Note: The Nightfall agent will only install correctly if the required .mobileconfig profile has been deployed beforehand.


    1. Log in to app.nightfall.ai and navigate to Settings > MDM Profile.

    2. Select JumpCloud from the list of supported MDM providers.

    3. Complete the OAuth flow to grant Nightfall read-only access to your JumpCloud device and user directory. This maps JumpCloud user identities to devices in the Nightfall console automatically.


    1. In JumpCloud Admin Portal, navigate to Device Management → Policy Management.

    2. Create a new MDM Custom Configuration Profile.

      1. Click the + button → select Mac tab → select MDM Custom Configuration Profile > click Configure

    1. In JumpCloud Admin Console, navigate to Device Management → Commands → + Command → Command.

      1. Type: Mac

      2. Paste the contents of mac_bundle folder → mdm_scripts folder →mdm_jumpcloud_deploy.sh as the command body.

    1. Save and run by pressing Run Now.

    • JumpCloud console: Check Commands → Results for the command's exit code and output after execution.

    • Verify the agent is running:

      • Open Activity Monitor → CPU and search for "Nightfall". Two processes should be running — one as root (daemon) and one as the logged-in user (agent).

    To remove the Nightfall agent from devices, run mdm_nightfall_ai_agent_uninstall.sh as a one-time JumpCloud command:

    1. Create a new Command in JumpCloud.

    2. Paste the contents of mdm_nightfall_ai_agent_uninstall.sh as the command body.

    3. Assign to the target devices and run.

    Nightfall macOS Agent Deployment: Rippling MDM

    This document explains the process of installing Nightfall AI agent using the Rippling MDM.

    NOTE: Rippling MDM has a requirement where the .mobileconfig profile has to be uploaded from a MacBook. It cannot be uploaded from another type of OS; otherwise the upload will not stick.

    Please note there are two parts to this process:

    1. Deploy the "mobileconfig" that pushes the profile and permissions.

      1. Step 1 - Create & Deploy Profiles

    2. Deploy the agent via the .PKG and scripts.

      1. Step 2.1 -

      2. Step 2.2 - Deploy the Nightfall Endpoint DLP Agent

    Confirm the following:

    • The macOS devices are onboarded.

    • Download the package from the console:

      • On your Nightfall console, navigate to

      • Click Download Package for macOS

    After confirming, move to "Step 1" as shown below.

    1

    In this step, you will create a custom profile for each of the profiles provided in your Nightfall endpoint payload.

    1. Locate NightfallAI_Profile_with_Browser_Extensions.mobileconfig in the downloaded Nightfall Endpoint payload package.

    2. Navigate to and click Upload.

    The below describes the steps to upgrade endpoints with a new version of the agent:

    1. Search or scroll to the old version of the Nightfall Endpoint DLP Agent and click “Edit”.

      a. Remove all devices from the installation list and click “Save”.

    2. Follow the to configure the new software package for the new version

    3. Follow to deploy the new version.

    The Nightfall Endpoint DLP Agent will now deploy to all selected target endpoints. Installation may take up to 48 hours and is dependent on the endpoint devices being turned on and connected.

    Nightfall Windows Agent Deployment: Microsoft Intune

    Learn how to install the Nightfall Agent for Windows using Intune as a Line-of-Business (LOB) app.

    The Microsoft Intune installation consists of the following steps:

    1. Connect Microsoft Intune to Nightfall (API-based MDM Onboarding)

    2. Deploy the Nightfall Agent via Intune

    Prerequisites

    • You are a Systems Administrator in Nightfall

    • You must have access to Microsoft Intune with the necessary admin privileges. An Intune administrator account with permission to approve OAuth access

    • Get the .msi package and command arguments form

      • Download the .msi installer file for the Nightfall Agent.

      • Note the API Key and Company ID in the command line provided by Nightfall.

    This step enables automated mapping of user profiles to devices without requiring manual scripts.

    API-based MDM onboarding allows Nightfall to automatically map the user email attribute to specific devices by syncing device inventory from your Microsoft Intune tenant using OAuth-based authentication.

    1. Log in to the Nightfall Console at

    2. Navigate to Settings - MDM Profile

    3. Click Add MDM

    4. Select Microsoft Intune from the list of supported MDM providers

    Once authentication is complete, Nightfall will automatically connect to your Intune tenant and begin syncing device data.

    Important: This API-based connection enables Nightfall to automatically map user email addresses to devices. You do not need to deploy any additional scripts for user-to-device mapping when using this method.

    Nightfall requests the following Microsoft Graph API permissions:

    • DeviceManagementManagedDevices.Read.All - Read managed device information

    • User.Read.All - Read user profiles

    • Organization.Read.All - Read basic organization details

    These are read-only permissions. Nightfall does not modify device settings or configurations.

    Once connected, Nightfall will periodically sync device inventory from Microsoft Intune. You can now proceed to deploy the Nightfall agent to your devices following the steps below.

    1. Log into the Intune Admin Center

      • Navigate to .

      • Go to: Home > Apps > All Apps > Add

    Do I still need to install a Nightfall agent on devices after API-based onboarding?

    Yes. API-based MDM onboarding enables Nightfall to map user email addresses to devices automatically. You still need to deploy the Nightfall agent to the devices using the steps above.

    What permissions does Nightfall need in Microsoft Intune?

    Nightfall requires least privilege read-only access to device inventory and user information via Microsoft Graph API. It does not modify device settings or configurations. The user email to device attribution is automatically managed with API-based MDM onboarding and no manual scripts are needed.

    Is OAuth-based authentication secure?

    Yes. Nightfall uses Microsoft's OAuth 2.0 authentication flow with encrypted connections. Credentials are securely stored and refreshed automatically.

    What happens if OAuth permissions are revoked?

    If OAuth permissions are revoked:

    • Device syncing will stop. New devices added or removed will not be reflected in Nightfall during that time.

    • Nightfall will surface an error in the console.

    • You can re-authenticate without reconfiguring policies by reconnecting from Settings → MDM Profile.

    Can I disconnect or change my MDM connection later?

    Yes. Contact Nightfall Support to disconnect or update your MDM connection from Settings → MDM Profile.

    What device types are supported with Intune?

    Microsoft Intune supports both Windows and macOS devices. Nightfall will sync inventory for both device types when connected via API-based onboarding.

    Who should I contact if onboarding fails?

    If you encounter issues:

    • Verify you have admin permissions in Microsoft Intune

    • Check the error message in the Nightfall console

    • Ensure you approved all requested OAuth permissions

    • Contact Nightfall Support for assistance

    Unknown Session Behavior in Endpoint Exfiltration Policies

    Overview

    When Personal accounts only or Corporate accounts only is enabled, Nightfall uses the browser session to decide whether an event is in-scope. On supported domains, that usually means: the Nightfall browser extension reads the signed-in email, and Nightfall compares the email domain against your Corporate Domains collection.

    Sometimes the session cannot be determined. Common causes:

    • The user is not signed in

    • The browser is in incognito / private mode

    • The Nightfall browser extension is missing, disabled, or disconnected

    • The site is loading and no logged-in identity is available yet

    Unknown session behavior controls what the policy does in that case. It only applies to supported domains (hover the violet Supported domains pill to see the list). Domains that do not support session detection continue to be monitored for all account types, regardless of this setting.

    This control appears under the session-check toggle on the policy Trigger step.

    Use this when the policy should fire only on uploads, pastes, or git pushes into a personal account.

    Use this when the policy should fire only on data that originated in a corporate account. The default is inverted: skipping unknown sessions means treating them as not corporate.

    Recommended default: skip the incident when the session cannot be determined. This is the setting shown as Treat as corporate - skip incident on personal-account destination policies. It reduces false positives when Nightfall cannot read the signed-in user, while still enforcing the policy whenever the session is known to be personal.

    The toggle copy in the console is:

    Only tracks data sent to personal account sessions for Supported domains. Remaining domains monitored for all account types.

    That means:

    1. Supported domain + known personal session → personal-account policy can create an incident

    2. Supported domain + known corporate session → personal-account policy skips

    3. Supported domain + unknown session → follows the radio option above

    4. Unsupported domain → session check is not applied; the event is evaluated like any other destination/source match

    Unsupported domains are not skipped just because unknown-session behavior is set to skip. They are monitored for all account types.

    • An Endpoint Exfiltration policy with Browser uploads to, Paste to (browser), or Git Push to

    • At least one selected collection that includes session-detection-supported domains

    • Nightfall browser extension installed, enabled, and connected on the device

    • Nightfall Agent macOS v1.2.13+ or

    After saving the policy:

    1. Confirm the session toggle is On and the expected radio option is selected

    2. Hover Supported domains and confirm the destinations you care about are listed

    3. On a test device, sign into a personal account on a supported domain and confirm an incident is created

    4. Sign into a corporate account on the same domain and confirm the personal-account policy does

    If the destination is a supported domain and the session could not be determined, the default (Treat as corporate - skip incident) intentionally does not create an incident. Check whether the user was signed in, whether the extension was connected, and whether the browser was in incognito.

    That is expected. Unknown-session behavior only applies to supported domains. Remaining domains in the collection are monitored for all account types.

    On a Personal accounts only policy, yes for supported domains: unknown and corporate sessions are out of scope. The file may still match a different policy that does not use session detection.

    The policy is configured to Create incident - mark account as unknown. Nightfall created the incident because the session could not be resolved, not because it confirmed a personal or corporate account.

    The extension typically cannot read the signed-in user in private windows. Those events are unknown-session events and follow this setting.

    Remediation for MAC OS Policies

    This document explains what admins can do when a macOS policy is violated.

    Managing Violations in Nightfall

    Nightfall admins can manage violations from within the Nightfall console. The Events page in Nightfall lists all the violations under the Exfiltration tab. End-users can get a detailed view of each exfiltration violation recorded.

    To view violations in Nightfall

    1. Navigate to Exfiltration Prevention from the left menu.

    Steps 2-6 help you filter the events to only view the alerts generated by macOS.

    1. Click Filter.

    2. Click + Add Filter.

    3. Select Integration.

    4. Select the macOS check box.

    5. Click Apply.

    6. Select Integration.

    7. Select the macOS check box.

    8. Select Integration.

    9. Select the macOS check box.

    10. Click Apply.

    You can click an event to view the details. The detail view window consists of the following tabs.

    The Summary tab consists of the following details.

    • Assets: The name of the uploaded asset(s) that was exfiltrated.

    • Policy: The name of the policy violated.

    • Device ID: The device ID of the device from which the asset was uploaded.

    • Machine Name: The physical name of the device from which the asset was uploaded.

    • App Name: The name of the cloud storage app to which the asset containing sensitive data was uploaded. This field is applicable only for uploads done to cloud storage apps.

    • Account Type: The nature of the cloud storage app to which the asset was uploaded. The account type is generally either a personal account or a business account. This field is applicable only for uploads done to cloud storage apps.

      • Account type: Personal → when a personal session is detected

    The Summary tab for a Browser upload action is as follows.

    The Summary tab for a Cloud storage app event is as follows.

    The Summary tab for a Clipboard Paste action is as follows.

    The Summary tab also displays a log of activities that occurred on the event. The Summary tab also displays a log of activities that occurred on the event. The first log entry is always the asset creation date. The subsequent logs display the actions applied to the event. You can also add comments on the Summary tab. The comments added by you can be viewed by other users as well.

    This tab displays the details of the asset that was uploaded to a domain or cloud storage app. The asset tab also displays a number in brackets. This number indicates the number of assets that were uploaded as part of the event.

    In the following image, there are two assets that were uploaded, and these four uploads together triggered the event. In such cases when there are multiple assets involved, you can use the drop-down menu to switch between assets and view the asset details.

    The Assets tab displays the following details for the Browser upload action and the Cloud Storage app action.

    • Name: The name of the asset uploaded.

    • Where: The location of the asset in the device.

    • Medium: The medium used to upload the asset. This can be a browser or cloud storage app.

    • Size: The size of the asset.

    The Assets tab also contains the Asset History section. This section displays the source or origin from where the asset was downloaded. Additionally, it also displays the destinations to which the asset was uploaded. If the source and destination details are not available, this section does not display any information. Users can use the time filter to view historic data. By default, the asset history is displayed for the last 7 days. You can click the Last 7 Days drop-down menu to view historic asset details.

    The assets tab for the copy/paste action displays the following information.

    • Content Origin: The site from which the data was copied. If Nightfall cannot find the origin, this field displays Local Machine (Unknown origin).

    • Content Destination: The location where the copied information was pasted.

    • Time of Copy: The date and time when the data was copied.

    • Time of Paste

    If the copy/pasted content contains sensitive data, the asset tab displays the sensitive data and also the text surrounding the sensitive data. The sensitive data is highlighted so that it can be recognized easily.

    The asset history section displays the timeline and the number of times data was copied and pasted.

    The device tab displays the details of the device used to upload the asset. You can view the following details on this tab.

    • Device ID: The device ID of the device from which the asset was uploaded.

    • Device Name: The name of the device from which the asset was uploaded.

    • Connection Status: The current status of the device. This can either be Connected or Disconnected. If the device is not in contact with the Nightfall agent for more than 6 hours, the connection status changes to disconnected.

    You can perform the following actions on all three tabs. These actions are present at the bottom.

    • Copy Event Link: This action copies the link of the event to the clipboard.

    • Acknowledge: This action modifies the status of the event to Acknowledged.

    • Notify Slack: This action sends a Slack notification about the event to the recipient configured in the⁣ section.

    • Notify Email: This action sends an email notification about the event to the recipient configured in the

    Configuring Integration Alerts

    Nightfall Exfiltration prevention for Salesforce allows you to configure alerts at the policy level and also at the integration level. Alerts can be sent in Salesforce by using the following alert channels.

    • Slack

    • Email

    • Webhook

    • Jira Tickets

    When you configure alert settings at the integration level, the alert settings apply to all the policies, created for the Salesforce integration. However, when you configure alert settings specifically for a policy, which is created in the Salesforce integration, the alert settings are applicable only for that specific policy.

    This document explains how to configure alerts at the integration level. To learn about how to configure alerts at the policy level, read .

    • To use Slack as an alert platform, you must first perform the required Slack configurations. You can refer to to learn more about how to configure Slack as an Alert platform.

    • To use Webhook as an alert platform, you must first perform the required Webhook configurations. You can refer to to learn more about how to configure Webhook as an Alert platform.

    • To use JIRA as an alert platform, you must have the DLP for the JIRA app installed from the . You can read more about the DLP for JIRA integration .

    You can configure alerts at the integration level once you have installed the Nightfall for Salesforce integration.

    To configure alerts at the integration level:

    1. Navigate to the Salesforce integration

    2. Scroll down to the Alerting section.

    3. You can configure one or multiple alert channels.

    1. To configure Slack as an alert channel, click + Slack channel.

    1. In the Slack alert channel field, enter the name of the Slack channel in which you wish to receive the alerts.

    2. Click Save.

    A confirmation pop-up box is displayed to confirm if the Slack channel (entered in the second step) must be used only for Salesforce integration or all the Nightfall integrations.

    1. Select No, only integration level to use the Slack channel only for Salesforce, or select Yes, please to use the selected Slack channel for all the Nightfall integrations.

    1. Click + Email.

    1. Enter the Email ID of the recipient who should receive the notifications.

    2. Click Save.

    A confirmation pop-up box is displayed to confirm if the Email ID (entered in the second step) must be used only for Salesforce integration or all the Nightfall integrations.

    1. Select No, only integration level to use the Slack channel only for Salesforce, or select Yes, please to use the selected Slack channel for all the Nightfall integrations.

    1. Click + Webhook.

    2. Enter the Webhook URL.

    3. Click Test. If the test result is not successful, check the Webhook URL.

    4. (Optional) Click Add Header to add headers.

    1. Click + Jira Ticket.

    2. Select a JIRA project from the Jira Project drop-down menu.

    3. Select an issue type from the Issue Type drop-down menu.

    4. (Optional) Add comments to be added in the JIRA ticket.

    A confirmation pop-up box is displayed to confirm if the JIRA settings configured for the Salesforce integration must be applied to all the other Nightfall integrations too.

    1. Select No, only integration level to use the configurations only for Salesforce, or select Yes, please to use the selected JIRA configurations for all the Nightfall integrations.

    When a Violation occurs, Nightfall sends a notification to the end-user whose actions triggered the violation. While notifying the end-user, Nightfall also sends a text message. You can draft the text message to be sent to the end-user. This message applies to all the policies. Click Save changes once done.

    Remediation for Windows OS Policies

    Managing Violations in Nightfall

    Nightfall admins can manage violations from within the Nightfall console. The Events page in Nightfall lists all the violations under the Exfiltration tab. End-users can get a detailed view of each exfiltration violation recorded.

    To view violations in Nightfall

    1. Navigate to Exfiltration Prevention from the left menu.

    Steps 2-6 help you filter the events to only view the alerts generated by Windows OS.

    1. Click Filter.

    2. Click + Add Filter.

    3. Select Integration.

    4. Select the Windows check box.

    5. Click Apply.

    You can click an event to view the details. The detail view window consists of the following tabs.

    The Summary tab consists of the following details.

    • Assets: The name of the uploaded asset(s) that was exfiltrated.

    • Policy: The name of the policy violated.

    • Device ID: The device ID of the device from which the file upload was performed.

    • Machine Name: The physical name of the device from which the file upload was performed.

    The Summary tab also displays a log of activities that occured on the Event. The first log entry is always the asset creation date. The subsequent logs display the actions applied on the event. You can also add comments on the Summary tab. The comments added by you can be viewed by other users as well.

    This tab displays the details of the asset (with sensitive data) that was uploaded to a domain or cloud storage app. The asset tab also displays a number in brackets. This number indicates the number of assets that were uploaded as part of the event.

    In the following image, there were two assets which were uploaded, and these four uploads together triggered the event. In such cases when there are multiple assets involved, you can use the drop-down menu to switch between assets and view the asset details.

    The Assets tab displays the following details.

    • Name: The name of the asset uploaded.

    • Where: The location of the asset in the device.

    • Medium: The medium used to upload the asset.

    • User: The username of the device owner.

    The Assets tab also contains the Asset History section. This section displays the source or origin from where the asset was downloaded. Additionally, it also displays the destinations to which the asset was uploaded. If the source and destination details are not available, this section does not display any information. Users can use the time filter to view historic data.

    The device tab displays the details of the device used to upload the asset. You can view the following details on this tab.

    • Device ID: The device ID of the device from which the asset was uploaded.

    • Device Name: The name of the device from which the asset was uploaded.

    • Connection Status: The current status of the device. This can either be Connected or Disconnected. If the device is not in contact with the Nightfall agent for more than 6 hours, the connection status changes to disconnected.

    Remediation for Salesforce Exfiltration

    This document explains what admins and end-users can do once a policy is violated.

    Admin Notification and Remediation

    When end-users violate a policy, the Nightfall admin is notified about the incident. The notification channel used to notify the Nightfall admin depends on the settings configured in the Admin Alerting section. If you have not enabled any notification channels in the Admin alerting section, Nightfall admins are not notified.

    If you have enabled the email notification in the Admin alerts section, Nightfall admins receive an email. The email is as shown in the following image.

    The Email consists of the following data.

    • Event: The event that caused the violation. For Salesforce, the event is always download of assets.

    • Who: The Email ID of the user who downloaded the file.

    • When: The date and time when the email was downloaded.

    • What: The name of the file that was downloaded.

    • Policies Violated: The name of the policy that was violated.

    • Violation Dashboard: The link to the Events screen to view the violation in detail.

    • Actions: The list of actions that the Nightfall admin can take.

    Also, a Slack message is sent if you have enabled the Slack alerts for the Nightfall admin.

    End-users receive notifications and remediation actions if the Nightfall admin has enabled these settings. The notifications are based on the settings configured in the section. The end-user remediation actions are based on the settings configured in the section.

    If you have configured the Email notification for end-users and enabled the end-user remediation, end-users can take remediation actions from the Email itself. The end-user Email is shown in the following image.

    If you have configured Slack notifications for end-user and enabled end-user remediation, end-users also get a message in the respective Slack channel configured.

    To manage violations in the Nightfall console:

    1. Click Events from the left menu.

    1. Click the Exfiltration tab.

    The Exfiltration Events page lists all the exfiltration events. To view events specific to the Salesforce integration:

    1. Click Filters and select + Add Filter.

    1. Select Integration in the Select a filter field.

    1. Select the Salesforce check box in the Select an option field.

    1. Click Apply.

    Now, only the Salesforce events are displayed.

    1. To view events with specific statuses, you can click the respective tabs.

    To view historic events, click the Time filter and select the required time period.

    You can click an event to view the details. The detail view window is as follows.

    The detail view window consists of the following tabs.

    • Summary: The Summary tab displays highlights of the event like the name of the downloaded asset, the name of the violated policy, and the email ID of the user who violated the policy.

    • Asset: The asset tab displays the details of the asset. You can view details like name of the downloaded asset, size of the downloaded asset, exfiltration action (download), owner's Salesforce ID and IP address. If there are multiple assets in a single violation, you can choose which asset's details must be displayed.

    • Actor: The actor tab displays the email ID of the Salesforce user who downloaded the asset. You can add notes on this tab which is displayed in the Admin notes section.

    The events list view displays an ellipsis menu at the extreme right corner. Admins can click this menu to take appropriate action on an exfiltration event.

    The various available actions are explained as follows.

    • Acknowledge: This action can be taken when you just wish to acknowledge that you have viewed the violation.

    • Notify Email: This action sends an email notification to the end-user who caused the violation.

    • Notify Slack: This action sends a Slack notification to the end-user who caused the violation.

    • Ignore: This action ignored the violation. You can take this action when an event is false positive.

    Once the action is implemented, the status of the event changes respectively. By default, an event can have one of the following two statuses.

    • Active: The event has been generated but no action has been taken.

    • Input Requested: A notification has been sent to the end-user requesting their response.

    Scope

    When there is a high volume of exfiltration (basically download) in your organization, the scoping capability enables you to reduce the noise from low risk events so that you can zero in on genuine exfiltration events and resolve them.

    Exfiltration (Download monitoring) can be scoped to:

    • Location: All or a specific set of drives

      • This allows you create flexible policies to monitor all or specific high-risk locations. This is a required scope for all policies.

    Install Nightfall AI Extension via Google Workspace Admin

    If an organization is utilizing Google Workspace to deploy extensions to Chrome, two options are provided to deploy the Nightfall extension and avoid conflicts on the machine.

    Nightfall typically deploys the extension through common install methods, such as:

    • macOS: macOS Profile

    • Windows: MSI and registry key entries

    However, some administrators utilize Google Workspace for extension deployment to Chrome. Here are two methods to deploy the Nightfall extension successfully using Google Workspace:

    MCP Gateway End-User FAQs

    This guide is written for employees - developers, engineers, data scientists, and other end-users - who have been invited to connect their AI tools to the Nightfall MCP Gateway.


    Model Context Protocol (MCP) is an open standard developed by Anthropic that allows AI assistants (such as Cursor, Claude, and VS Code) to securely interact with external tools, issue trackers, databases, and APIs. Instead of manually copying and pasting context into chat prompts, MCP allows your AI assistant to query data (like reading pull requests, inspecting Jira/Linear tickets, or searching internal documentation) on your behalf.

    The Nightfall MCP Gateway is a centralized, secure bridge between your AI clients and approved enterprise tools (such as GitHub, Linear, Notion, and internal APIs). Instead of having every developer generate personal API keys, configure separate local .json files, and manage individual tokens, the Gateway provides a single setup URL that securely routes and authenticates all approved tool calls through your organization's Single Sign-On (SSO).

    Your security team provisioned this gateway to empower you with AI tools while eliminating friction and security risks:

    All device types except – Exclude specific device types from enforcement

  • If no specific type is selected, all removable media types are included by default.

  • Vendor filtering

    1. Nightfall supports ~1,200 removable media vendors out of the box.

    2. You can configure vendor behavior as follows:

      1. Monitor all vendors (default)

      2. Specific vendor(s) – Apply the rule only to selected vendors

      3. All vendors except – Exclude specific vendors from enforcement

      4. Vendor matching is based on device metadata reported by the operating system.

      5. Example use cases:

        1. Allow corporate-approved encrypted USB vendors

        2. Block unknown or consumer-grade USB brands

  • Device Serial Number Filtering

    1. Serial number filters provide the most granular level of control.

      Options:

      1. Monitor all (default)

        • Specific serial numbers – Apply enforcement only to listed devices

        • All serial numbers except – Exclude specific devices from enforcement

          • Serial numbers are matched exactly as reported by the endpoint OS.

      2. Example use cases:

        • Allow a small set of approved devices

        • Exempt forensic or IT-issued USB drives

  • Filter precedence and evaluation logic

    1. When multiple device filters are configured, Nightfall evaluates them together using the following rules:

      1. Include rules are evaluated first

      2. Exclude rules override include rules

      3. If no include filters are specified, the rule defaults to include all

    2. Practical Implications

      1. If you select Specific vendors, only those vendors are eligible

      2. If you then exclude a serial number, that device will never trigger the policy

      3. If both vendor and serial filters are empty, all removable media is in scope

  • All other vendors will be blocked.
    Only listed devices will be allowed; all others blocked.
    Enforcement: Block
  • Corporate-approved devices are excluded from enforcement.

  • HTTP(S) download (macOS only; see Windows notes)

    rsync

    Sync files to a remote host (macOS only; see Windows notes)

    aws s3

    AWS CLI S3 copy / sync

    npm

    Package publish / fetch that moves files through npm

    Browser uploads to

    File sent with AirDrop

    AirDrop

    File sent over Bluetooth

    Bluetooth

    Google document

    Browser Name: The name of the browser from which the asset was uploaded.

  • Domain: The domain URL to which the asset containing sensitive data was uploaded. This field is applicable only for browser uploads. When you hover over a domain that is not added to any Collection, the list of Collections is displayed. You can choose to add the domain to an existing Collection or create a new collection and add the domain to the newly created collection. If you are already leveraging the domain collection as part of your monitoring policies, the new addition will be automatically picked up. For example, if the domain is added to a collection of sanctioned domains your policy is ignoring, future uploads to this destination will be ignored.

  • Upload Start Time: The start date and start time of the upload.

  • Upload End Time: The end date and end time of the upload.

  • Size: The size of the downloaded asset.

    OS: The operating system used on the device. This field always displays the Windows OS.
  • MAC Address: The physical MAC address of the device.

  • Last Connection: The date and time when the device was last connected.

  • Agent Version: The Nightfall agent version installed on the device.

  • OS Version: The Windows OS version used on the device.

  • To view historic events, click the Time filter, select the required time period or enter it manually by selecting the Custom Range option. Once the required time period is selected, click Apply. By default, the filter displays results for the Last 7 days. You can click Last 7 Days and choose the required historic time period.

    Summary Tab

    Assets Tab

    Asset History

    Device Tab

  • Freeze User: This action freezes the user account and logs them out of Salesforce. Users cannot login until admin unfreezes their account.

  • Revoke User Permission: This permission revokes the user's download privileges. Users can only view data in Salesforce. This action assigns the Salesforce's Minimum access profile to the user. You can learn more about this profile from this Salesforce document.

  • Unfreeze User: Once you freeze a user, this action is active. You can unfreeze a freezed user with this action.

  • End-User Notification and Remediation

    Manage Violations in Nightfall

    Taking Actions on the Events Page

    You can also take action from the event detail view page. The actions are available at the bottom of the detail view page.

    Automation
    End-User Remediation

    Policy Name: (Name the new policy)

  • Mobile Configuration File: Click the upload file button

  • From mac_bundle → profiles → select NightfallAI_Profile_with_Browser_Extensions.mobileconfig

  • (Optional) On the Policy Groups tab, select any desired groups.

  • On the Device Groups tab, select the chosen group of devices to deploy too, or choose an individual test device from the Devices tab.

  • Click Save and confirm the devices receive the profile.

  • Command Name: (Name the command)

  • Run As: root

  • Event: (Recommend Run as Repeating → Day)

    1. If scheduled as Run as Repeating, set the Days and Run at time.

  • Click + File → select mac_bundle folder → select nightfall-ai-agent-signed.pkg → click Open

  • Click the Save button

  • From the Device Groups tab, select the group (same group as Step 1).

  • 3

    Package file not found atPKG_PATH

    4

    Package installation failed

    5

    Required MDM configuration profile not installed

    6

    Health check completed with unresolved errors

    Verify the endpoint is communicating with Nightfall:
    • In the Nightfall web console, navigate to Integrations → macOS → Manage.

    • Confirm the device is listed with Agent Status = Connected.

    Asset

    Purpose

    NightfallAI_Profile_with_Browser_Extensions.mobileconfig

    Pre-authorizes macOS permissions required by the Nightfall agent (Full Disk Access, System Events, Automation) and silently installs/enables the Nightfall browser extension. Prevents user prompts and tampering with security controls.

    mdm_jumpcloud_deploy.sh

    Creates the agent configuration file, installs the .pkg if the agent is missing, and verifies services are running on every scheduled execution.

    nightfall-ai-agent-signed.pkg

    Code

    Meaning

    0

    Success (installed, repaired, or already healthy)

    1

    Not running as root

    2

    Step 1: Connect JumpCloud to Nightfall

    Step 2: Deploy the MDM Profile

    Step 3: Create the Deployment Command

    Note the file path shown after upload. If it differs from the default /tmp/nightfall-ai-agent-signed.pkg, update PKG_PATH in the script to match.

    Exit codes

    Step 4: Monitor and Verify

    Uninstalling

    Signed installer package for the Nightfall AI Endpoint Agent.

    Credentials not populated (script still contains placeholders)

    Create incident - mark account as unknown

    Creates an incident and tags the account type as Unknown

    Visibility into session-detection failures without asserting personal vs. corporate

    Create incident - mark account as unknown

    Creates an incident and tags the account type as Unknown

    Visibility into session-detection failures on the source side

    Windows v1.4.35+

    Audit trail of session-detection gaps (extension down, incognito)

    Personal or Corporate accounts only

    Create incident - mark account as unknown

    Track data that left a corporate session, any destination

    Corporate accounts only

    Treat as personal - skip incident (default)

    not
    fire
  • Repeat in incognito (or with the extension disabled) and confirm the unknown-session option behaves as configured

  • On an unsupported domain in the same collection, confirm the event is still monitored (all account types)

  • Option

    What Nightfall does

    When to use it

    Treat as corporate - skip incident (recommended default)

    Treats the unknown session as corporate. A personal-account-only policy does not create an incident.

    Production policies where you want to avoid false positives from extension gaps, incognito, or unsigned-in tabs

    Treat as personal - create incident

    Treats the unknown session as personal and creates an incident

    Option

    What Nightfall does

    When to use it

    Treat as personal - skip incident (recommended default)

    Treats the unknown session as personal. A corporate-account-only policy does not create an incident.

    Production source-scoped policies where you want to avoid false positives

    Treat as corporate - create incident

    Treats the unknown session as corporate and creates an incident

    Policy goal

    Session toggle

    Unknown-session setting

    Block uploads to personal Drive / Gmail / ChatGPT with low noise

    Personal accounts only

    Treat as corporate - skip incident

    Departing-user or watchlist: do not miss personal-account egress

    Personal accounts only

    When session cannot be determined

    Personal accounts only (destination)

    Corporate accounts only (source)

    How it works with supported vs. remaining domains

    Prerequisites

    Recommended configurations

    Validation checklist

    Frequently Asked Questions (FAQ)

    Why did a personal-account policy not fire?

    Why am I still seeing incidents on domains that do not support session detection?

    Does skipping unknown sessions mean corporate uploads are allowed?

    What does Account Type = Unknown mean on an incident?

    Does this work in incognito?

    High-risk or departing-user policies where missing a personal-account transfer is worse than extra noise

    Fail-closed source policies (for example, departing-user watchlists)

    Treat as personal - create incident, or mark as unknown

    No Plaintext API Tokens on Laptops: Personal API keys and long-lived tokens no longer need to be generated or stored in local configuration files.

  • Streamlined Onboarding: You get immediate access to all approved development tools with a single URL and one-click SSO login.

  • Safe Guardrails: Destructive operations (such as deleting repositories or dropping database tables) are blocked at the gateway, enabling safe, high-speed read and query capabilities.

  • Nightfall AI is your organization's enterprise AI security and data security partner. Nightfall provides the zero-trust token brokering, granular permission scoping, and audit infrastructure powering the MCP Gateway.


    The MCP Gateway supports any client, IDE, or agent framework that supports standard Streamable HTTP / Server-Sent Events (SSE) and OAuth MCP connections, including:

    • Cursor IDE (Composer, Chat & Agent)

    • Claude Desktop & Claude Code CLI

    • VS Code (via MCP extensions)

    • Windsurf IDE (Cascade)

    • JetBrains IDEs (via MCP plugins)

    • Claude.ai / ChatGPT Custom Connectors (Enterprise / Team workspaces)

    • Custom AI Scripts & Autonomous Agents (LangChain, LlamaIndex, AutoGen, custom Python/Node agents)

    Setup takes less than 60 seconds:

    1. Click the activation link in your invite email and log in via your company SSO.

    2. Copy your unique Tenant MCP Endpoint URL from the Setup tab.

    3. Paste the URL into your AI client's MCP configuration settings.


    No. The gateway brokers credentials centrally. For OAuth-supported tools (like GitHub or Linear), you simply click Connect in the gateway once to authenticate via SSO. You never have to generate, copy, paste, or rotate personal access tokens.

    No. Stored tokens and OAuth secrets are encrypted at rest and injected directly into upstream tool calls. Administrators can see connection status (e.g., Connected or Token Expired), but they cannot view secrets, passwords, or personal keys.

    No. Nightfall does not train AI models on your code, prompts, or tool data. The gateway functions strictly as an enterprise proxy. Tool calls and payloads are logged solely for your organization's security audit trail (with strict data retention limits).


    No. The gateway uses high-throughput, low-latency streaming HTTP connections. Tool discovery and invocations typically execute with sub-millisecond proxy overhead, ensuring your AI assistant responds instantaneously.

    If a specific backend server encounters downtime, the gateway immediately surfaces the vendor's error message and short-circuits repeated failing calls. All other enabled tools and servers continue operating without disruption.

    Yes. On the Enabled Servers page in your Gateway dashboard, you can toggle Enabled for me on individual tools. If there are certain tools you prefer not to load into your assistant's context window, disabling them removes them exclusively from your client.


    1. Check SSO Authorization: Ensure you have completed the one-time browser consent (Approve) when connecting your client to the gateway.

    2. Verify Upstream Connection: If using a server like GitHub, verify that your account shows Connected under the Enabled Servers tab in the Gateway dashboard.

    3. Check Client URL: Confirm that the endpoint URL in your client configuration matches the exact URL provided in your Setup tab.

    • Reach out to your internal IT/Security team or post in your company's dedicated help channel

    • For platform documentation and support, visit help.nightfall.ai or contact support@nightfall.ai.

    MCP Gateway End-User FAQs

    1. Getting Started & Overview

    What is Model Context Protocol (MCP)?

    What is the Nightfall MCP Gateway?

    Why did my Security / IT Team set this up for me?

    Who is Nightfall AI?

    2. Supported Clients & Environments

    Which AI clients, IDEs, and tools are supported?

    How long does setup take?

    3. Authentication, Tokens & Privacy

    Do I need to create or manage personal API tokens for GitHub, Linear, etc.?

    Can administrators see my passwords or private credentials?

    Does the MCP Gateway or Nightfall read or train on my code and prompts?

    4. Performance & Daily Workflow

    Will the MCP Gateway slow down my AI assistant?

    What happens if an upstream vendor (like GitHub or Linear) experiences an outage?

    Can I customize or hide specific tools in my IDE?

    5. Troubleshooting & Support

    Why does my AI client say "Tool not found" or fail to connect?

    Where can I get help or request access to new MCP servers?

    Vivaldi

    Arc

  • Brave

  • Vivaldi

  • Perplexity Comet

  • ChatGPT Atlas

  • Windows - The following browsers are supported on Windows:

    1. Chrome

    2. Edge

    3. Firefox

    4. Arc

    5. Brave

    6. Vivaldi

    7. Not supported on Windows:

      1. ChatGPT Atlas (not available on Windows)

      2. Perplexity Comet (Windows version does not allow installation of browser extensions)

  • Grant System Permissions

    Grant Full Disk Access

    Grant Accessibility Permissions

    Reboot The Agent

    Grant Browser Permissions

    At this stage, your manual installation is complete. Your machines should start showing up on you Nightfall AI management console under https://app.nightfall.ai/endpoint

    Supported Browsers

    Uninstalling the Nightfall AI Agent

    Install Nightfall AI Agent for Mac
    status code if successful.

    An example of Webhook request is as follows.

    This is part of alert event consumption and can be ignored.

    {
      "service": "nightfall",
      "test": true,
      "timestamp": "2024-03-07T23:18:39Z"
    }
    sudo ./mdm_pre_installation_script.sh
    mdm_nightfall_ai_agent_uninstall.sh
    {
      "service": "nightfall",
      "test": true,
      "timestamp": "2024-03-07T23:18:39Z"
    }
    1. (Optional) To add more Domains to the Collection, you can either click + Add Domain and enter the domain manually, or click Upload txt and upload another text file containing domains.

    2. (Optional) Click the delete icon to remove a domain from the Collection.

    3. Click Save Changes.

    All the domains must be separated by a comma. The file must have a .txt extension.

    Creating Policy
    Remediation for MAC OS Policies
    Remediation for Windows OS Policies

    Important

    When you add a domain, the sub domain is not included automatically. For instance, if you add abcd.com, docs.abcd.com is not included. To include subdomains, you must enter the full URL containing the subdomain. If you have multiple subdomains, you can use the asterisk wildcard (*) and enter the domain as *.abcd.com

    Unpack the contents of the downloaded file.

  • (Optional) In the downloaded folder, locate the README.md under /Profiles to learn about the various MDM profiles available.

  • Upload and save provided config profile.

    • Policy name: “Nightfall AI Agent Profile”

    • Policy description: “Nightfall AI Agent profile”

    • Platform: “macOS”

    • Drop or select NightfallAI_Profile_with_Browser_Extensions.mobileconfig.

    • Click Save & continue.

  • Navigate to https://app.rippling.com/it/hardware/configurations?section=everything-else. Click the three-dot context menu located on the far right of the new profile. Deploy from

    • Select all employees or specific target devices.

    • Click Save to deploy the software.

  • 2

    Step 2 - Configure & Deploy Software Package

    Step 2.1 - Create & Configure the Software Package

    1. Navigate to: https://app.rippling.com/hardware/software

    2. Click Upload Software on the right of the page.

      • Name: “Nightfall Endpoint DLP Agent <version>”

        • <version> is the version of the package your received from Nightfall.

      • Operating System: “macOS”

      • Category: “My Uploads” (Default)

      • Description: “Nightfall Endpoint DLP Agent”.

      • Upload Installer File: drop or select the provided nightfall-ai-agent-signed.pkg file.

      • Install-check script: provided in your package as mdm_pre_install_check_script.sh

      • Pre-install script: provided in your package as mdm_pre_installation_script.sh

      • Click Submit.

      • Click Add on the newly created Software Item.

      • Click Finished Selecting.

    1. Search or scroll to the newly added Software Item matching the name you used in "Step 2.1".

    2. Click Edit. NOTE: If the Software Item was just recently created it may take a few minutes to leave from the "Pending" status.

    3. Select all employees or specific target devices.

    4. Click Save.

    The Nightfall Endpoint DLP Agent will now deploy to all selected target devices. This may take up to 72 hours and is dependent on the endpoint devices being turned on, connected, and pre-requisite profiles deployed.

    mdm_pre_installation_script.sh

    The script is used by MDMs to ensure that a macOS machine is in a clean state before installing the Nightfall Agent. It wipes any existing Nightfall installation and prepares a clean environment for a new install, including:

    • Loading API keys

    • Rebuilding folders

    • Resetting launch daemons

    NightfallAI_Profile_with_Browser_Extension.mobileconfig

    This profile is designed to pre-authorize and enable what the Nightfall Endpoint Agent requires on a macOS machine without needing user prompts.

    • Silently installs/enables the Nightfall browser extension

    • Allows the extension to run without prompts

    • Authorizes required permissions (content inspection, file uploads, scanning)

    • Grants macOS Privacy Permissions required by Nightfall:

      • Full Disk Access (FDA)

      • System Events/Automation Permissions

      • Application Control Permissions

    • Configures the payloads for browser + system integration

    • Prevents users from tampering with the security controls

    IMPORTANT: Both Steps 1 and 2 require defining the devices to deploy to. This means that the "mobileconfig" profile requires the devices to be selected to assign to, and the agent requires selecting the devices to assign to as well. Ideally, both lists should match.

    Prerequisites

    To install the Nightfall agent in stealth mode (without notifying the end-user), see Install Nightfall AI Agent for Mac.

    Step 1 - Create & Deploy Profiles

    Upgrading to a New Version

    Create & Configure the Software Package
    https://app.nightfall.ai/endpoint
    https://app.rippling.com/it/hardware/configurations?section=macos
    steps
    these steps

    Click Microsoft Intune Login

  • You will be redirected to Microsoft's login page

  • Authenticate with your Microsoft admin account

  • Review and approve the requested permissions:

    • Read device information

    • Read user profiles

    • Access basic organization information

  • Click Accept to grant permissions

  • Select App Type
    • Under App type, choose: Line-of-business app

  • Add App Package

    • In the App package file section, click Select app package file.

    • Upload the NightfallAgent.msi file.

  • Configure App Information

    • Fill in the Name, Description, and other fields as desired.

    • Click Next.

  • Specify Install Command Line

    • In the Command-line arguments field, enter:

      API_KEY=your_api_key_here COMPANY_ID=your_company_id_here INSTALL_NF_DRIVER=1
      
      ⚠️ Important:
      - Do NOT include msiexec /i NightfallAgent.msi — This is handled automatically.
      - Do NOT wrap the values in double quotes.
      - Make sure to include INSTALL_NF_DRIVER=1.
      - If INSTALL_NF_DRIVER=1 is not included you may receive a Driver Error.
      
      ✅ Correct Example: API_KEY=ufapuhaefaw COMPANY_ID=qohuifpqrwf
  • Assign the App

    • Assign the app to the appropriate device groups or users.

    • Click Next and complete the wizard.

      IMPORTANT: Add the preferred group under "Available for enrolled devices"

  • Monitor Deployment

    • Go to Monitor > App Install Status to confirm successful deployment.

  • Verify Installation on a target/test machine

    1. Once installation shows as successfull by Intune, check if the agent is running:

      1. Open Task Manager (Ctrl + Shift + Esc).

      2. Look for the Nightfall Agent & NightfallUI processes under the Processes tab.

    2. Confirm the Nightfall agent is configured to your Nightfall tenant

      1. On the windows machine:

        1. Double-click the Nightfall agent icon in the status bar.

        2. The displayed UUID should match your Nightfall tenant UUID located under

  • Step 1: Connect Microsoft Intune to Nightfall (API-based MDM Onboarding)

    Connecting Microsoft Intune to Nightfall

    Permissions Required

    After Connection

    Step 2: Deployment Steps

    Frequently Asked Questions (FAQs)

    https://app.nightfall.ai/endpoint
    https://app.nightfall.ai
    Microsoft Intune Admin Center

    Browser Name: The name of the browser from which the asset was uploaded. This field is applicable only for those events that were triggered by the browser upload action.

  • Domain: The domain URL to which the asset containing sensitive data was uploaded. This field is applicable only for browser uploads. When you hover over a domain that is not added to any Collection, you can choose to add it to an existing Collection or create a new one. If you are already leveraging the domain collection as part of your monitoring policies, the new addition will be automatically picked up. For example, if the domain is added to a collection of sanctioned domains your policy is ignoring, future uploads to this destination will be ignored.

  • Account type: Corporate → when corporate session is detected
  • Empty → when session differentiation is not applicable or unavailable

  • Upload Start Time: The start date and start time of the upload.

  • Upload End Time: The end date and end time of the upload.

  • : The date and time when the data was pasted.
    OS: The operating system used on the device.
  • MAC Address: The physical MAC address of the device.

  • Last Connection: The date and time when the device was last connected.

  • Agent Version: The Nightfall agent version installed on the device.

  • OS Version: The MAC OS version used on the device.

  • section.
  • Resolve: This action resolves the event and modifies the status to resolved.

  • Ignore: This action ignores the event and modifies the status to ignored.

  • To view historic events, click the Time filter, select the required time period or enter it manually by selecting the Custom Range option. Once the required time period is selected, click Apply. By default, the filter displays results for the Last 7 days. You can click Last 7 Days and choose the required historic time period.

    Summary Tab

    Assets Tab

    If you have configured in the Scope section of the policy and if the asset contains sensitive data, the asset tab also displays a preview of the sensitive data and the detectors violated. Additionally, you can also find a new field called Sensitive Data that displays the name of the detector(s) violated.

    Asset History

    Asset Tab for Clipboard Paste Action

    Device Tab

    Important

    If a user uploads the same file to multiple browser destinations (say 3), 3 exfiltration events are generated. However, if you uploads multiple files to the same destination, only a single event is generated.

    If multiple violations are recorded within a span of five minutes, all the violations are clubbed under a single exfiltration event. The Assets Tab of this event displays the details of each asset.

    However, if you upload multiple files to different browser domains or upload multiple files to different cloud storage apps, within a span of five minutes, a separate exfiltration event is generated for each of the uploaded file.

    Actions

    Advanced Settings
    Advanced Settings

    Click Save.

    Click Save changes.

    Prerequisites

    Configure Alerts at the Integration Level

    Configuring Slack as an Alert Channel

    Configuring Email as an Alert Channel

    Configuring Webhook as an Alert Channel

    When you configure alerts to a Webhook, Nightfall AI sends occasional posts to:

    • To validate that the Webhook is properly configured before the policy is saved.

    • Periodically thereafter to ensure that the Webhook is still valid.

    The response to the test Webhooks is 200 status code if successful.

    An example of Webhook request is as follows.

    This is part of alert event consumption and can be ignored.

    Configuring JIRA as an Alert Channel

    Configure End-User Notification

    this document
    this document
    this document
    Atlassian Marketplace
    here
    User or User Group (Actor): Any or a specific set of users or user groups
    • This allows you to create custom policies for specific high-risk individuals or user groups. As such, you can create policies to monitor download activity by a disgruntled employee or departing employees. This can be set in combination to other scoping capabilities.

  • Permissions: Public, Organization or Restricted

    • This allows you to tailor your policies to drives or files with specific access restrictions. This can be set in combination to other scoping capabilities.

  • Detection rules: Any or a specific set of sensitive data protection detection rules

    • You can reuse any of detection rules you've already created or create new ones. This helps focus your detection on files which have associated sensitive data violations identified by your sensitive data scanning product. This can be set in combination to other scoping capabilities.

  • The Scope stage consists of two main sections.

    • Drive Selection: This section allows you to include various files and drives for monitoring. In this section, you can select the different types of drives to be monitored.

    • Add Filters: This section allows you to scrutinize your policy scope at more granular levels. While the Drive selection section allows you to select the whole drive to be monitored, this section provides you more granular level filters. You can select specific files within the selected drives for monitoring.

    The Drive Selection section allows you to select various drives for monitoring. You can select either User Drives or Shared Drives to be monitored by Nightfall for exfiltration.

    This section allows you to select various drives in your Google Drive to be monitored. There are two options in this section. You can either choose to scan the User drives, Shared drives, or both.

    • User Drives: The User Drives is the personal drive of the user. The files in this drive are visible only to the owner of the file and other users to whom the owner has granted access. User Drive is commonly known as My Drive in Google Drive. To monitor a User Drive, you must select the User drives check box as shown in the following image.

    • Shared Drives: Shared drives are common storage locations accessed by all the users in your Workspace. To select this option, you must select the Shared drives check box.

    The following image displays the scenarios when you select the Shared Drives check box.

    If you select the All Drives, except for option, you must also select the shared drives which must be excluded from monitoring.

    Similarly, if you select the Specific Drive(s) option, you must also select the specific shared drives which must be monitored.

    The filters section provides you the flexibility to include and exclude users at a granular level.

    For instance, in the previous section, irrespective of whether you selected Shared Drive, User Drive, or specific User Drives, you ended up selecting one or a set of Drives for monitoring.

    Once you select the Drives to monitor, in this section, you can overlay additional filters to further scope your monitoring. Nightfall provides the following additional filters:

    Internal Users

    External Users

    Internal Groups

    External Groups

    Permission

    Detection Rules

    Labels

    • Specific User(s): Choose this option to monitor one or a specific set of internal users. Once you choose this option, Nightfall populates the list of users from the synced IdPs in Directory Sync. You must select the required users.

    • All Users, except for: Choose this option to exclude specific individuals from your monitoring policy. Once you choose this option, Nightfall populates the list of users from the synced IdPs in Directory Sync. You must select the required users.

    • Specific User(s): Choose this option to monitor one or a specific set of external users. Once you choose this option, you must manually enter the email ID(s) of the external users and hit the enter key.

    • All Users, except for: Choose this option to exclude specific external users, from being monitored. Once you choose this option, you must manually enter the email ID(s) of the external users and hit the enter key.

    • Specific Group(s): Choose this option to monitor one specific or a set of internal groups. Once you choose this option, Nightfall populates the list of internal groups from the synced IdPs in Directory Sync. You must select at least one group.

    • All Groups, except for: Choose this option to exclude one specific, or a set of, internal groups from being monitored. Once you choose this option, Nightfall populates the list of internal groups from the synced IdPs in Directory Sync. You must select the required users.

    • Specific Group(s): Choose this option if you have external user groups defined in your IdP and would like to monitor one specific or a set of external groups. Once you choose this option, you must select at least one external user group to monitor then hit the enter key.

    • All Groups, except for: Choose this option if you have external user groups defined in your IdP and would like to exclude one or more external groups from being monitored. Once you choose this option, you must select at least one external user group to monitor then hit the enter key.

    Before understanding the Permission filters, we must understand Google's General Access feature.

    The general access feature in Google Workspace consists of three types of access, which are as follows.

    • Restricted: Files with this permission can only be accessed by users who have been granted access.

    • Target Audience: Files with this permission can be accessed by the users of the selected target audience group. There is a default target audience that gets created when the Google workspace is provisioned. This target audience has the same name as provisioned in the Google Workspace and includes all members of the organization. You can refer to this Google document to learn more about the target audiences.

    • Anyone with the Link: Files with this permission can be accessed by any user who has the file link.

    Nightfall also provides inclusion and exclusion of files in policy scope that resembles the General Access sharing principle in Google Workspace. The Nightfall General Access permission options are as follows.

    • Restricted: Choose this option to scope monitoring to files with restricted access.

    • Shared with target audiences: Choose this option to scope monitoring to files shared with target audiences within your Google Workspace environment.

    • Anyone with the link: Choose this option to scope monitoring to files shared with anyone with a link.

    The Nightfall Detection Rules consist of a single or multiple detectors. You can use this filter to either include all the detection rules or include only specific detection rules. Note that upon a download event, Nightfall will check if the downloaded file has been previously scanned, and results matched at least one of the selected detection rules (i.e. The file is not rescanned upon download).

    • All: If you select this option, all the detection rules are included.

    • Specific Detection Rule(s): If you select this option, you must also select the required detection rules. Nightfall scans your files only for the selected detection rules.

    A Label is a metadata that you can create to help users organize, find, and apply policy to files in Google Drive. To learn more about Google Drive Labels, refer to this Google document.

    You can choose one of the following options.

    • Specific Label(s): You must choose this option to monitor only those files that contain the selected Labels. Once you choose this option, you must select the Labels. Nightfall only monitors those files that have the selected labels.

    • All Labels, except for: You must choose this option to exclude the monitoring of files that contain the selected Labels. Once you choose this option, you must select the Labels. Nightfall does not monitor the files that contain the selected labels.

    Configuring the Drive Selection Section

    Select Drives

    IMPORTANT

    If you choose to monitor the User drives, all the User drives in your Google domain are selected for monitoring. You do not have the option to choose specific User drives for monitoring.

    IMPORTANT

    If you choose to monitor the Shared Drives, you can select whether to monitor all the Shared drives or only specific shared drives. Nightfall provides the following options.

    • If you select the All Drives option, all the Shared drives in your Google Workspace are selected for monitoring.

    Configuring Add Filter Section

    Internal Users

    Note

    If you have not configured the feature, the users list is populated from the . As a result, you can see the Google Drive icon before the user name. However, if you have set up Directory sync, the users list is fetched from the IdP used for the configuration. In the above image, the users list is populated from the Microsoft Azure IdP and hence you can see the Azure icon before the users’ names.

    Important

    For exclusions, Nightfall only checks the file ownership. For inclusions, Nightfall checks both file ownership and shared access. This rule is applicable to all the filters.

    External Users

    Internal Groups

    External Groups

    Permission

    General Access

    Detection Rules

    Labels

    Before utilizing filters for Labels, you must as per instructions and create labels in your Google Drive.

    Policy Precedence (Preferred)

  • Policy MergeList

  • Within Google Workspace, set the Policy Precedence as Machine Cloud.

    This is the preferred method of installing Nightfall, due to the control of the app deployment being handled and secured by Google Workspace cloud as opposed to the individual machine.

    This option will include the following changes:

    • Changing Policy Precedence to Machine Cloud.

    • Adding the Nightfall DLP for Browsers app to Google Workspace.

    • Adjusting the Nightfall extension to Force Install.

    • Enabling the extension when in Incognito mode.

    1. From within the Google Workspace Admin console, adjust the Policy Precedence.

      1. Click on Chrome Browser > Settings > Select the OU

      2. Navigate down to Setting sources

      3. Confirm Policy precedence is set to Machine Cloud first.

        1. If yes, leave it as-is.

        2. If not, adjust it to Machine Cloud.

          1. Click into the Policy precedence setting.

          2. Click on the "Configuration" flow under Inheritance. It may look like this:

    2. From within the Google Workspace Admin console, add the Nightfall DLP extension to Force Install so it automatically deploys.

      1. Navigate to Devices > Chrome > Apps & Extensions

      2. Select the appropriate OU.

      3. Identify the Nightfall DLP for Browsers app

    Within Google Workspace, set the Policy MergeList to merge policies from both sources - Cloud and Machine.

    This is a last resort method to use if you do not want to adjust the Policy Precedence, and instead accept policies from both Google Workspace and direct from the machine (e.g., MDM Profile).

    1. From within the Google Workspace Admin console, navigate to Devices > Chrome > Settings.

    2. Under Setting sources, select Policy mergelist

    3. Select the specific Organizational Unit for your deployment scope.

    4. Under Configuration, specify individually the two policies, ExtensionInstallForceList and ExtensionSettings (one per line).

    5. Confirm the policy is applied in: chrome://policy

    6. Check that the Source shows as Merged for the policies you want merged.

    IMPORTANT: Nightfall does not know your environment. Each organization has to decide for themselves what method of deployment to utilize in their own environment.

    Option 1: Policy Precedence (Preferred)

    NOTE: If the Policy Precedence is NOT changed to Machine Cloud, and Google Workspace is being utilized for extension deployment, Nightfall's profile that is deployed via MDM will override any conflicts that occur with Google Workspace. This is why it is being recommended to change Policy Precedence to Machine Cloud and control extension deployment via Google Workspace.

    Only proceed if this is appropriate for your environment.

    Option 2: Policy MergeList

    IMPORTANT: This takes control away from Google Workspace and allows both Cloud and Machine policies of equal importance to coexist. It is recommended to use Option 1, instead of Option 2, in most scenarios.

    Nightfall macOS Agent Deployment: Iru (Kandji) MDM

    This document explains the process of installing Nightfall AI agent using the Kandji MDM.

    The Kandji MDM has now been rebranded as Iru.

    Prerequisites

    • You are a Systems Administrator in Nightfall

    • You have administrator access to Kandji

    • The Kandji APN is set.

    • The target macOS devices are onboarded.

    • On your Nightfall console, navigate to and click the Download Package button on the top right corner of the page. Click Download Package for macOS and unpack the contents of the downloaded file.

    This step enables automated mapping of user profiles to devices without requiring manual scripts.

    API-based MDM onboarding allows Nightfall to automatically map the user email attribute to specific devices by syncing device inventory from your Iru (Kandji) instance.

    To connect Iru (Kandji) to Nightfall, you'll need:

    • Iru (Kandji) Organization API URL (for example: yourcompany.api.kandji.io)

    • API Token with read access to device inventory

    1. Log in to your Iru (Kandji) instance

    2. Navigate to Settings > Access > API Token

    3. Click Generate New Token

    4. Configure the following:

    Your Kandji Organization API URL follows this format: yourcompany.api.kandji.io

    Where yourcompany is your organization's subdomain in Kandji.

    You can find this in your Kandji admin panel:

    1. Log in to Kandji

    2. Look at your browser URL (e.g., https://yourcompany.kandji.io)

    3. Your API URL is: yourcompany.api.kandji.io

    1. Log in to the Nightfall Console at

    2. Navigate to Settings → MDM Profile

    3. Click Add MDM

    4. Select Kandji from the list of supported MDM providers

    Nightfall will validate the credentials and begin syncing device information automatically.

    Important: This API-based connection enables Nightfall to automatically map user email addresses to devices. You do not need to deploy any additional scripts for user-to-device mapping when using this method.

    Once connected, Nightfall will periodically sync device inventory from Kandji. You can now proceed to deploy the Nightfall agent to your devices following the steps below.

    1. Navigate to

    2. Click New Blueprint on the top right corner.

    3. Click New Blueprint on the pop up menu.

    4. Enter a name for the blueprint in the Blueprint name field.

    In this section, we create a custom profile for each of the profiles provided in the Nightfall endpoint payload and assign them to the blueprint you have created in the previous section.

    1. In the downloaded folder, locate the README.md under /Profiles to learn about the various MDM profiles available.

      1. Choose the NightfallAI_Profile_with_Browser_Extensions.mobileconfig.

    2. Navigate to .

      a. Click Add new.

    b. Select Custom Profile and click Add & Configure on the pop-up window.

    c. Add Title, Select Blueprint, and finally drag and drop the .mobileconfig file.

    d. Click Save.

    In this section, we will create a custom app item for Nightfall Endpoint Agent.

    1. Navigate to .

    2. Click Add New.

    1. Click Custom App

    2. Click Add & Configure on the pop-up window.

    a. Add Title, Select the Blueprint you previously created.

    b. Select the Audit and enforce option.

    c. Paste the content of mdm_kandji_audit_script into the Audit Script text box.

    d. Choose the Installer Package option.

    e. Add Preinstall Script & Upload the installer package.

    I. Paste the content of mdm_pre_installation_script into the Pre-install Script text box.

    II. Upload the installer package

    i. Drag and drop or click to upload the provided nightfall-ai-agent_v*.*.*.pkg file

    1. Save the change and wait for the changes to get deployed on the node machine.

    Do I still need to install a Nightfall agent on devices after API-based onboarding?

    Yes. API-based MDM onboarding enables Nightfall to map user email addresses to devices automatically. You still need to deploy the Nightfall agent to the devices using the steps above.

    What permissions does Nightfall need in Kandji?

    Nightfall requires least privilege access to device inventory. It does not modify device settings or configurations. The user email to device attribution is automatically managed with API-based MDM onboarding and no manual scripts are needed.

    What happens if API credentials expire or are revoked?

    If credentials expire or are revoked:

    • Device syncing will stop. New devices added or removed will not be reflected in Nightfall during that time.

    • Nightfall will surface an error in the console.

    • You can re-authenticate or update credentials without reconfiguring policies.

    Can I disconnect or change my MDM connection later?

    Yes. Contact Nightfall Support to disconnect or update your MDM connection from Settings → MDM Profile.

    Who should I contact if onboarding fails?

    If you encounter issues:

    • Verify API credentials and permissions in Kandji

    • Check the error message in the Nightfall console

    • Contact Nightfall Support for assistance

    Nightfall Windows Agent Deployment: JumpCloud MDM

    Instructions on how to install the Nightfall agent on Microsoft Windows using the JumpCloud MDM.

    Before beginning the install, make sure you have the following:

    • A JumpCloud Admin / MDM environment ready, and the JumpCloud Agent already configured or in process of being configured for your Windows devices.

    • The Nightfall Windows Agent (MSI) and associated parameters (API_KEY / COMPANY_ID) as from the page → Download Packages.

    Temporary Exception Requests - User Justification and Override Workflow

    When Nightfall detects a policy violation and blocks a data transfer, it can optionally prompt the user to provide a business justification before the action is logged. This gives employees a chance to explain their intent while ensuring security teams have full context.

    Once a justification is submitted, it appears in the Nightfall console for security admin review, and admins can approve it if warranted.

    When a blocked action triggers the justification workflow, a floating panel appears on screen from the Nightfall AI user agent.

    Panel contents:

    • Header: Nightfall AI branding + timestamp of the event

    Step 2.2 - Deploy the Nightfall Endpoint DLP Agent

    On the Nightfall console:

    1. The newly configured device should be listed under https://app.nightfall.ai/endpoint.

    https://app.nightfall.ai/settings/

    Name: Nightfall Integration

  • Permissions: Select Read for:

    • Device List

    • Device Details

    • User List

  • Click Generate Token

  • Copy the API Token - you'll need this in the next step and it will only be shown once

  • Enter the following information:

    • Kandji Organization API URL: Your Kandji API URL (e.g., yourcompany.api.kandji.io)

    • API Token: The API Token you created in Kandji

  • Click Connect

  • Enter a description for the blueprint in the Blueprint description field.

  • Click Create Blueprint.

  • mdm_pre_installation_script.sh

    The script is used by MDMs to ensure that a macOS machine is in a clean state before installing the Nightfall Agent. It wipes any existing Nightfall installation and prepares a clean environment for a new install, including:

    • Loading API keys

    • Rebuilding folders

    • Resetting launch daemons

    NightfallAI_Profile_with_Browser_Extension.mobileconfig

    This profile is designed to pre-authorize and enable what the Nightfall Endpoint Agent requires on a macOS machine without needing user prompts.

    • Silently installs/enables the Nightfall browser extension

    • Allows the extension to run without prompts

    • Authorizes required permissions (content inspection, file uploads, scanning)

    • Grants macOS Privacy Permissions required by Nightfall:

      • Full Disk Access (FDA)

      • System Events/Automation Permissions

      • Application Control Permissions

    • Configures the payloads for browser + system integration

    • Prevents users from tampering with the security controls

    To install the Nightfall agent in stealth mode (without notifying the end-user), see Install Nightfall AI Agent for Mac.

    Connect Iru (Kandji) to Nightfall (API-based MDM Onboarding)

    What You'll Need from Iru (Kandji)

    Creating API Token in Iru (Kandji)

    Important: Store the API token securely. It will not be displayed again after you close the dialog.

    Finding Your Iru (Kandji) Organization API URL

    Connecting Iru (Kandji) to Nightfall

    After Connection

    Create a Blueprint

    Create Custom Profiles

    Create a Custom App

    Frequently Asked Questions (FAQs)

    https://app.nightfall.ai/endpoint
    https://app.nightfall.ai
    https://<your-company-name>.kandji.io/blueprints
    https://<your-company-name>.kandji.io/library
    https://<your-company-name>.kandji.io/library

    If you select the All Drives, except for option, you can exclude some shared drives from being monitored.

  • If you select the Specific Shared Drives option, you get the option to choose specific Shared drives for monitoring.

  • Directory Sync
    Google Drive integration setup
    enable Google Drive Labels
    {
      "service": "nightfall",
      "test": true,
      "timestamp": "2024-03-07T23:18:39Z"
    }
  • Select Machine Cloud as the primary configuration.

  • Click Save

  • If the Nightfall DLP for Browsers app is not present, then install it from the Chrome Web Store.

    • Click the yellow circle with the + symbol at the bottom right.

    • Select "Chrome Web Store"

      • Name: Nightfall DLP for Browsers

      • ID: jgmgecncmjklkabkejnjfgfkglapfgek

  • Once the Nightfall DLP for Browsers app is visible, select it.

  • Change Allow install to Force install

  • Toggle on Extension is mandatory for Incognito

  • Click Save

  • Internal device group or OU targeting plan within JumpCloud (for example: Windows corporate laptops, desktops, etc).
  • Communication to end-users (if needed) and any documentation of maintenance windows or reboots.

  • Valid credentials / admin rights on target Windows devices (or ability via MDM / script to install silently).


    1. Log in to app.nightfall.ai and navigate to Settings > MDM Profile.

    2. Select JumpCloud from the list of supported MDM providers.

    3. Complete the OAuth flow to grant Nightfall read-only access to your JumpCloud device and user directory. This maps JumpCloud user identities to devices in the Nightfall console automatically.

    Use JumpCloud’s Commands/Policies feature to deploy the Nightfall Agent silently to the target Windows device group:

    1. In JumpCloud Admin Portal: Device Management → Commands → Commands tab → click + Command (or use Policies if available)

      • Type: Windows

      • Check "Windows PowerShell"

      • Command: Copy/paste in the command shown below.

        • Replace the File Destination ($msi value) as needed or leave as-is.

        • Replace the API_KEY and COMPANY_ID with what is in the Nightfall console.

          • From the page > click Download Package > copy the API_KEY and COMPANY_ID from the Windows command.

      • Command Name: (e.g., “Install Nightfall Agent Windows”)

    2. Under Files > click + File > upload the NightfallAgent.msi

    3. Copy the File Destination where the MSI would be copied onto the enrolled devices by jumpcloud mdm.

    4. Choose a Device Group

      1. Navigate to the Device Groups tab.

      2. Check the group to use for deployment.

    5. Click "Save".

    6. Click "Run Now".​


    After installation, verify that the Nightfall Agent is functioning correctly:

    • In JumpCloud, Device Management → Devices, check that the device remains active and that there are no policy conflicts or errors.

    • In the Nightfall Console → Integrations → Manage (macOS or Windows) → confirm the device is in the “Connected” state.

    • On the Windows machine, check Programs & Features to confirm “Nightfall Agent” appears.

    • In Services (services.msc), verify the Nightfall service is installed and running.

    • Confirm that the NightfallUI app is shown on the taskbar and that the Version, Company UUID, and Device ID are correct.

    • Conduct a simple test of exfiltration detection (per your internal policy) to ensure the agent is monitoring as expected.​


    • Ensure that the MSI installation parameters (API_KEY, COMPANY_ID) are correct and correspond to your Nightfall account.

    • If installation fails silently, re-run the installation with log flags and check the install log file:

    • If devices have pending reboots or other software installations, consider staging installation to avoid conflicts.

    • Because you’re installing via JumpCloud, ensure the device’s JumpCloud Agent is up-to-date and reporting properly before deploying Nightfall.

    • For stealth or minimal-disruption deployment (if desired), schedule installs during off-hours and consider using silent /qn /norestart. The Nightfall Windows guide supports silent installs.

    • Document versioning of Nightfall Agent: if you need to upgrade later, consider how you’ll script uninstall + reinstall or patch. The MSI guide covers uninstall.

    • Monitor JumpCloud’s device compliance and policy execution logs to ensure the command executed successfully.


    1. In JumpCloud Admin Portal: Device Management → Commands → + Command

      • Type: Windows

      • Check "Windows PowerShell"

      • Command: Copy/paste in the command shown below:

      • Command Name: (e.g., “Uninstall NightfallAI Agent Windows”)

      1. Choose a Device Group

        1. Navigate to the Device Groups tab.

        2. Check the group to use for deployment.

      2. Click "Save".

    2. Run whenever needed.


    • Nightfall Windows Agent MSI Deployment Guide – Nightfall Help Center: Install Nightfall AI Agent for Windows OS

    • JumpCloud Windows Agent Installation Walk-through – JumpCloud Support: JumpCloud Agent Windows Installation Walkthrough

    • JumpCloud Commands / Remote Application Install guide: Install Applications Remotely via JumpCloud

    Prerequisites

    Nightfall Endpoint
    $args = @( 
        '/i', ""$msi"" 
        'API_KEY="<API_KEY>"' 
        'COMPANY_ID="<COMPANY_ID>"' 
        'INSTALL_NF_DRIVER=1'
        '/qn'
    
        '/L*V’,'C:\\Windows\\Temp\\NightfallAgent-install.log’
    )

    Connect JumpCloud to Nightfall

    Deploy the Nightfall Agent via JumpCloud

    Post-Installation Verification

    Troubleshooting & Best Practices

    Uninstall via JumpCloud

    Appendix / Reference Links

    Alert title and message: Configured by your security admin (e.g., "Action Blocked — Policy Violation Detected")
  • Action Details section: Contextual information about what was blocked, including:

    • For browser uploads: Source browser + destination domain + file name

    • For cloud sync apps: App name

    • For clipboard paste: Destination domain or app

    • For removable media: File name + device label

    • For code pushes: Repository name

    • For print jobs: Printer name + destination

  • Business reason text field: Free-text input, up to 300 characters. Placeholder: "e.g: working on a project with a partner"

  • Buttons:

    • Submit for approval - enabled only when text is entered; submits justification to Nightfall

    • Cancel - dismisses the prompt without submitting

  • Note: Only one justification prompt is shown at a time. If the same policy triggers within 15 minutes, the prompt is suppressed to avoid repetition.


    On Windows, the justification prompt appears as a toast notification in the bottom-right corner of the screen, above the system tray.

    Window contents:

    • Header: Nightfall AI logo + app name + idle countdown timer ("Closes in: 15s")

    • Alert title and message: Configured by your security admin

    • Event Details box: Shows:

      • File: Name of the file involved (if applicable)

      • Destination: Where the data was being sent (domain or app)

      • Time: Timestamp of the event

      • View Assets link: (if configured) — links to the violation record in the Nightfall console

      • Business Justification field: Text input, up to 300 characters with live character counter (e.g., "0/300")

      • Info line: "Your justification will be logged for security review."

    • Buttons:

      • Cancel - dismisses without submitting

      • Submit & Proceed - enabled only when text is entered

    Auto-dismiss behavior:

    • The window auto-closes after 15 seconds of idle (no mouse hover, no keyboard focus, no text typed)

    • The countdown pauses while the user is actively interacting with the window

    • The window hard-closes when the backend action expires (15 minutes from event time)

    Once a user submits a justification:

    1. Nightfall records the event as an exfiltration violation in the console

    2. The justification text is attached to the violation record

    3. The violation appears in the Violations view with activity: "Provided Business Justification"

    4. If the policy is configured for block override with justification, an "Approve Business Justification" action becomes available to security admins

    Security admins review submitted justifications in the Nightfall console under Violations.

    Each violation with a submitted justification shows:

    • The event details (user, device, file, destination, timestamp)

    • The user's justification text (logged in the activity timeline)

    • The current violation state

    • Available actions, including Approve Business Justification (if block override is enabled)

    Action

    Description

    Approve Business Justification

    Grants a policy override for the specified device and policy, allowing the action to proceed

    Bulk Annotate - Business Justification

    Annotates the violation as having a valid business justification without granting a device override

    Resolve

    Note: "Approve Business Justification" is only available on endpoint exfiltration violations where the policy has Allow Block Override with Justification enabled.

    Nightfall sends alert notifications to configured channels (Slack, email, webhook) when a violation with a justification is created. The notification includes:

    • Who triggered the violation (user + device)

    • What was blocked (file, destination, timestamp)

    • A link to the violation record in the console

    • The justification text in the activity log

    From Slack, admins can open a "Provide Justification" modal to annotate directly from the alert message.

    In the Nightfall console, navigate to Policies > [Your Policy] > Action Notification Settings.

    For the BLOCK action, enable:

    • Enable notification: On

    • Notification type: Pop-up (or Banner)

    • Title: Custom alert title shown to the user (e.g., "Action Blocked by Nightfall")

    • Message: Custom message shown to the user (e.g., "Your action was blocked by a security policy. Please provide a business justification if this action is necessary.")

    • Allow Override with Justification: ✅ Enabled

    If you want admins to be able to approve and unblock the action after reviewing the justification, also enable:

    • Allow Block Override with Justification on the policy's automated action settings

    This surfaces the "Approve Business Justification" action in the Nightfall console.


    Behavior

    Detail

    Prompt re-show interval

    15 minutes per policy (per device)

    Justification window (Windows)

    Expires 15 minutes from event time

    Auto-dismiss idle timeout (Windows)


    The justification prompt fires for blocked events across all monitored channels:

    Transfer Type

    Details shown in prompt

    Browser upload

    Browser name + destination domain + file name

    Cloud sync app upload

    App name

    Clipboard paste


    Q: What happens if I cancel the justification prompt?

    The blocked action is logged as a standard policy violation. No justification is recorded, and your action does not proceed.

    Q: What happens if the window closes before I can type my justification?

    On Windows, the prompt auto-dismisses after 15 seconds of idle. If this occurs, the violation is logged without a justification. You can reach out to your security team directly to explain the context.

    Q: Will submitting a justification automatically allow my action?

    Not automatically. The justification is submitted for admin review. If your admin has enabled block override approval, they can approve it from the console — which creates a policy exception for your device.

    Q: Will I be prompted again for the same action?

    If the same policy blocks you again within 15 minutes, the prompt will not reappear. After 15 minutes, the prompt may show again if the action is blocked.

    Q: Where does my justification text go?

    It is securely logged in the Nightfall platform, visible only to your security team. It is attached to the violation record for audit purposes.

    User attempts transfer
            ↓
    Policy detects violation → BLOCK action fires
            ↓
    Justification prompt appears on-screen (Mac or Windows)
            ↓
    User types justification and submits (or cancels / window expires)
            ↓
    Justification recorded in Nightfall console as a violation event
            ↓
    Security admin reviews → can Approve Business Justification

    Overview

    How It Works - End to End

    The User Experience

    macOS

    Windows

    What Happens After Submission

    Admin Experience - Reviewing Justifications

    What admins see

    Available actions

    Admin notifications

    Configuration - Enabling the Feature

    Step 1: Enable the justification notification in policy settings

    Step 2: (Optional) Enable block override approval

    Deduplication and Timing

    Supported Data Transfer Types

    Frequently Asked Questions

    Exfiltration Events

    Learn the details available on the Nightfall Exfiltration Events page

    The Nightfall Exfiltration page displays various details of the Exfiltration Events. An Exfiltration Event is automatically created in Nightfall when an Exfiltration policy is violated. The Event displays useful information like the integration on which the exfiltration occurred (Google Drive, Salesforce, macOS/Windows Endpoint), the name of the policy violated, the details of the asset responsible for the violation, and so on.

    Exfiltration Event List View

    You can navigate to the Exfiltration Event page by clicking Exfiltration Prevention button from the left menu.

    Once you land on the Exfiltration Events page, all the Exfiltration Events are listed. This view can be called as the Event list view. When you click an Event on the Event list view, the details of only the selected Event is displayed. We can call it the Event Detail view.

    Some of the Event features are common to both Exfiltration and Data Detection and Response. In such cases, we will provide a link to the respective section in Data Detection and Response.

    The Event list view contains a table which displays details of the Events. You can click here to learn more about the details displayed in the Event list view.

    Filtering Data

    You can filter the data on the list view by date or by integrations. To filter the data by integrations, you must execute the following steps.

    1. Navigate to Exfiltration Prevention from the left menu.Steps 2-6 help you filter the events to only view the alerts generated by Windows OS.

    2. Click Filter.

    3. Click + Add Filter.

    4. Select Integration.

    5. Select the check box required integration(s).

    6. Click Apply.

    You can also use the date filter to view historic Exfiltration events. To learn more about how to use the historic time filter, .

    Nightfall provides a powerful search bar to search specific Exfiltration events. Nightfall provides you various search operators to perform your search. You must use the following syntax to search data.

    For example, to search events that are in active state, you must use the State search operator with the following syntax.

    The various Exfiltration search operators provided by Nightfall are as follows.

    Search Operator Name
    Description
    Integration
    Operator Name
    Description

    To learn more about how to search special characters, refer to . Nightfall allows you to share and download the Event data. The Share button creates a link to the current view with all the filters applied. When you click this link, the Events page opens with all the filters applied.

    Nightfall macOS Agent Deployment: JAMF MDM

    This document explains the process of installing the Nightfall AI agent using JAMF.

    The JAMF installation consists of the following steps.

    1. Connect JAMF Pro to Nightfall (API-based MDM Onboarding)

    2. Upload Device Profiles to Jamf Pro

    3. Upload and Add the Pre-Installation Check Script

    • You are a Systems Administrator in Nightfall

    • You have administrator access to JAMF Pro

    • Target macOS devices are onboarded.

    • On your Nightfall console, navigate to and click the Download Package button on the top right corner of the page. Click Download Package for macOS and unpack the contents of the downloaded file.

    1

    This step enables automated mapping of user profiles to devices without requiring manual scripts.

    API-based MDM onboarding allows Nightfall to automatically map the user email attribute to specific devices by syncing device inventory from your JAMF Pro instance.

    To connect JAMF Pro to Nightfall, you'll need:

    • Jamf Pro URL (for example: https://yourcompany.jamfcloud.com)

    Do I still need to install a Nightfall agent on devices after API-based onboarding?

    Yes. API-based MDM onboarding enables Nightfall to map user email addresses to devices automatically. You still need to deploy the Nightfall agent to the devices using the steps above.

    What permissions does Nightfall need in JAMF Pro?

    Nightfall requires least privilege access to device inventory. It does not modify device settings or configurations. The user email to device attribution is automatically managed with API-based MDM onboarding and no manual scripts are needed.

    What happens if API credentials expire or are revoked?

    If credentials expire or are revoked:

    • Device syncing will stop. New devices added or removed will not be reflected in Nightfall during that time.

    • Nightfall will surface an error in the console.

    • You can re-authenticate or update credentials without reconfiguring policies.

    Can I disconnect or change my MDM connection later?

    Yes. Contact Nightfall Support to disconnect or update your MDM connection from Settings → MDM Profile.

    Who should I contact if onboarding fails?

    If you encounter issues:

    • Verify API credentials and permissions in JAMF Pro

    • Check the error message in the Nightfall console

    • Contact Nightfall Support for assistance

    Nightfall Windows Agent Deployment: MSI

    This guide explains multiple ways to deploy the Nightfall Agent (NightfallAgent.msi) with the required API_KEY and COMPANY_ID parameters.

    We cover:

    • PowerShell scripts (local, network share, download from URL)

    • Deployment through Group Policy (GPO)

    • One-liner script for testing

    • You have the MSI installer (NightfallAgent.msi) provided by Nightfall.

    • Installation requires two properties:

      • API_KEY="YOUR-API-KEY"

      • COMPANY_ID="YOUR_SECRET_VALUE"

    Use this if you or your RMM tool place the .msi directly on the machine before running the script.

    Use this if you keep the MSI on a file server. Make sure Domain Computers or the target machines have read access to the share.

    ⚠️ Use UNC paths (\\server\share\...) — mapped drives won’t work for GPO Startup scripts.

    Use this if you host the MSI on an internal HTTPS server or CDN.

    Recommended for domain-joined Windows machines. Use a Startup Script because the built-in “Software Installation” GPO cannot pass custom properties like API_KEY.

    Steps:

    1. Place the script (e.g., Install-NightfallAgent-FromShare.ps1) in

      \\<domain>\SYSVOL\<domain>\scripts\Nightfall\

    2. Ensure Domain Computers have read access.

    3. In Group Policy Management:

      • Go to Computer Configuration → Policies → Windows Settings → Scripts (Startup/Shutdown).

    If you have an MST transform that embeds API_KEY and COMPANY_ID, you can deploy the MSI via:

    Computer Configuration → Policies → Software Settings → Software installation.

    • Add the MSI via UNC path.

    • Open its Properties → Modifications → Add your .mst.

    Without an MST, use GPO via Startup Script instead. One-liner for Testing

    Run manually on a single machine (PowerShell elevated):

    • Check for expected services:

    • Confirm presence of the Nightfall AI icon in the system tray (this may take a few seconds).

      • Double click the icon

      • You should see a connected status as seen in the image above.

    Creating an AI Agent Security Policy

    AI Agent Security policies are configured as exfiltration policies in Nightfall. This guide walks through each step of the policy creation wizard.


    Getting Started

    1. Navigate to Configuration > Policies > Exfiltration.

    2. Click + New Policy.

    3. Select AI Agent Security as the integration type.


    Step 1: Choose Hook Types

    Enable one or more hook types. Each can be independently toggled:


    Defines which MCP servers this policy is evaluated against. This scope also applies to tool responses (data coming back from the server, not just outbound calls). What happens when a match occurs - block, alert, etc. - is configured separately under Remediation Actions.

    • All MCP servers - the policy applies to every connected MCP server.

    • Specific MCP servers - the policy applies only to a chosen list of servers.

    • All except these MCP servers - the policy applies to every server except a chosen list of excluded servers.

    When you select “Specific MCP servers” or "All except these MCP servers," a drop-down picker appears:

    Select one or more named server collections. All servers across selected collections are combined.

    • There are pre-defined collections organized by category:

    • Code Hosting

    • Databases

    • Communication

    You can navigate to Collections list page under AI Governance > Collections and manually add a new MCP server, tool calls for a server. Select individual servers and optionally limit to specific tools within each server. Tool inventory will be captured and will be available in the Collections list page via the Add server and Add tools button. There is no blanket collection which will have all the servers and tools discovered.

    For example, you could allow the GitHub MCP server but only for read operations. To do so, specify this in the MCP server collection and configure an appropriate policy.

    Nightfall identifies the MCP server from the tool name reported by each AI client. Because clients format these names differently, the server is not always identifiable. The table below uses the fetch tool on a server named github as an example.

    • Claude Code - Server-specific scoping works as expected.

    • GitHub Copilot - Server-specific scoping works in most cases. When a server or tool name contains underscores, Nightfall may not be able to tell the server and tool apart reliably.

    • Cursor - Cursor does not include the server name in its tool names. A Specific MCP servers or All except these MCP servers policy therefore cannot match Cursor traffic by server, and Cursor activity is treated as if All MCP servers were selected.

    Recommendation: If you need to scope policies by server and your organization uses Cursor, pair the policy with a broader All MCP servers rule so Cursor traffic is still covered.


    When Shell Commands monitoring is enabled, you can optionally scope to specific command patterns. Leaving this field empty scans all shell commands.

    Enter patterns as chips (type + Enter to add). Recommended patterns are shown as clickable suggestions below the input.


    Select the Nightfall detectors that define what sensitive data to look for. This works the same as any other exfiltration policy:

    • Built-in detectors: PII (SSN, credit cards, phone numbers), credentials (API keys, passwords, tokens), source code patterns

    • Custom detectors: Regular expressions, dictionaries, or ML-based classifiers you have created

    • Detection rule logic: Combine multiple detectors with AND/OR logic and set confidence thresholds


    Configure where violation alerts are sent:

    • Slack - post to a channel

    • Jira - create a ticket

    • Email - send to specified recipients

    • Webhook - POST to a custom endpoint

    End-user notifications are not available with AI Agent Security policy at this time. The custom message will be displayed in AI clients like Cursor, Claude Code & VS Code.

    • The notification text as per the custom block message (e.g., "This action was blocked because it contains sensitive data. Contact security@company.com for help.")

    • Policy name and description

    • Risk score - use the Nightfall default or set a custom severity (Critical, High, Medium, Low)


    Here is an example of a common policy configuration:

    1. AI Clients: Claude Code, Cursor, VS Code

    2. Hook Types: User Prompts (Block), Tool Calls (Block), Shell Commands (Monitor)

    3. MCP Server Scope: All MCP servers

    4. Detection Rules: API Keys, Passwords, AWS Credentials (High confidence)

    This policy prevents developers from accidentally pasting API keys or credentials into AI prompts or tool calls, while monitoring shell commands for credential exposure.

    Hooks vs. Open Telemetry

    Nightfall uses two complementary mechanisms to monitor AI agent activity. This page explains the differences, when to use each, and the recommended deployment strategy.


    Closes the violation

    Create Jira Issue

    Escalates to Jira

    Notify via Slack / Email

    Sends a notification to the violating user

    15 seconds of inactivity

    Max justification length

    300 characters

    Simultaneous prompts

    One at a time (additional events are queued/suppressed)

    Destination domain or application

    Removable media

    File name + device/volume label

    Thick app upload (Outlook, iMessage, etc.)

    App name + file name

    Git push

    Repository name

    Print

    Printer name + print destination

    Tool Responses

    No

    Tool output after execution (monitor only)

    Model Responses

    No

    Model response after execution (monitor only)

    Shell Commands

    Yes

    Shell command string before execution

    Cloud Infrastructure
  • Observability

  • Project Management

  • File System

  • mcp_<server>_<tool>

    mcp_github_fetch

    Usually

    Cursor

    MCP:<tool>

    MCP:fetch

    No

    Action: Block

  • Alerts: Slack #security-alerts + Email to security team

  • Hook Type

    Can Block

    What It Scans

    User Prompts

    Yes

    Prompt text before it reaches the AI model

    Tool Calls

    Yes

    AI client

    Tool name format

    Example

    Server identified?

    Claude Code

    mcp__<server>__<tool>

    mcp__github__fetch

    Yes

    Action

    Behavior

    Block

    The AI agent action is denied. The end-user sees a block message.

    Monitor

    The action proceeds. An incident is created for review.

    Step 2: MCP Server Scope

    1: MCP Server Collections

    2: Wildcard Patterns

    How servers are identified

    What this means for your policies

    Step 4: Shell Command Patterns (Optional)

    Step 5: Detection Rules

    Step 6: Actions and Alerts

    Enforcement action

    Admin alerting

    End-user notification

    Policy metadata

    Example: Block Credentials in Prompts

    Tool name and input parameters before execution

    GitHub Copilot

    Nightfall Endpoint
    Setting the path of the file upload

    Search the unique Exfiltration event ID.

    event_type

    Search the Exfiltration event type.

    integration_name

    Search the integration name.

    last_action

    Search the last action implemented on an event. Example of action can be Acknowledge, Ignore, Resolve, and so on.

    last_actioned_by

    Search for the user who last took an action on the event.

    notes

    Search the notes entered in an Event.

    policy_id

    Search the unique policy ID.

    policy_name

    Search the policy name.

    resource_content_type

    Search the resource type of the file that was exfiltrated. Resource type refers to the file format and can be PDF, .doc, d.ocx, and so on.

    resource_id

    Search the resource ID. This unique identifier is assigned to resources by their integration (Google Drive, Salesforce)

    resource_name

    Search the resource name (file name) that was exfiltrated.

    resource_owner_email

    Search the email of the user who owns the exfiltrated file.

    resource_owner_name

    Search the name of the user who owns the exfiltrated file.

    state

    Search the current status of the Event. This could be Active, Acknowledge, and so on.

    violation_id

    Search the unique violation ID of the event.

    violation_type

    Search the violation type

    endpoint.browser_upload.domain

    Search the domain name that was used to upload file.

    Endpoint (Browser upload)

    endpoint.browser_upload.file_name

    Search the name of the file.

    Endpoint (Browser upload)

    endpoint.browser_upload.origin.browser_name

    Search the browser from which the exfiltrated file emerged.

    Endpoint (Browser upload)

    endpoint.browser_upload.origin.domain

    Search the domain from which the exfiltrated file emerged.

    Endpoint (Browser upload)

    endpoint.browser_upload.origin.url

    Search the exact URL from which the exfiltrated file emerged.

    Endpoint (Browser upload)

    endpoint.browser_upload.url

    Search the URL used to upload the exfiltrated file.

    Endpoint (Clipboard Copy/Paste)

    endpoint.clipboard_copy.destination.browser_name

    Search the destination browser name to which the copied data was pasted.

    Endpoint (Clipboard Copy/Paste)

    endpoint.clipboard_copy.destination.domain

    Search the destination domain name to which the copied data was pasted.

    Endpoint (Clipboard Copy/Paste)

    endpoint.clipboard_copy.origin.browser_name

    Search the origin browser name from which the data was copied.

    Endpoint (Clipboard Copy/Paste)

    endpoint.clipboard_copy.origin.domain

    Search the origin domain name from which the data was copied.

    Endpoint (Clipboard Copy/Paste)

    endpoint.clipboard_copy.origin.url

    Search the origin URL from which the data was copied.

    Endpoint (Cloud Sync)

    endpoint.cloud_sync.account_name

    Search the name of the account to which the file was uploaded.

    Endpoint (Cloud Sync)

    endpoint.cloud_sync.account_type

    Search the account type (personal/business) of the account to which the file was uploaded.

    Endpoint (Cloud Sync)

    endpoint.cloud_sync.app

    Search the cloud storage app name (Google Drive, OneDrive) to which the file was uploaded.

    Endpoint (Cloud Sync)

    endpoint.cloud_sync.destination_file_path

    Search the destination directory in the storage app to which the file was exfiltrated.

    Endpoint (Cloud Sync)

    endpoint.cloud_sync.email

    Search the email ID of the account to which the file was uploaded.

    Endpoint (Cloud Sync)

    endpoint.cloud_sync.file_name

    Search the name of the file which was uploaded to a cloud storage app.

    Endpoint

    endpoint.device_id

    Search the endpoint device ID of the device from which the exfiltration was performed.

    Endpoint

    endpoint.machine_name

    Search the endpoint device name from which the exfiltration was performed.

    Google Drive

    gdrive.drive

    Search a drive within Google Drive. Returns all the events that were exfiltrated from the searched drive.

    Google Drive

    gdrive.file_owner

    Search a Google Drive user. Returns all the events that were owned by the searched user and were exfiltrated.

    Google Drive

    gdrive.label_name

    Search a Google Drive label. Returns all the events that contained the searched label and were exfiltrated.

    Google Drive

    gdrive.permission

    Search a Google drive permission (restricted, pubic). Returns all the events that contain the searched permission and exfiltrated.

    Google Drive

    gdrive.shared_external_email

    Search the shared Gmail external email ID.

    Google Drive

    gdrive.shared_internal_email

    Search the shared Gmail internal email ID.

    Salesforce

    salesforce.file.session_level

    Search for Salesforce session level file

    Salesforce

    salesforce.file.source_ip

    Search the IP address of the source machine that initiated the exfiltration of the file.

    Salesforce

    salesforce.report.description

    Search the description provided in Salesforce report.

    Salesforce

    salesforce.report.event_source

    Search the Salesforce report event source.

    Salesforce

    salesforce.report.operation

    Search the Salesforce report operation.

    Salesforce

    salesforce.report.scope

    Search the Salesforce report scope.

    Salesforce

    salesforce.report.session_level

    Search the Salesforce session level report.

    Salesforce

    salesforce.report.source_ip

    Search the source IP address of the Salesforce report.

    actor_Email

    Search using the Email ID of the actor whose action triggered the Event.

    actor_Name

    Search using the name of the actor (device name) from which the Event was triggered.

    Endpoint (Browser upload)

    endpoint.browser_upload.browser_name

    Search the Web browser that was used to upload file.

    Search Events

    General Search Operators

    Integration Operators

    refer this section
    this section

    event_id

    Endpoint (Browser upload)

    Installation is silent (/qn /norestart) and requires administrator rights.

  • Logging is enabled with /l*v for troubleshooting.

  • Add a Startup Script.

    • Script name: powershell.exe

    • Script parameters: -ExecutionPolicy Bypass -File "\\SYSVOL<domain>\scripts\Nightfall\Install-NightfallAgent-FromShare.ps1"

  • Apply the GPO to the desired OU.

  • Run gpupdate /force or reboot a target machine.

  • Assumptions

    PowerShell: Local MSI (already copied to the machine)

    PowerShell: Install from a Network Share

    PowerShell: Download MSI from a URL

    GPO Deployment via Startup Script

    GPO Software Installation with MST (Advanced)

    One-liner for Testing

    Verification After Install

    Uninstalling The Nightfall AI Agent

    Uninstall with or without the .msi present.
    $msi = 'C:\\Windows\\Temp\\NightfallAgent.msi'
    $args = @(
        '/i', "`"$msi`""
        'API_KEY="<API_KEY>"'
        'COMPANY_ID="<COMPANY_ID>"'
        'INSTALL_NF_DRIVER=1'
        '/qn'
    )
    
    Start-Process msiexec.exe -ArgumentList $args -Wait -NoNewWindow
    # Uninstall "NightfallAI Agent" silently via MSI ProductCode, with full logging.
    # Works for both 64-bit and 32-bit (WOW6432Node) installs.
    
    $TargetDisplayName = 'NightfallAI Agent'
    $UninstallHives = @(
      'HKLM:\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall',
      'HKLM:\\SOFTWARE\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall'
    )
    
    Write-Host "Searching for '$TargetDisplayName' in uninstall registry..." -ForegroundColor Cyan
    
    $found = $null
    foreach ($hive in $UninstallHives) {
      if (-not (Test-Path $hive)) { continue }
      foreach ($sub in Get-ChildItem $hive -ErrorAction SilentlyContinue) {
        try {
          $p = Get-ItemProperty $sub.PSPath -ErrorAction SilentlyContinue
          if ($p.DisplayName -eq $TargetDisplayName) {
            $found = [pscustomobject]@{
              KeyName         = $sub.PSChildName
              KeyPath         = $sub.PSPath
              DisplayName     = $p.DisplayName
              UninstallString = $p.UninstallString
            }
            break
          }
        } catch { }
      }
      if ($found) { break }
    }
    
    if (-not $found) {
      Write-Host "Not installed: $TargetDisplayName — nothing to do." -ForegroundColor Yellow
      exit 0
    }
    
    Write-Host "Found:" -ForegroundColor Green
    Write-Host "  Key: $($found.KeyPath)"
    Write-Host "  UninstallString: $($found.UninstallString)"
    
    # Try to extract ProductCode (GUID) from key name or UninstallString
    $guid = $null
    if ($found.KeyName -match '^\\{[0-9A-Fa-f-]{36}\\}$') { $guid = $found.KeyName }
    elseif ($found.UninstallString -match '\\{[0-9A-Fa-f]{8}(-[0-9A-Fa-f]{4}){3}-[0-9A-Fa-f]{12}\\}') { $guid = $matches[0] }
    
    $LogPath = 'C:\\Windows\\Temp\\NightfallAgent-uninstall.log'
    
    if ($guid) {
      Write-Host "Using ProductCode $guid for silent uninstall via msiexec..."
      $args = @('/x', $guid, '/qn', '/norestart', '/L*V', $LogPath)
      $proc = Start-Process -FilePath msiexec.exe -ArgumentList $args -Wait -PassThru -NoNewWindow
      $code = $proc.ExitCode
      Write-Host "msiexec exit code: $code"
      if (Test-Path $LogPath) { Write-Host "MSI log: $LogPath" }
      exit $code
    }
    else {
      # Fallback: run the UninstallString directly (best effort).
      # If it's msiexec without silent flags, try to add /qn /norestart.
      $cmd = $found.UninstallString
      if ([string]::IsNullOrWhiteSpace($cmd)) {
        Write-Error "UninstallString missing — cannot continue."
        exit 1
      }
    
      if ($cmd -match 'msiexec(\\.exe)?\\s+/I\\s*(\\{[^\\}]+\\})') {
        # Convert /I to /x for remove, add silent + log
        $guid2 = $matches[2]
        Write-Host "Converting msiexec /I to silent remove for $guid2"
        $args = @('/x', $guid2, '/qn', '/norestart', '/L*V', $LogPath)
        $proc = Start-Process -FilePath msiexec.exe -ArgumentList $args -Wait -PassThru -NoNewWindow
        $code = $proc.ExitCode
        Write-Host "msiexec exit code: $code"
        if (Test-Path $LogPath) { Write-Host "MSI log: $LogPath" }
        exit $code
      }
      elseif ($cmd -match 'msiexec(\\.exe)?') {
        # It's some other msiexec form; append silent flags if missing
        $aug = $cmd
        if ($aug -notmatch '/qn')       { $aug += ' /qn' }
        if ($aug -notmatch '/norestart'){ $aug += ' /norestart' }
        if ($aug -notmatch '/L\\*V')     { $aug += " /L*V `"$LogPath`"" }
    
        Write-Host "Running: $aug"
        $proc = Start-Process -FilePath 'cmd.exe' -ArgumentList '/c', $aug -Wait -PassThru -NoNewWindow
        $code = $proc.ExitCode
        Write-Host "msiexec exit code: $code"
        if (Test-Path $LogPath) { Write-Host "MSI log: $LogPath" }
        exit $code
      }
      else {
        # Non-MSI uninstaller (unlikely for your MSI). Launch as-is.
        Write-Host "Non-MSI uninstall string; executing as-is."
        $proc = Start-Process -FilePath 'cmd.exe' -ArgumentList '/c', $cmd -Wait -PassThru -NoNewWindow
        $code = $proc.ExitCode
        Write-Host "Uninstaller exit code: $code"
        exit $code
      }
    }
    search operator name:"search term"
    State:"Active"
    # Install-NightfallAgent-Local.ps1
    
    $msiPath   = "C:\Temp\NightfallAgent.msi"
    $apiKey    = "REPLACE_WITH_API_KEY"
    $companyId = "REPLACE_WITH_COMPANY_ID"
    
    $logDir = "C:\Windows\Temp\Nightfall"
    $logFile = Join-Path $logDir "NightfallAgent_Install.log"
    
    New-Item -ItemType Directory -Path $logDir -Force | Out-Null
    
    if (Test-Path $msiPath) {
        Write-Output "MSI found at $msiPath. Starting install..."
        $args = "/i `"$msiPath`" API_KEY=`"$apiKey`" COMPANY_ID=`"$companyId`" /qn /norestart /l*v `"$logFile`""
        $proc = Start-Process "msiexec.exe" -ArgumentList $args -Wait -PassThru -NoNewWindow
        if ($proc.ExitCode -eq 0) {
            Write-Output "Nightfall agent installed successfully."
        } else {
            Write-Output "Installer returned exit code $($proc.ExitCode). Check log: $logFile"
            exit $proc.ExitCode
        }
    } else {
        Write-Output "MSI not found at $msiPath. Skipping install."
        exit 2
    }
    # Install-NightfallAgent-FromShare.ps1
    
    $sourceMsi = "\\fileserver\software\Nightfall\NightfallAgent.msi"
    $localMsi  = "C:\Temp\NightfallAgent.msi"
    $apiKey    = "YOUR_API_KEY_HERE"
    $companyId = "YOUR_SECRET_VALUE"
    
    $logDir = "C:\Windows\Temp\Nightfall"
    $logFile = Join-Path $logDir "NightfallAgent_Install.log"
    
    New-Item -ItemType Directory -Path $logDir -Force | Out-Null
    New-Item -ItemType Directory -Path (Split-Path $localMsi) -Force | Out-Null
    
    Write-Output "Copying MSI from $sourceMsi to $localMsi..."
    Copy-Item -Path $sourceMsi -Destination $localMsi -Force -ErrorAction Stop
    
    if (Test-Path $localMsi) {
        Write-Output "Copy complete. Starting install..."
        $args = "/i `"$localMsi`" API_KEY=`"$apiKey`" COMPANY_ID=`"$companyId`" /qn /norestart /l*v `"$logFile`""
        $proc = Start-Process "msiexec.exe" -ArgumentList $args -Wait -PassThru -NoNewWindow
        if ($proc.ExitCode -eq 0) {
            Write-Output "Nightfall agent installed successfully."
        } else {
            Write-Output "Installer returned exit code $($proc.ExitCode). Check log: $logFile"
            exit $proc.ExitCode
        }
    } else {
        Write-Output "MSI copy failed. Check share permissions and path."
        exit 3
    }
    # Install-NightfallAgent-FromUrl.ps1
    # Purpose: Download the Nightfall MSI from a URL, validate it looks like a real MSI, then install silently.
    # Notes:
    #   - Run elevated (admin). Works as a GPO Startup script.
    
    # --- EDIT THESE VALUES ---
    $downloadUrl = "https://example.com/NightfallAgent.msi"  # <-- Replace with your direct MSI URL
    $localMsi    = "C:\Temp\NightfallAgent.msi"
    $apiKey      = "<API_KEY>"        # <-- Replace
    $companyId   = "<COMPANY_ID>"     # <-- Replace
    # --------------------------
    
    $ErrorActionPreference = "Stop"
    
    # Paths for logging
    $logDir  = "C:\Windows\Temp\Nightfall"
    $logFile = Join-Path $logDir "NightfallAgent_Install.log"
    
    # Ensure folders exist
    New-Item -ItemType Directory -Path (Split-Path $localMsi) -Force | Out-Null
    New-Item -ItemType Directory -Path $logDir -Force | Out-Null
    
    # Helper: quick MSI signature + size sanity check
    function Test-IsMsi {
        param([string]$Path)
        if (-not (Test-Path $Path)) { return $false }
        $len = (Get-Item $Path).Length
        if ($len -lt 1MB) { return $false } # tiny files are likely HTML/error pages
    
        # MSI is a CFBF (OLE) container: header D0 CF 11 E0 A1 B1 1A E1
        $fs = [System.IO.File]::Open($Path, 'Open', 'Read', 'ReadWrite')
        try {
            $buf = New-Object byte[] 8
            [void]$fs.Read($buf, 0, 8)
            $hex = ($buf | ForEach-Object { $_.ToString("X2") }) -join " "
            return ($hex -eq "D0 CF 11 E0 A1 B1 1A E1")
        } finally {
            $fs.Close()
        }
    }
    
    Write-Output "Downloading MSI from $downloadUrl ..."
    try {
        # Use HttpClient for robust redirects + streaming
        Add-Type -AssemblyName System.Net.Http
        $handler = New-Object System.Net.Http.HttpClientHandler
        $handler.AllowAutoRedirect = $true
        $handler.AutomaticDecompression = [System.Net.DecompressionMethods]::GZip -bor `
                                          [System.Net.DecompressionMethods]::Deflate -bor `
                                          [System.Net.DecompressionMethods]::Brotli
        $client = New-Object System.Net.Http.HttpClient($handler)
        $client.Timeout = [TimeSpan]::FromMinutes(10)
        $client.DefaultRequestHeaders.UserAgent.ParseAdd("Nightfall-Agent-Installer/1.0")
    
        $response = $client.GetAsync($downloadUrl, [System.Net.Http.HttpCompletionOption]::ResponseHeadersRead).GetAwaiter().GetResult()
        if (-not $response.IsSuccessStatusCode) {
            throw "HTTP $([int]$response.StatusCode) $($response.ReasonPhrase)"
        }
    
        $stream = $response.Content.ReadAsStreamAsync().GetAwaiter().GetResult()
        $tmp = "$localMsi.download"
        $fs = [System.IO.File]::Open($tmp, [System.IO.FileMode]::Create, [System.IO.FileAccess]::Write, [System.IO.FileShare]::None)
        try {
            $buffer = New-Object byte[] (1024*256) # 256 KB chunks
            while (($read = $stream.Read($buffer, 0, $buffer.Length)) -gt 0) {
                $fs.Write($buffer, 0, $read)
            }
        } finally {
            $fs.Dispose()
            $stream.Dispose()
            $client.Dispose()
            $handler.Dispose()
        }
    
        if (Test-Path $localMsi) { Remove-Item $localMsi -Force }
        Move-Item $tmp $localMsi -Force
    
    } catch {
        Write-Error "Download failed: $($_.Exception.Message)"
        exit 100
    }
    
    # Validate the download looks like a real MSI
    if (-not (Test-IsMsi -Path $localMsi)) {
        $size = (Get-Item $localMsi).Length
        Write-Error "Downloaded file does not look like a valid MSI (size=$size bytes). The URL may be a landing page or error."
        exit 101
    }
    
    # Remove MOTW just in case
    try { Unblock-File -Path $localMsi -ErrorAction SilentlyContinue } catch {}
    
    # Install silently with logging
    Write-Output "MSI validated. Installing Nightfall Agent..."
    $args = "/i `"$localMsi`" API_KEY=`"$apiKey`" COMPANY_ID=`"$companyId`" /qn /norestart /l*v `"$logFile`""
    $proc = Start-Process "msiexec.exe" -ArgumentList $args -Wait -PassThru -NoNewWindow
    
    switch ($proc.ExitCode) {
        0     { Write-Output "Nightfall Agent installed successfully."; exit 0 }
        1603  { Write-Error "Fatal error during installation (1603). See log: $logFile"; exit 1603 }
        1618  { Write-Error "Another installation is already in progress (1618)."; exit 1618 }
        1620  { Write-Error "Package could not be opened (1620). File may be invalid. See log: $logFile"; exit 1620 }
        default { Write-Error "Installer returned exit code $($proc.ExitCode). See log: $logFile"; exit $proc.ExitCode }
    }
    $msiPath="C:\Temp\NightfallAgent.msi"; Start-Process msiexec.exe -ArgumentList "/i `"$msiPath`" API_KEY=`"YOUR_API_KEY_HERE`" COMPANY_ID=`"YOUR_SECRET_VALUE`" /qn /norestart /l*v `"`"C:\Windows\Temp\Nightfall\NightfallAgent_Install.log`"`"" -Wait
    Get-Service Nightfall*
    $ProductName = "NightfallAI Agent"
    
    # Function to retrieve installed products matching product name
    function Get-MatchingProducts($name) {
        Write-Host "Searching for products matching: '$name'..."
        Get-WmiObject -Class Win32_Product -ErrorAction SilentlyContinue |
            Where-Object { $_.Name -like "*$name*" }
    }
    
    # Function to uninstall a product by ProductCode
    function Uninstall-Product($product) {
        $name = $product.Name
        $productCode = $product.IdentifyingNumber
    
        if ($productCode) {
            Write-Host "Uninstalling '$name' (ProductCode: $productCode)..." -ForegroundColor Green
            Start-Process "msiexec.exe" -ArgumentList "/x $productCode /qn" -Wait -NoNewWindow
            Write-Host "Uninstalled: $name" -ForegroundColor Green
        } else {
            Write-Warning "Skipping ${name}: missing ProductCode."
        }
    }
    
    # Try finding the initial product
    $products = Get-MatchingProducts -name $ProductName
    
    # If not found, try old NightfallAI Agent name 'Agent'
    if (-not $products -or $products.Count -eq 0) {
        Write-Warning "No installed products found matching: '$ProductName'"
        Write-Host "Trying to search for old NightfallAgent name : 'Agent'" -ForegroundColor Yellow
        $products = Get-MatchingProducts -name "Agent"
    }
    
    # Final check before uninstall
    if (-not $products -or $products.Count -eq 0) {
        Write-Host "No matching products found for either '${ProductName}' or 'Agent'."
        exit 1
    }
    
    foreach ($product in $products) {
        Uninstall-Product -product $product
    }
    
    Client ID
  • Client Secret

  • The Jamf Pro API client must have permissions to read device and computer inventory.

    1. Log in to your JAMF Pro instance

    2. Navigate to Settings > System > API Roles and Clients

      1. Under the API Roles tab, click the + New button.

        1. Configure the following:

          • Display Name: Nightfall API Role

          • Privileges: Grant access to:

            • Read Computer Inventory Collection

        2. Click Save

      2. Next, navigate to the API Clients tab and click the + New button.

        1. Configured the following:

          • Display Name: Nightfall API Client

    1. Log in to the Nightfall Console at https://app.nightfall.ai

    2. Navigate to Settings → MDM Profile

    3. Click Add MDM

    4. Select Jamf Pro from the list of supported MDM providers

    5. Enter the following information:

      • Jamf Pro URL: Your JAMF instance URL (e.g., https://yourcompany.jamfcloud.com)

      • Client ID: The Client ID you created in JAMF Pro

      • Client Secret: The Client Secret you created in JAMF Pro

    6. Click Connect

    Nightfall will validate the credentials and begin syncing device information automatically.

    Important: This API-based connection enables Nightfall to automatically map user email addresses to devices. You do not need to deploy any additional scripts for user-to-device mapping when using this method.

    Once connected, Nightfall will periodically sync device inventory from JAMF Pro. You can now proceed to deploy the Nightfall agent to your devices following the steps below.

    2

    Step 2 - Upload and Add Pre-Installation Check Script

    This script checks if the required profiles are installed and that the endpoint agent is at the desired version.

    1. Unpack the zip file provided and locate the mdm_pre_install_check_script.sh file under the .\\mdm_scripts\\ folder

    2. On Jamf Pro, navigate to Settings > Computer management > Scripts

    3. Click the + New button.

    4. Enter a display name for the script (e.g., "Nightfall AI Pre-Installation Check").

    5. Click on the Script tab.

    6. Paste the contents of mdm_pre_install_check_script.sh into the script editor.

    7. Click Save.

    3

    Step 3 - Upload and Add the Pre-Installation Script

    This script configures the target machine and prepares it to connect to your Nightfall instance once the package is deployed.

    1. Locate the mdm_pre_installation_script.sh file under the .\\mdm_scripts\\ folder

    2. On Jamf Pro, navigate to Settings > Computer management > Scripts

    3. Click the New button.

    4. Enter a display name for the script (e.g., "Nightfall AI Pre-Installation Script").

    5. Click on the Script tab.

    6. Paste the contents of mdm_pre_installation_script.sh into the script editor.

    7. Click Save.

    4

    Step 4 - Upload The Nightfall MDM Profile of your choice to Jamf Pro

    1. In the downloaded folder, locate the README.md under /Profiles to learn about the various MDM profiles available.

      1. Choose NightfallAI_Profile_with_Browser_Extensions.mobileconfig.

    2. Log in to your Jamf Pro account.

    3. Navigate to Computers > Configuration Profiles.

    4. Click the Upload button.

    5. Click the Upload button and upload NightfallAI_Profile_with_Browser_Extensions.mobileconfig.

    6. In the Scope tab, add the target devices or device groups to which this profile should be deployed.

    7. Click Save.

    Once assigned, profiles will be automatically deployed as part of the next Jamf inventory cycle.

    5

    Step 5 - Upload the Nightfall App Package

    1. Navigate to Settings > Computer management > Packages

    2. Click the + New button.

    3. Enter a display name for the package (e.g., "Nightfall AI Agent").

    4. Click the Choose File button and upload nightfall-ai-agent-signed.pkg.

    5. Click Save.

    6

    Step 6 - Create a Policy and Add scripts and package

    1. Navigate to Computers > Policies.

    2. Click the + New button.

    3. Enter a display name for the policy (e.g., "Deploy Nightfall AI").

    4. From the General tab, configure the Trigger and Execution Frequency as needed.

    5. Click Package from the left pane & click on configure

    6. Add Nightfall AI Agent package

    7. Click on Scripts from the left pane & click on configure

    8. Add Pre-Install Check Script and Pre-Install Script. Ensure the Priority is Before and the sequence is [ The scripts must be run once & in sequence to prepare the machine for the package install. ] -

      1. Pre-Install Check Script

      2. Pre-Install Script

    9. Click on Scope and determine the Target, Limitations, and Exclusions per need.

    10. Click Save.

    mdm_pre_installation_script.sh

    The script is used by MDMs to ensure that a macOS machine is in a clean state before installing the Nightfall Agent. It wipes any existing Nightfall installation and prepares a clean environment for a new install, including:

    • Loading API keys

    • Rebuilding folders

    • Resetting launch daemons

    NightfallAI_Profile_with_Browser_Extension.mobileconfig

    This profile is designed to pre-authorize and enable what the Nightfall Endpoint Agent requires on a macOS machine without needing user prompts.

    • Silently installs/enables the Nightfall browser extension

    • Allows the extension to run without prompts

    • Authorizes required permissions (content inspection, file uploads, scanning)

    • Grants macOS Privacy Permissions required by Nightfall:

      • Full Disk Access (FDA)

      • System Events/Automation Permissions

      • Application Control Permissions

    • Configures the payloads for browser + system integration

    • Prevents users from tampering with the security controls

    Prerequisites

    To install the Nightfall agent in stealth mode (without notifing the end-user), see Install Nightfall AI Agent for Mac.

    Step 1 - Connect JAMF Pro to Nightfall (API-based MDM Onboarding)

    What You'll Need from JAMF Pro

    Frequently Asked Questions (FAQs)

    Upload and Add the Pre-Installation Script
    Upload the Nightfall App Package
    Create a Policy and Add scripts and package
    https://app.nightfall.ai/endpoint

    Creating API Credentials in JAMF Pro

    Connecting JAMF Pro to Nightfall

    After Connection

    After the action completes

    Can block actions

    Yes

    No - monitor only

    Prompt text scanning

    Yes

    Yes (requires OTEL_LOG_USER_PROMPTS=1)

    Tool I/O scanning

    Yes

    Yes (requires OTEL_LOG_TOOL_DETAILS=1)

    Cost and token tracking

    No

    Yes (costUSD, inputTokens, outputTokens)

    Model name

    No

    Yes (e.g., claude-sonnet-4-6)

    Complete session audit trail

    Partial (hook points only)

    As supported via OTEL

    API error tracking

    No

    Yes (failed requests, retries)

    Detect hook bypass

    No

    Yes, Hooks status is available via device list page (detects if hooks were disabled)


    Not every agent supports both mechanisms. Use this matrix to understand what is available for each agent:

    Agent

    Hooks

    OTel

    Enforcement Options

    Claude Code

    Yes

    No

    Block or Monitor


    • Block sensitive data from being sent to AI models or external tools

    • Prevent shell commands that could leak credentials

    • Enforce MCP server allowlists in real time

    • Stop tool calls to unauthorized services before they execute

    • Track costs - token usage and dollar cost per prompt

    • Audit complete session activity including tool decisions and API calls

    • Monitor Claude Cowork - the only mechanism available

    • Detect hook bypass - identify when developers disable or circumvent hooks

    Compliance logging - capture every prompt for regulatory requirements

    The Nightfall agent registers handlers for four hook points. Each hook fires at a specific moment in the AI agent's workflow:

    Hook Point

    When It Fires

    What It Scans

    Can Block?

    User Prompts

    Before the prompt is sent to the AI model

    Full prompt text

    Yes

    Tool Responses capture content after the tool has already executed - the action has completed and cannot be reversed. Nightfall still scans the output for policy violations and creates incidents, but blocking is not possible at this point.


    When a hook fires, the following happens:

    1. The AI agent (Claude Code, Cursor, or VS Code) pauses the action and sends the content to the Nightfall agent running on the endpoint.

    2. The Nightfall agent evaluates the content against your active AI agent policies and enforces remediation actions such as block user prompts, tool calls or shell commands.

    3. The agent returns a verdict:

    • Allow - the action proceeds normally.

    • Block - the action is denied. The end-user sees a message explaining why.

    1. If a violation is detected, the incident is recorded in your Nightfall console regardless of whether the action was blocked or monitored.

    If the Nightfall agent is temporarily unavailable or takes longer than 15 seconds to respond, the hook fails open - the AI agent action proceeds normally. This ensures that developer workflows are never blocked by infrastructure issues.

    When the agent recovers, hooks resume normal enforcement automatically.


    Claude Cowork is monitored through OpenTelemetry (OTel) rather than hooks. You need to configure OpenTelemetry for Claude Cowork. You can follow the steps available here to setup OTel https://claude.com/docs/cowork/monitoring#events

    Capability

    Hooks (Real-Time)

    OTel Telemetry (Async)

    Timing

    Hooks vs. OTel Telemetry

    Capability Comparison

    Before the action executes

    Agent Support Matrix

    When to Use Each

    Use hooks when you need to:

    Use OTel when you need to:

    What Hooks Intercept

    Why Tool Responses are monitor-only

    How Enforcement Works

    Fail-open design

    Claude Cowork Monitoring

    Session Replay and Bring Your Own Bucket

    Capture screen recordings around endpoint exfiltration events and store them in your own cloud bucket.

    Session Replay (shown in the console as Record Before & After) captures the user's screen around an endpoint exfiltration event so investigators can review what happened. You can store those recordings in a cloud bucket that your organization owns.

    This capability is available for macOS and Windows endpoint policies.

    How it works

    1. Enable Session Replay for your organization in Endpoint settings.

    2. Connect a storage bucket (or use Nightfall-managed storage, if it is enabled for your account).

    3. Turn on Record Before & After on each endpoint exfiltration policy that should capture recordings, and choose the storage destination.

    4. When that policy detects an exfiltration event, Nightfall records the screen for a window before and after the event and writes the recording to the selected bucket.

    5. Open the event in Nightfall to play the recording.

    If an event matches more than one policy with recording enabled, Nightfall can write the recording to each policy's selected bucket.

    Area
    Support

    On macOS, the Nightfall agent requires Screen Recording permission to capture recordings.

    Your bucket stores the session recordings captured around matching exfiltration events.

    Nightfall writes a recording when a policy with Record Before & After enabled is triggered. The recording covers the configured window before and after the event.

    Nightfall recommends enabling encryption on the bucket (for example, AWS SSE-KMS, Google CMEK, or Azure customer-managed keys). Encryption is a best practice and is not required to connect the bucket.

    • The Nightfall endpoint agent is installed and connected on the device.

    • Session Replay is enabled in Endpoint → Settings.

    • A storage destination is available: a connected customer bucket, or Nightfall-managed storage if it is enabled for your account.

    • The Nightfall user who connects buckets has bucket management access.

    1
    1. In Nightfall, open Endpoint.

    2. Open the Settings tab.

    3. Enable Session Replay / Record Before & After.

    Nightfall accesses the bucket with a cross-account IAM role. No long-lived access keys are stored.

    What you enter in Nightfall

    Field
    Description

    Create an IAM policy that grants Nightfall access to the bucket. Replace YOUR_BUCKET_NAME and, if you use SSE-KMS, YOUR_KMS_KEY_ARN.

    If the bucket does not use KMS, you can omit the KMSAccess statement.

    1. In the AWS IAM console, create a role.

    2. Trusted entity: AWS account

    Nightfall accesses the bucket by impersonating a service account in your Google Cloud project.

    What you enter in Nightfall

    Field
    Description
    1. Create a GCS bucket in your project.

    2. Create a dedicated service account (for example, nightfall-dlp-worker@YOUR_PROJECT.iam.gserviceaccount.com).

    3. Grant that service account Storage Object Admin and Storage Legacy Bucket Reader on the bucket.

    1. If the bucket uses a customer-managed encryption key, grant the Cloud Storage service agent Cloud KMS CryptoKey Encrypter/Decrypter on that key.

    2. Enter the bucket name and service account email in Nightfall and connect the bucket.

    Nightfall accesses the container with federated identity. No long-lived secrets are exchanged.

    What you enter in Nightfall

    Field
    Description
    1. Create a storage account and a container for recordings.

    2. Create a managed identity or app registration and add a federated credential. Nightfall provides the OIDC issuer, audience, namespace, and service account values during setup.

    3. Grant the identity Storage Blob Data Contributor and Storage Blob Delegator on the storage account.

    4. Optionally grant Reader on the storage account so Nightfall can check lifecycle policies.

    Situation
    What to check

    MCP Server Visibility

    AI Governance is the Nightfall console for MCP (Model Context Protocol) servers on developer machines. It covers local stdio servers and remote HTTP/SSE servers used by clients such as Claude Code, Cursor, VS Code, Windsurf, Codex, Copilot, and others.

    Go to AI Governance. With the current inventory experience you get:

    • Inventory, with sub-tabs for MCP servers, Hooks, and Plugins

    • Collections

    • Users & Devices

    • Settings (notification triggers and alert channels)

    Some tenants still see the older Server Inventory tab (servers only, no Hooks, Plugins, or Settings). If that is what you have, ask your Nightfall account team to enable the current AI Governance experience.

    This page is about what is actually running on endpoints. Sanctioned remote servers that you want clients to call through Nightfall are documented on .

    Filter High or Critical risk, or look for the Shadow badge, when you want unsanctioned servers first.

    Use risk plus the tool list when you need to know whether a server only reads data or can write and delete.

    Use the Managed filter when you want the list of servers that came from an org-managed config file. Treat project-level configs as extra review when they name servers that are not on your approved list.

    When a DLP alert involves an agent tool call, open the server here. You can see the device, the user, the tools, and the config file that was in place.

    Put approved servers in a collection, then scope an endpoint exfiltration policy to all MCP servers, only those collections, or everything except those collections. Binding by fingerprint keeps the policy on the same server if someone renames it in mcp.json.

    MCP data shows up only when the endpoint agent can collect it:

    • macOS: Nightfall Agent v1.2.12.11 or later, plus MDM Profile v3. The agent can auto-update. The profile does not. IT or SecOps has to deploy v3. The profile ships in the macOS agent bundle from v1.2.12.9 onward.

    • Windows: Nightfall inventories MCP on Windows endpoints the same way. Confirm the minimum Windows agent build with your Nightfall account team.

    Hooks and Plugins need the current inventory experience and the extra telemetry those views use. If servers appear but Hooks and Plugins do not, check the tenant experience first, then the agent version with Nightfall.

    Inventory > MCP servers is the org-wide table. Each row is one server. The name cell can also show Managed and Shadow.

    Column
    What it means

    Recognized clients include Claude Code, Cursor, VS Code, Claude Cowork, Claude (including Claude Desktop), Windsurf, Codex, Copilot, and Antigravity. Anything else stays in the unrecognized list.

    stdio: count of local process starts. The detail header labels this Process Starts. One typical agent session that uses the server is one start.

    http / sse: bytes sent and bytes received (shown with up/down markers). High outbound volume is the number to look at if you are worried about data leaving the device.

    Open a row for the server page. Tabs are Overview and Devices.

    • About: description from the public MCP registry. If the server is not listed, the card says so and points you at Identity.

    • Identity: Endpoint (remote URL, HTTP servers only), Package, Version, Source (repository link), Transport, Fingerprint (the server id), and Configured As (each configured name plus how many tools that name has).

    • Risk score: composite level and the signal groups behind it.

    The header actions are Add to collection, Override risk, and Override provenance.

    Who is using the server, on which endpoint, through which host app. Rows can also show provenance, risk, clients, and a logo when Nightfall can resolve one from the remote URL.

    Each observation is tagged Config file, Process start, and/or Network, depending on how it was seen.

    Nightfall keeps versions of the config files that mention the server, for example ~/.claude.json, .cursor/mcp.json, or the VS Code user-level mcp.json.

    Files group by client and by scope: Global (all projects for that user) or Project (one repo or workspace). You get the path, the scope badge, last modified, and the file body at each version (v1, v2, and so on).

    The Risk score card uses Known, Low, Medium, High, or Critical.

    Signals are grouped as:

    Group
    Question

    Each group has a contribution. Thin evidence gets a low confidence badge. Groups that do not apply are greyed out.

    The written explanation is generated after the score. While that runs, the card shows Analyzing risk and the group breakdown is still the source of truth. If explanation generation fails, the breakdown stays and Nightfall retries on the next recompute.

    To override: Override risk, pick Critical, High, Medium, or Low (not Known), and enter a reason. The card then shows the computed level, the level you set, who did it, when, and the reason. Revert to auto-detected clears the override.

    Every discovered tool gets a category and a severity.

    • Category: Read-only, Read-write, or Destructive

    • Severity: Low, Medium, High, or Critical

    Filter pills on the Tools card jump to a category or severity. You can override both values on a tool and clear the override later.

    Provenance is where the server came from:

    • First-party: an admin added it as your organization's own

    • Official: matches a verified registry entry

    • Community: published in a community marketplace

    • Unknown: source could not be determined

    Admins can override provenance and revert it.

    Managed means the install came from an org-managed config file (admin or MDM). You can filter servers, hooks, and plugins to Managed.

    Shadow means the server is not tied to a recognized MCP client, so it is running outside governed tooling. That raises its risk score.

    A developer-added server inside Claude Code or Cursor is usually neither Managed nor Shadow.

    Inventory > Hooks lists event-triggered commands that clients run during an agent session (for example a shell command before a tool call).

    Columns:

    • Event: lifecycle event. Org-deployed hooks can show Managed

    • Handler: how the hook is invoked

    • Command: what it runs

    • Client: which AI application owns it

    Filter by event or Managed. Open a hook for the full definition and the device list.

    Inventory > Plugins lists extensions installed into AI clients. A plugin can ship its own MCP servers and hooks.

    Columns include name and marketplace, Status, Trust, Provenance, client, and device count.

    Status values are Available, Installed, and Enabled. The list hides Available (seen in a marketplace, not on a device) until you add it in the Status filter.

    Trust is Allowed or Blocked, from the client's own trust state.

    Open a plugin for the servers it bundles (transport, risk, provenance), the hooks it bundles (event and handler), and the devices that have it.

    Users & Devices is the fleet view. Open a device for MCP servers, Hooks, and Plugins, each with a count.

    Config files on that device are scanned. Scan status is shown, including when a scan produced a violation.

    Collections are named sets of servers. You use them in reports and in endpoint exfiltration policies.

    From a server page, Add to collection has two steps: Group selection, then Tool selection.

    On group selection you either bind the entire server by fingerprint (default; every configured name stays in the collection) or pick specific configured names. Fingerprint-bound entries show Bound by fingerprint in collection management.

    Manage collections under AI Governance > Collections.

    In an endpoint exfiltration policy, MCP scope is:

    • All MCP servers

    • Specific MCP servers (the collections you pick)

    • All except these MCP servers

    You can create a collection from the policy wizard (Create new collection). You can also add tool-name patterns. Those patterns are exclusions when the scope is All except these MCP servers. Details: .

    AI Governance > Settings has two parts.

    Notification triggers (nothing is sent until you save a preference; a company with no saved preferences is opted out):

    Area
    Events

    Alert channels use Nightfall's standard integrations. You need at least one channel or nothing is delivered. Typical channels are email, Slack, and webhook.

    A practical first save is config file Added, hook Added, and plugin Installed.

    Opt out of all notifications clears every trigger.

    Nightfall Hooks for Cursor

    This guide walks an MDM administrator through deploying Nightfall's Cursor hooks to corporate-managed developer devices, end to end. It covers all five supported MDMs in detail. The deployment package ships as a zip (Hooks Setup/cursor/) containing this payload, the install scripts, and a README.md quick reference. This guide is the long-form companion to that README.


    This guide is for Cursor, which requires a MDM deployment of a system-level hooks.json.

    Use the automatic path for Claude Code and VS Code. Use this guide to add reliable hook coverage for Cursor on managed devices.


    Cursor reads its hook configuration from a single file at a fixed path and a fixed name (

    Cursor

    Yes (via Claude Code)

    No

    Block or Monitor

    VS Code

    Yes (via Claude Code)

    No

    Block or Monitor

    Claude Cowork

    No

    Yes

    Monitor only

    Tool Calls

    Before a tool executes

    Tool name and input parameters

    Yes

    Tool Responses

    After a tool finishes executing

    Tool name and output content

    Yes (Not supported in VS Code Copilot)

    Model Responses

    After a model finishes evaluating task

    Model response

    No

    Shell Commands

    Before a shell command executes

    Full shell command string

    Yes

    Read Mobile Device Inventory Collection
  • Read Computers

  • API roles: Select the newly created role.

  • Enable/disable API Client: Enable the API client.

  • Click Save

  • Copy the Client ID and Client Secret. You will need these in the next step.

  • The MDM profile has to be deployed on target machines prior to deploying additional payload. In Jamf, you can enforce this requirement through the creation of a Smart Group in which you can set the presence of the profile created above as a pre-requisite for any other payload targeting the group.

    Enforcement

    Works with monitor, warn, and block policies

    Storage

    Amazon S3, Google Cloud Storage, and Azure Blob Storage

    Nightfall-managed storage

    Available when Nightfall has enabled it for your account

    Displays

    Multiple monitors

    Playback

    Exfiltration event Replay view, including timeline controls and event markers

    The Nightfall user who plays recordings has screen recording access.

  • On macOS, Screen Recording permission is granted to the Nightfall agent.

  • Review Snapshot Frequency (every 1–5 seconds) and the Recording Window shown for the time before and after an event.

    Snapshot frequency is configured at the organization level and applies to policies that have recording enabled.

    2

    Connect a storage bucket

    1. Go to Settings → Storage Buckets.

    2. Click Connect Bucket (or use the command palette and search for Connect Bucket).

    3. Choose Amazon S3, Google Cloud Storage, or Azure Blob Storage.

    4. Complete the cloud setup for that provider, then enter the connection details in Nightfall.

    5. Nightfall validates access (write, read, and delete) before saving the bucket.

    A successful connection may still show a warning if the bucket's lifecycle policy could remove recordings earlier than 180 days. You can continue and adjust the lifecycle policy in your cloud console.

    Bucket statuses:

    • Active — Nightfall can store recordings.

    • Inactive — Access failed a health check. Use Reconnect after you restore permissions.

    • Disabled — The destination is turned off for the account.

    You cannot delete a bucket that is still selected on a policy. Remove it from those policies first.

    3

    Enable recording on the policy

    1. Create or edit an endpoint exfiltration policy.

    2. On the Automated Actions step, enable Record Before & After.

    3. Under Storage Destination, select the bucket for this policy.

    4. If Nightfall-managed storage is available, you can keep Use Nightfall-managed storage (default) selected instead of a customer bucket.

    5. Save the policy.

    The policy toggle is available only after Session Replay is enabled for the organization. If no customer bucket is connected and Nightfall-managed storage is not available, connect a bucket before you save the policy.

    4

    View a recording

    1. Open Exfiltration Prevention and select an event.

    2. On the event summary, click Replay.

    3. Use the timeline to move through the recording. If the device has more than one display, switch between monitors in the player.

    If the recording is still arriving from the device, the player shows that screenshots are still uploading. Refresh the event after a few minutes.

    →
    Another AWS account
    .
  • Account ID: 053737762392 (Nightfall).

  • Enable Require external ID and paste the External ID shown in Nightfall (your Company ID).

  • Attach the IAM policy from the previous tab.

  • Copy the role ARN into Nightfall and connect the bucket.

  • Grant the service account permission to sign requests (roles/iam.serviceAccountTokenCreator on itself).
  • Allow Nightfall's hub service account to impersonate your service account:

  • Client ID

    Application (client) ID of the identity Nightfall uses

    Subscription ID and Resource group

    Optional. Include these if you want Nightfall to check lifecycle policies

  • If you use customer-managed keys, grant Key Vault Crypto Service Encryption User on the key.

  • Enter the values in Nightfall and connect the bucket.

  • macOS devices are not producing recordings

    Confirm Screen Recording permission is granted to the Nightfall agent.

    Player says screenshots are still uploading

    Wait for the post-event window to finish, then refresh the event.

    Player cannot load the recording

    Confirm the bucket is Active and that lifecycle rules have not removed the recording.

    You cannot delete a bucket

    Remove the bucket from every policy that uses it as the storage destination, then delete it.

    Platforms

    macOS and Windows

    Policies

    Endpoint exfiltration policies

    Triggers

    Bucket name

    Name of the S3 bucket

    IAM Role ARN

    Role Nightfall assumes to access the bucket

    External ID

    Bucket name

    Name of the GCS bucket

    Service account email

    Service account Nightfall impersonates

    Storage account name

    Azure storage account

    Container name

    Blob container for recordings

    Tenant ID

    Record Before & After is disabled on the policy

    Enable Session Replay in Endpoint → Settings.

    Nightfall asks you to connect a bucket before saving

    Connect a bucket in Settings → Storage Buckets, or select Nightfall-managed storage if it is available.

    Bucket is Inactive

    What is supported

    What is stored in your bucket

    Keep recordings in the bucket for at least 180 days. If a lifecycle rule deletes objects sooner, investigators may not be able to play older events.

    Requirements

    Enable Session Replay

    Turn on Session Replay for the organization

    Connect Amazon S3

    Connect Google Cloud Storage

    Connect Azure Blob Storage

    Troubleshooting

    Any endpoint trigger that produces an exfiltration event, including browser uploads, clipboard paste, desktop apps, cloud sync, removable media, print, and Git push

    Filled automatically with your Nightfall Company ID

    Microsoft Entra tenant ID

    Restore write, read, and delete access in your cloud account, then use Reconnect. Recordings may not store correctly while the bucket is inactive.

    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Sid": "S3Access",
          "Effect": "Allow",
          "Action": [
            "s3:PutObject",
            "s3:GetObject",
            "s3:DeleteObject",
            "s3:ListBucket",
            "s3:GetBucketLocation",
            "s3:GetLifecycleConfiguration"
          ],
          "Resource": [
            "arn:aws:s3:::YOUR_BUCKET_NAME",
            "arn:aws:s3:::YOUR_BUCKET_NAME/*"
          ]
        },
        {
          "Sid": "KMSAccess",
          "Effect": "Allow",
          "Action": [
            "kms:GenerateDataKey",
            "kms:Decrypt",
            "kms:DescribeKey"
          ],
          "Resource": "YOUR_KMS_KEY_ARN"
        }
      ]
    }
    gcloud iam service-accounts add-iam-policy-binding YOUR_SERVICE_ACCOUNT_EMAIL \
      --role="roles/iam.serviceAccountTokenCreator" \
      --member="serviceAccount:saas-hub-operator@gcs-byod-prod.iam.gserviceaccount.com"

    Provenance

    First-party, Official, Community, or Unknown. See .

    Users

    How many users have this server.

    Clients

    Recognized AI clients plus any unrecognized process names. A +N chip means more clients than the row can show.

    Volume

    For stdio: how many times the process started. For remote: data sent and received.

    Last Activity

    Last time any device used the server.

    Tools: classified tool list.
  • Clients: recognized clients and a count of unrecognized ones.

  • Collections: collections this server is bound to.

  • Behavioral

    What is it doing?

    Devices: how many endpoints have it

    Server Name

    Name reported by the device (from mcp.json, claude.json, or similar). Remote container images often show as an image name. Version appears under the name when Nightfall has it.

    Type

    Transport. stdio is a local subprocess (no outbound network). http / sse are remote and send data off the device.

    Risk

    Capability

    What can it do?

    Provenance

    Who made it?

    Governance

    MCP Servers

    Config file changes: Added, Removed, Updated. Runtime detections: stdio servers, Remote servers

    Hooks

    Hook changes: Added, Removed, Updated

    Plugins

    Use cases

    Prerequisites

    If the Mac MDM profile is still below v3, AI Governance stays empty for those devices even when the agent is current and the feature is on for your tenant.

    MCP servers

    Volume

    Server details

    Overview

    Devices

    Configuration file versions

    Risk

    Tools

    Provenance, Managed, and Shadow

    Hooks

    A hook can run arbitrary commands inside an agent session. Use this list to confirm you only have the hooks you expect, including Nightfall's own protection hooks. How to install those is under Auditability and Control.

    Plugins

    Users and devices

    Collections and policies

    Notifications

    MCP Gateway
    Creating an AI Agent Security Policy

    Known, Low, Medium, High, or Critical. A small dot on the badge means an admin overrode the computed level.

    Is it sanctioned?

    Plugin changes: Installed, Enabled, Disabled, Uninstalled

    hooks.json
    ). Deployment is a
    two-step model
    :
    1. Stage the payload. Your MDM's file-distribution (or app-deployment) feature drops Nightfall's hooks.json at a staging path on each device.

    2. Run the merge script. A script provided in the package splices Nightfall's entries into Cursor's hooks.json at the path Cursor actually reads.

    The file Cursor reads (hooks.json) is shared - another security vendor or your own org policy may already own entries in it. And because the filename and path are dictated by Cursor, you can't rename or relocate it without Cursor ceasing to read it.

    So the install scripts merge: they drop any existing Nightfall-marked entries, then append the staged Nightfall entries, leaving every other vendor's entries untouched. This makes re-runs idempotent - periodic re-execution never accumulates duplicates.


    Before deploying the Cursor hooks payload:

    1. The Nightfall endpoint agent is already installed and running on the managed devices. The agent owns the nightfall-hook-relay binary the hooks invoke.

    2. You've selected the MDM scope (device group / smart group) that will receive the deployment.

    3. jq is present on macOS devices where a hooks.json may already exist. The macOS install script refuses to run — rather than clobber another vendor's entries - if a target hooks.json exists and jq is not installed. (Greenfield devices with no existing hooks.json do not need jq.)


    The scripts are MDM-agnostic - the same install.sh works whether your MDM is Rippling, Jamf Pro, Kandji, or Workspace ONE. The per-MDM sections below show which MDM feature to wire each script into.


    Nightfall registers four Cursor events. The two pre-action events carry failClosed: true, which blocks the action if the hook crashes, times out, or returns invalid JSON.

    Event

    When it fires

    failClosed

    beforeSubmitPrompt

    Before a prompt is submitted to the model

    true

    preToolUse

    Before a tool executes

    All four invoke the same command: nightfall-hook-relay --source cursor.

    failClosed: true on the pre-action events (beforeSubmitPrompt, preToolUse) means the action is blocked if the hook can't complete cleanly. The post-action events (postToolUse, afterAgentResponse) observe content after the action has already happened, so they monitor only there is nothing left to block.


    macOS

    Windows

    Staging path (MDM drops the payload here)

    /opt/nightfall/hooks/cursor/hooks.json

    C:\Nightfall\Hooks\cursor\hooks.json

    Target path (Cursor reads from here)

    /Library/Application Support/Cursor/hooks.json

    The target path and filename are dictated by Cursor and must not be changed.

    On macOS, a greenfield device (no existing target hooks.json) is handled by a plain cp - no jq required. If a target already exists, the script requires jq to merge and refuses to run without it. On Windows, the merge runs in PowerShell, writes the result as UTF-8 without a BOM, then locks the file down with icacls.


    Every MDM follows the same two-step wiring: distribute the payload to the staging path, then run the install script to merge it into Cursor's hooks.json. The install scripts hard-fail unless run as root (macOS) or SYSTEM / Administrator (Windows), so always run them in a System / SYSTEM context.

    macOS

    1. Distribute the payload — Use Rippling's file/app distribution to place payloads/hooks.json at /opt/nightfall/hooks/cursor/hooks.json.

    2. Run the merge — Create a Custom Script that runs scripts/macos/install.sh at System scope, triggered on enrollment and daily.

    Windows

    1. Distribute the payload to C:\Nightfall\Hooks\cursor\hooks.json.

    2. Run the merge - Create a PowerShell Script that runs scripts/windows/install.ps1 at SYSTEM scope.

    macOS

    1. Distribute the payload to /opt/nightfall/hooks/cursor/hooks.json (e.g. via a package or a Files and Processes distribution).

    2. Run the merge - Add scripts/macos/install.sh as a Script, then attach it to a Policy scoped to your device group with the triggers Recurring Check-in and Enrollment Complete.

    macOS - Kandji's Custom Script library item pairs an audit script with a remediation script, which matches the package's presence-check model exactly:

    1. Distribute the payload to /opt/nightfall/hooks/cursor/hooks.json (Custom App or file distribution).

    2. Audit - Set scripts/macos/audit.sh as the Audit Script. It exits 0 when Nightfall's command is already present and exits 1 when remediation is needed.

    3. Remediation - Set scripts/macos/install.sh as the Remediation Script. Kandji runs it only when the audit reports drift.

    Windows - Wire into a Win32 / Proactive Remediation (Detection + Remediation):

    1. Distribute the payload to C:\Nightfall\Hooks\cursor\hooks.json (e.g. a Win32 app).

    2. Detection - Use scripts/windows/detect.ps1 as the Detection script. It exits 0 (present) when Nightfall's command is already in hooks.json and exits 1 to trigger remediation. Run it in the SYSTEM context (64-bit PowerShell).

    3. Remediation - Use scripts/windows/install.ps1 as the Remediation script, also in the SYSTEM context.

    Workspace ONE covers both platforms via its Scripts feature, run in the System / SYSTEM context with Periodic and Enrollment triggers.

    macOS

    1. Distribute the payload to /opt/nightfall/hooks/cursor/hooks.json.

    2. Run the merge - Add scripts/macos/install.sh as a Script in the System context, scheduled Periodic + on Enrollment.

    Windows

    1. Distribute the payload to C:\Nightfall\Hooks\cursor\hooks.json.

    2. Run the merge - Add scripts/windows/install.ps1 as a Script in the SYSTEM context, scheduled Periodic + on Enrollment.


    Open the Devices page in the Nightfall console. Each device shows a per-client hook status indicator - a healthy status for Cursor means the deployment is working on that device. A healthy Cursor hook status on the Devices page confirms the payload was staged, the merge script ran, and Cursor is reading Nightfall's entries.


    The audit/detection scripts (audit.sh / detect.ps1) check for the presence of Nightfall's command in hooks.json (a grep / regex match), not byte equality. Byte equality with the staged payload isn't meaningful because hooks.json is shared with other vendors.

    The install scripts are idempotent: each run drops any existing Nightfall-marked entries and re-appends the staged ones, so periodic re-execution never accumulates duplicates and never disturbs other vendors' entries.

    If the staging payload hasn't been deployed yet, the audit/detection scripts report present / exit 0 rather than failing. Remediation couldn't succeed without the staged file, so this stops the MDM from looping on a state it can't fix from the device.


    To remove Nightfall's Cursor hooks, hand-edit hooks.json on the device (or push an edited copy via your MDM) and remove every entry whose command is nightfall-hook-relay --source cursor. Leave all other vendors' entries - and your own org policy's entries - untouched.

    The nightfall-hook-relay binary stays installed; the Nightfall endpoint agent owns its lifecycle.

    A scripted rollback may be added in a future release. For now, removal is a manual entry edit.


    Symptom

    Likely cause

    Resolution

    macOS install exits with "jq is not installed"

    A hooks.json already exists and jq is missing, so the script refuses to merge

    Install jq on the device and re-run the install script

    Install exits with "must run as root" / "administrator privileges"

    Script ran in a user context


    • Cursor enterprise hooks bug (Feb 2026): Hooks configured in Cursor's admin dashboard sometimes don't materialize at the expected endpoint path. MDM-deployed hooks.json is the reliable path until Cursor resolves this.

    • Cursor cloud agents don't yet honor team/enterprise-managed hooks — only a project-committed .cursor/hooks.json runs in cloud sessions. The MDM deployment in this guide covers local Cursor sessions on managed devices.


    When to use this guide

    Why Cursor needs a manual path (Cursor enterprise hooks bug, Feb 2026): Hooks configured in Cursor's admin dashboard sometimes don't materialize at the endpoint path Cursor reads from. Until Cursor resolves this, deploying hooks.json directly through your MDM is the reliable way to enforce Nightfall hooks in Cursor.

    How it works

    payloads/hooks.json                    # Nightfall's Cursor hook entries
    scripts/macos/install.sh               # MDM-agnostic merge (idempotent on re-run)
    scripts/macos/audit.sh                 # presence check (grep)
    scripts/windows/install.ps1            # MDM-agnostic merge (idempotent on re-run)
    scripts/windows/detect.ps1             # presence check (regex match)
    README.md
    

    Why merge instead of overwrite

    Prerequisites

    Package contents

    Hooks installed

    Paths reference

    Per-MDM setup

    Rippling

    Jamf Pro

    Kandji

    Microsoft Intune

    Workspace ONE

    Validation

    Drift & re-run behavior

    Rollback

    Troubleshooting

    Known issues / notes

    Session Detection: Corporate and Personal Account Filtering

    Overview

    User session detection allows Nightfall to distinguish between corporate and personal account activity on supported web domains. When enabled in an Endpoint Exfiltration policy, Nightfall uses browser session context to determine whether data is being uploaded from (or pasted to) a corporate account or a personal account. This lets you create policies that, for example, only trigger on uploads from corporate Google Drive or only flag paste actions to personal ChatGPT.

    Session detection requires the Nightfall browser extension to be installed and connected. It works by inspecting the active browser session on supported domains to determine account ownership.


    Supported Domains

    Session detection is available on the following 32 domains, organized by category:

    The supported domains pill in the policy UI groups these into display categories:

    • Google Workspace: Docs, Gmail, Calendar, Meet, Drive, Keep

    • Microsoft 365: Teams, SharePoint, Outlook, OneDrive, Office apps

    • Cloud Storage: Box, Dropbox, iCloud

    • AI Assistants: Claude, ChatGPT, Gemini, Copilot, Perplexity


    When creating or editing an Endpoint Exfiltration policy, the Trigger step is where you configure session detection. The Trigger step contains two main sections: Asset Origin and Action.

    The Action dropdown selects the type of endpoint activity to monitor. Available actions:

    • AI Agent Security - Monitors AI agent activity (Claude Code, Cursor, VS Code, Claude Cowork)

    • Browser uploads to - File uploads through the browser

    • Cloud syncing to - Cloud sync applications (Google Drive, Dropbox, OneDrive, Box, iCloud)

    • Git Push to - Git push operations to remote repositories

    The Asset Origin section lets you scope monitoring to assets originating from specific sources:

    1. Select Source (Domain / URL-Based) from the scope dropdown

    2. Choose Source in or Source not in to include or exclude specific domain collections

    3. Select a domain collection from the collection picker

    When you select collections, each collection pill displays with color coding:

    • Violet: The collection contains domains that support session detection and session check is enabled

    • Default: Standard collection display

    When the selected source collections include domains that support session detection, the Corporate accounts only toggle appears. Enabling this toggle restricts the policy to only trigger on data originating from corporate account sessions on supported domains.

    The toggle only appears when:

    • The action is Browser uploads to, Paste to, or Git Push to

    • The scope is set to Source in (not "Source not in" or "Any source")

    • At least one selected collection contains session-detection-supported domains

    For actions like Browser uploads to, Paste to, and Git Push to, you can also scope the destination:

    1. Select the action type from the dropdown

    2. Choose destination scope (Any, specific collections included, or specific collections excluded)

    3. Select domain collections for the destination

    When the selected destination collections include domains that support session detection, the Personal accounts only toggle appears. Enabling this toggle restricts the policy to only trigger on data sent to personal account sessions on supported domains.

    The toggle only appears under the same conditions as the Corporate toggle (appropriate action type, "Source in" scope, and session-detection-supported domains in the selected collections).

    When you select a domain collection, the UI shows an "X of Y domains supports session detection" indicator. This tells you how many of the domains in your selected collection are in the supported domains list. For example, if your collection has 10 domains and 6 are in the supported list, it shows "6 of 10 domains supports session detection."

    Content Scanning configuration has been moved from the Scope step to the Trigger step, keeping all trigger-related settings in one place.


    Action Type
    Session Detection Available
    Notes

    By default, with no session detection enabled, Nightfall monitors all uploads and paste events across all account types on all configured domains - it does not distinguish whether a user is in a personal Google account or a corporate Workspace account.

    Session detection lets you scope monitoring to an account context. There are two independent toggles, each controlling a different axis:

    Toggle
    What it does
    When to use it

    These toggles are independent - enabling one does not affect the other.

    Behavior by state

    Source toggle
    Destination toggle
    What is monitored

    Session detection coverage is domain-dependent. Not all domains in a collection support session detection. The UI shows how many domains in your selected collection are covered (e.g., "3 of 12 domains across 2 collections support session detection"). Domains outside coverage are always monitored for all account types, regardless of toggle state. If none of the selected domains support session detection, the toggle has no effect and all domains are monitored for all account types.


    Destination toggle - personal account monitoring

    The most common pattern. Enable this when your primary concern is data ending up in a personal account on a domain your organization also uses corporately.

    Common policies seen in practice:

    • "Block Uploads to Personal Storage Accounts"

    • "PII to Personal Accounts"

    • "ChatGPT/Claude/Dropbox - Uploads to Personal Accounts"

    • "PHI Upload to Personal Account"

    Why this matters: On domains like drive.google.com, dropbox.com, or chatgpt.com, the same domain hosts both corporate and personal accounts. Without session detection, a policy scoped to these domains fires on all uploads - including uploads from an employee using their company-issued Google Workspace account, which is typically approved. Enabling the destination toggle narrows the policy to only fire when the upload goes into a personal session, eliminating noise from legitimate corporate activity.

    Recommended use:

    • Cloud storage: Separate a policy for drive.google.com personal from corporate Workspace. Enable destination toggle; scope collection to personal Google accounts.

    • AI tools: Most AI tools (ChatGPT, Claude) don't have a corporate/personal domain split - chatgpt.com is used by both. If your organization has a corporate ChatGPT Enterprise deployment on a subdomain, use the destination toggle on the public domain to filter for personal sessions only.

    • Sanctioned vs. unsanctioned: Some organizations run two policies on the same domain - one with session detection (alert-only for personal account use) and one without (broader coverage for truly unsanctioned destinations).


    Source toggle - corporate account monitoring

    Enable this when you want to track data that originated from a corporate account, regardless of where it ends up - including destinations that don't support session detection.

    Common policies seen in practice:

    • "Personal Account Upload From Corporate Account"

    • "Block Uploads of Corporate Docs to Unsanctioned Apps"

    • "Monitor Uploads of Customer Lists to Unsanctioned Cloud Storage"

    • "Departing Users - Block Google Workspace"

    Why this matters: The destination toggle only catches events where the destination domain supports session detection. If an employee copies a file from their corporate Google Drive and uploads it to a small SaaS tool or a domain that Nightfall can't distinguish account types on, the destination toggle misses it. The source toggle catches it because it evaluates account context at the point of copy, not the point of upload.

    This is also the appropriate pattern for departing user policies, where the goal is to track all outbound movement from corporate accounts during an offboarding window - regardless of destination.

    Recommended use:

    • Departing users: Enable source toggle scoped to all corporate domain collections. Apply to a user group or device scope targeting the departing user.

    • Broad corporate data egress: When you want to monitor "anything that left a corporate account session today" as an audit trail, source-only gives you the widest coverage without depending on destination session support.

    Important: Source-only policies deliberately monitor destinations outside Nightfall's session detection coverage. This is by design, not a misconfiguration. Do not add a destination toggle to these policies expecting it to refine them - it will instead restrict coverage and may miss the exfiltration paths the policy was built to catch.


    Applies to: Browser Uploads, Clipboard Paste, Git Push Monitoring

    Session detection works identically for these three triggers. For clipboard paste, the source toggle checks which account session the copied content came from; the destination toggle checks where the paste event lands. Given that clipboard events often land on domains with limited session detection support (note-taking apps, internal tools, miscellaneous SaaS), source-only session detection is generally more effective for clipboard monitoring than destination-only. For git push monitoring, content scanning is not supported - Nightfall monitors the source code originating from a corporate organization and subsequently getting transferred to a non-corporate organization or repository.


    The toggle only appears when all three conditions are met:

    1. The action type supports session detection (Browser uploads, Paste to browser)

    2. The collection scope is set to Source in (specific included collections)

    3. At least one domain in the selected collections supports session detection

    If your selected collections don't include any of the 32 supported domains, the toggle will not appear.

    This indicator shows how many domains in your selected collection are in Nightfall's supported domains list. Only those domains will have session-level account detection. Other domains in the collection will still be monitored but without corporate/personal distinction.

    Check the following:

    1. Supported domains: Verify the source domains are in the supported list above

    2. Browser extension: Ensure the Nightfall browser extension is installed, enabled, and connected on the user's device

    3. Correct browser: Session detection requires a supported browser with the extension (Chrome, Edge, Firefox). Safari require the extension to be installed separately

    4. Not incognito

    • Git Push to: Yes, session detection is available

    • Print: No. Print operations don't have browser context

    • To removable media: No. File transfers to external drives don't involve browser sessions

    • CLI Transfer / AirDrop / Bluetooth: No. These triggers do not use browser session context. Corporate accounts only and Personal accounts only do not appear.

    See the Supported Domains section above for the full list of 32 supported domains organized by category.

    The Corporate/Personal accounts only toggle will not appear. The policy will still work for monitoring the selected domains, but without the ability to distinguish between corporate and personal accounts.


    Session detection is not available in the following scenarios:

    • Actions without browser context: Cloud syncing, Print, To removable media, Uploads to desktop app, CLI Transfer, AirDrop, and Bluetooth operate outside the browser and cannot access session information

    • AI Agent Security: This action type uses hooks and OpenTelemetry for monitoring, not browser context

    • Domains not in the supported list: Even with the browser extension installed, session detection only works on the 32 listed domains

    Forensics Search

    Perform insider risk investigations and threat hunting across all detected data exfiltration events — not only policy-triggered alerts.

    1. Overview

    2. Quickstart: Investigate Potential Data Exfiltration

    3. When to Use Forensic Search

    Forensic Search provides a searchable timeline of detected data exfiltration events across your employee base. The search events include all events for all supported exfiltration vectors — not only policy-triggered alerts.

    Security teams use Forensic Search to investigate how organizational data moves to external destinations such as cloud storage platforms, SaaS applications, and external email systems.

    The interface allows analysts to search, filter, and review exfiltration events to determine:

    • which user moved data

    • which device performed the action

    • where the data was sent

    • whether sensitive data was involved

    This enables rapid investigation of insider risk incidents and potential data exfiltration activity.

    Forensic Search with Date Range and Actions filter applied.

    Use the following steps to quickly investigate suspicious data movement.

    1. Navigate to Discovery → Forensic Search.

    2. Select the user of interest with User filter.

    3. Set the Time Range to Last 7 days.

    4. Add a Risk filter and select:

    Security teams use Forensic Search to investigate how organizational data moves to external destinations and to identify potential data exfiltration activity.

    Common investigation scenarios include:

    • Investigating departing employees

    • Reviewing unusual data transfer alerts

    • Performing threat hunting for data exfiltration

    • Auditing data movement to external services

    Forensic Search tool zeroing in on a suspicious cloud sync activity.

    Forensic Search allows analysts to reconstruct how data moved outside the organization by examining sequences of exfiltration events.

    Data exfiltration rarely occurs as a single action. Instead, it typically appears as a pattern of related events occurring over a short period of time.

    Security analysts often look for the following behavioral patterns when investigating potential exfiltration.

    Pattern
    Description
    Why It Matters

    Most investigations follow this workflow:

    1. Identify suspicious data movement or receive an alert.

    2. Filter events by user and/or time range.

    3. Review event details and destinations.

    4. Identify patterns of data movement.

    This workflow allows analysts to quickly determine whether activity represents legitimate work or potential data exfiltration.


    To assist in identifying potentially risky behavior, Nightfall assigns a risk score to individual exfiltration events observed in Forensic Search. Each event receives a risk level that helps analysts prioritize investigations and quickly surface higher-risk data transfers.

    Event-level risk scoring is currently in beta and is intended to provide investigation guidance rather than definitive risk determinations. Analysts should evaluate events within the broader context of user activity and look for patterns of behavior across multiple events, rather than relying on a single event score.

    Risk Level
    Meaning

    In the current release, event risk scores are calculated are based on two primary signals:

    1. Application Risk Level

    2. User Session Context (Corporate vs Personal Account)

    These signals help determine whether data is being transferred to a higher-risk application or outside corporate identity boundaries.

    Every destination application detected in an exfiltration event inherits a baseline risk level from App Intelligence.

    App Intelligence continuously discovers and classifies the web applications employees interact with. Each application is categorized based on its function and typical data exposure risk, such as:

    • Cloud storage

    • File sharing

    • Developer tools

    • GenAI and AI Agent tools

    Applications that enable easy external data transfer or lack strong identity controls typically carry higher baseline risk.

    Risk scoring also considers whether the user is operating within a corporate identity boundary.

    When available, Nightfall determines whether a user is authenticated to a corporate account or a personal account within the destination application.

    Examples:

    Scenario
    Risk Impact

    Transfers to personal accounts represent a significantly higher risk of data exfiltration because the organization does not control those accounts.


    Investigators can export results using Export Events.

    Exports include:

    • event fields

    • timestamps

    • risk scores

    Exports are commonly used for:

    • incident response documentation

    • compliance reporting

    • deeper analysis in SIEM platforms

    Exports respect active filters, allowing analysts to export specific investigation scopes.


    1. Open Forensic Search.

    2. Set the time range to Last 30 days.

    3. Filter by the employee's email.

    4. Review the timeline histogram for activity spikes.


    1. Set the time range to Last 7 days.

    2. Review the timeline for late-night activity.

    3. Zoom into suspicious time windows.

    4. Filter by High and Critical risk events.


    1. Filter by Upload or Cloud Sync.

    2. Filter by Critical and High risk events.

    3. Look for sequential transfers to external services.

    4. Review event details to confirm file types and destinations.


    Events can be searched for up to 180 days. Currently, the earliest available events begin on February 6, 2026, so searches cannot return events earlier than that date.


    Events typically appear within 30 minutes of occurring.


    Yes. Events matching current filters can be exported to CSV.


    Saved searches are planned for a future release.


    Access is controlled through Nightfall role-based permissions.

    Frequently Asked Questions (FAQs)

    No. It must be explicitly enabled in endpoint exfiltration policies.

    Session differentiation only applies to supported domains and actions. If unavailable, the field remains empty.

    Yes. Differentiation is based on account session, not just domain.

    Yes. Use Domain in with Corporate Domains and enable User Session Check.

    Nightfall automatically populates the Corporate Domains collection by analyzing user email addresses and email alias domains from all connected identity providers (IdPs), including Okta, Entra ID, and Google Directory. Any domain or alias domain associated with users in these directory services is treated as a corporate domain.

    The initial population happens when the Nightfall endpoint agent is first enabled (on the first provisioned OS, macOS or Windows). At that time, Nightfall fetches all user email and alias domains from the connected identity providers and populates the Corporate Domains collection.

    After the initial population, the collection is periodically refreshed (hourly) to capture any newly discovered domains or updates from the connected identity providers.

    Yes. All supported browsers provide identical protection across file uploads, clipboard actions, and personal vs. business enforcement.

    true

    postToolUse

    After a tool finishes executing

    -

    afterAgentResponse

    After the agent returns its response

    -

    C:\ProgramData\Cursor\hooks.json

    Re-run in the System (macOS) or SYSTEM (Windows) context via your MDM

    Install exits with "payload not found"

    The payload wasn't staged before the script ran

    Deploy hooks.json to the staging path first, then re-run

    Windows hooks.json fails to parse on re-run

    A UTF-8 BOM was written by an older PowerShell 5.1 run

    Re-run the current install.ps1 — it strips the BOM on read and writes UTF-8 without a BOM

    Cursor hook status not showing in console

    Hooks not yet merged, or agent not connected

    Confirm the install script ran successfully and the Nightfall agent is running on the device

    Provenance, Managed, and Shadow

    Paste to - Clipboard paste actions (browser or desktop apps)

  • Print - Print operations

  • To removable media - File transfers to USB/external drives

  • Uploads to desktop app - File uploads through thick/desktop applications

  • CLI Transfer - File upload or download through selected CLI tools (scp, curl, wget, rsync, aws s3, npm)

  • AirDrop - File transfers sent with Apple AirDrop

  • Bluetooth - Bluetooth file transfers (not pairing or audio)

  • : Session detection does not work in incognito/private browsing mode
    Browser extension not installed or disconnected: The extension must be installed, enabled, and actively connected
  • Incognito/private browsing: Browser extensions are typically disabled in private windows by default

  • Firefox/Safari without extension: These browsers require separate extension installation;

  • Domain collections with "Source not in" scope: Session check toggles only appear when using "Source in" (include) scope, not "Source not in" (exclude) scope

  • Category

    Domains

    Google Workspace

    *.google.com, docs.google.com, drive.google.com, mail.google.com, calendar.google.com, meet.google.com, cloud.google.com, keep.google.com, gemini.google.com

    Microsoft 365

    *.microsoft.com, teams.microsoft.com, teams.live.com, *.cloud.microsoft.com, *.cloud.microsoft, *.officeapps.live.com, *.sharepoint.com, *.live.com, outlook.office.com, outlook.office365.com, outlook.cloud.microsoft, onedrive.live.com

    Apple

    icloud.com

    Cloud Storage

    box.com, dropbox.com, *.dropbox.com

    AI Assistants

    chat.openai.com, chatgpt.com, claude.ai, perplexity.ai

    Browser uploads to

    Yes

    Requires browser extension

    Paste to (Browser)

    Yes

    Corporate accounts only (source)

    Only tracks events where the file or content originated from a corporate account session

    You care about where data came from

    Personal accounts only (destination)

    Only tracks events where the upload destination is a personal account session

    Off

    Off

    All events on all domains, no account-type distinction

    Off

    On

    Configuring User Session Check in a Policy

    Action Dropdown

    Data Source (From) - Asset Origin

    Corporate Accounts Only Toggle

    Data Destination (To) - Action Section

    Personal Accounts Only Toggle

    Session Detection Support Indicator

    Content Scanning

    Session Detection Support Matrix

    How it works

    Frequently Asked Questions (FAQ)

    Why is the Corporate/Personal toggle grayed out or not visible?

    What does "X of Y domains supports session detection" mean?

    I enabled Corporate accounts only but uploads aren't being blocked

    Does session detection work with Git Push / Print / Removable media?

    Which domains support session detection?

    What happens if I select a collection with no session-detection domains?

    Unsupported Scenarios

  • Critical

  • High

  • Sort the event table by Timestamp to review the most recent events first.

  • Scan the Destination column for external services such as:

    • personal cloud sync

    • personal accounts

    • file-sharing sites

  • Click any event to open the Event Detail Panel.

  • Review the following fields:

    • User – who performed the action

    • Asset – what file or content was transferred

    • Destination – where the data was sent

  • If suspicious activity is confirmed, include all events by deleting the Risk Filter, and click Export Events to download a CSV for documentation or further investigation.

  • Identifying early adopters of Gen AI and AI Agent tools

  • Investigating suspicious cloud storage activity

  • Export events for investigation documentation.

    Business SaaS

    Filter to Critical and High risk events.

  • Review destinations and file metadata.

  • Zoom in on suspicious events by clicking on timeline.

  • Remove Risk filter and expand date range to review surrounding behaviors.

  • Export relevant events for documentation.

  • Review upload destinations.

    Export events if escalation is required.

    Burst Uploads

    Large numbers of uploads occurring in a short time window.

    May indicate bulk data staging prior to exfiltration.

    Off-Hours Activity

    Transfers occurring late at night or on weekends.

    🚨 Critical

    Immediate investigation recommended

    🔴 High

    Elevated risk signals detected

    🟡 Medium

    Upload to corporate Google Drive

    Low risk

    Upload to personal Google Drive

    Critical risk

    Files uploaded or copy-pastes to a GenAI site using a corporate account

    Overview

    Quickstart: Investigate Potential Data Exfiltration

    Filtering to Critical and High risk events is the fastest way to identify suspicious data transfers.

    Investigating Data Exfiltration with Forensic Search

    Investigation Workflow

    Risk Scoring

    Risk Signals

    Application Risk Level

    provides the discovery and classification layer used for application risk scoring.

    User Session Context

    Session detection requires the Nightfall browser extension to be installed.

    Exporting Investigation Evidence

    Tutorials

    Investigating a Departing Employee

    Investigating Off-Hours Transfers

    Investigating Unusual Data Movement

    FAQs

    How far back can I search events?

    How quickly do events appear?

    Can events be exported?

    Can searches be saved?

    Who can access Forensic Search?

    Investigation Workflow
    Risk Scoring
    Common Investigation Patterns
    Exporting Investigation Evidence
    Tutorials
    FAQs

    Safari is supported but Nightfall has not yet enabled Safari extension distribution. As a result, customers cannot currently deploy a publicly available Nightfall plugin on Safari but can install a private package.

    Perplexity Comet’s Windows version prevents third-party browser extension installation, which blocks Nightfall deployment.

    ChatGPT Atlas is not available on Windows at this time.

    The below capabilities are not support on Perplexity Comet and OpenAI/ChatGPT Atlas.

    ChatGPT Atlas

    • Personal vs. Business, menu + paste blocking are not supported; File upload monitoring and blocking is supported

    • Sidebar assistant: Cannot monitor activity in the sidebar assistant

    Perplexity Comet

    • File upload monitoring and blocking is supported

    • Nightfall browser plugin cannot track activity until a URL is loaded

    • Paste-then-navigate scenario: If users paste content in the initial attempt before URL changes, Nightfall cannot track it

    • Menu + Paste scenarios: Not supported when you open and paste in a new tab; Cannot monitor content on new tabs ()

    No. Arc, Brave, and Vivaldi receive full feature parity with Chrome.

    Yes. Nightfall policies apply consistently across all supported browsers and operating systems.

    • macOS & Windows: Fully supported

    • Capabilities: File uploads, clipboard copy/paste, and personal vs. business detection

    • Notes: Full feature parity across both operating systems

    • macOS & Windows: Fully supported

    • Capabilities: File upload protection, clipboard monitoring, and personal vs. business enforcement

    • Notes: Equivalent security coverage to Chrome

    • macOS & Windows: Fully supported

    • Capabilities: Full data exfiltration protection including file uploads, clipboard actions, and personal vs. business detection

    • Notes: No functional differences across OS

    • macOS: Fully supported

    • Windows: Not supported

    • Capabilities: File uploads, clipboard protection, and personal vs. business detection

    • Notes: Full feature parity with Chrome

    • macOS: Fully supported

    • Windows: Not supported

    • Capabilities: Complete exfiltration protection including file uploads, clipboard actions, and personal vs. business detection

    • Notes: No feature gaps compared to Chrome

    • macOS: Fully Supported

    • Windows: Not supported

    • Capabilities: Full coverage for file uploads, clipboard monitoring, and personal vs. business enforcement

    • Notes: Consistent functionality across OS

    • macOS: Supported

    • Windows: Not supported

    • Capabilities (macOS): Exfiltration protection including file uploads, clipboard actions.

    • Notes: Windows version blocks third-party extension installation

    • macOS: Supported

    • Windows: Not supported

    • Capabilities (macOS): File uploads, clipboard monitoring

    • Notes: Personal vs. business detection is not currently supported

    • macOS: Not currently supported for deployment

    • Windows: Not supported

    • Notes: Safari extension distribution is not yet available

    *Safari is supported, but Nightfall has not yet enabled Safari extension distribution. As a result, customers cannot currently deploy a publicly available Nightfall plugin on Safari but can install a private package.

    While configuring the Scope section, if I use the Filter and add my Slack domain. Now, if I download a file from the Slack app will Nightfall monitor this download?

    Yes. Nightfall monitors the downloads even from the Slack app.

    What happens if I don’t configure any removable media filters?

    If no Device Type, Vendor, or Serial Number filters are configured, the policy applies to all removable media by default. This is equivalent to selecting Monitor all for every device filter.

    How do include and exclude filters work together?

    Nightfall evaluates device filters using the following precedence:

    1. Include rules are evaluated first

    2. Exclude rules always override include rules

    3. If no include filters are set, the policy defaults to include all

    This ensures that exclusions (for example, approved corporate devices) are always respected.

    What if I select a specific vendor and a specific serial number in the removable media filters?

    Both conditions must match for the policy to apply:

    • The device must belong to the selected vendor

    • The device’s serial number must match the specified serial number

    If either condition does not match, the policy is not triggered.

    What happens if a removable media device matches an included vendor but is explicitly excluded by serial number?

    The device will not trigger the policy. Serial number exclusions always take precedence, even if the vendor or device type is included.

    What if the device does not report a serial number?

    If a removable device does not expose a serial number:

    • Vendor and Device Type filters are still evaluated

    • Serial number–based include or exclude rules will not match

    In these cases, enforcement behavior is determined by the remaining configured filters.

    Can I allow only a small number of approved USB devices?

    Yes. Configure:

    • Action: To removable media

    • Serial Number: Specific serial numbers

    • Enforcement: Block

    Only the listed devices will be allowed. All other removable media will be blocked.

    Can I block unknown USB drives but allow corporate-issued ones?

    Yes. You can either:

    • Exclude approved vendors, or

    • Exclude approved serial numbers

    All other removable devices will remain in scope for enforcement.

    Does Nightfall continuously support new removable media vendors?

    Yes. Nightfall supports ~1,200 removable media vendors out of the box, and vendor recognition is continuously updated as new devices are observed in the wild.

    Customers do not need to manually onboard new vendors to receive baseline coverage.

    Is enforcement applied if no sensitive data is detected?

    Removable media policies are only enforced when sensitive content is detected according to your configured detection rules. If no sensitive data is found, the file transfer is allowed. You can also block usage of removable media based on a data lineage policy without any content scanning enabled.

    Can I both monitor and block removable media activity?

    Yes. Policies can be configured to block transfers while still logging events for audit and investigation purposes.

    Which operating systems are supported?

    Endpoint Exfiltration Prevention for removable media is supported on:

    • Windows endpoints

    • macOS endpoints

    Behavior may vary slightly based on OS-level device reporting, but enforcement logic remains consistent.

    Does Nightfall inspect or scan my source code?

    No. Git Push Monitoring does not inspect source code, commits, diffs, file names, or repository contents. Nightfall evaluates only metadata associated with the Git push action, such as the destination URL, repository name, user, and device. To scan secrets or any other PII, PCI, PHI or file classifiers in GitHub, you can use Nightfall’s detection and response policies.

    Is any code copied, stored, or transmitted to Nightfall?

    No. Nightfall does not collect or store source code. Only high-level metadata required to identify the Git push event is processed.

    Does Nightfall block Git pushes?

    No. Git Push Monitoring is a monitor-only control. Git operations always complete successfully. When a policy violation occurs, Nightfall generates an event but does not interrupt developer workflows.

    What Git commands are supported?

    Nightfall detects Git push activity regardless of how the push is initiated. The following commands are supported and validated through testing:

    • git push

    • git push origin <branch>

    • git push --set-upstream origin <branch>

    • git push -u origin <branch>

    Pushes triggered indirectly (for example, by scripts or wrappers that ultimately invoke git push) are also detected.

    Are both HTTPS and SSH Git pushes supported?

    Yes. Git Push Monitoring supports:

    • HTTPS-based Git remotes (e.g., https://github.com/org/repo.git)

    • SSH-based Git remotes (e.g., git@github.com:org/repo.git)

    The destination domain is extracted and evaluated consistently across both protocols.

    Are IDE-based Git actions supported?

    Yes. Git pushes initiated from popular IDEs and Git clients are supported, including:

    • VS Code Git integration

    • JetBrains IDEs (IntelliJ, PyCharm, WebStorm, etc.)

    • GitHub Desktop

    • Sourcetree

    As long as the IDE ultimately invokes a Git push operation on a managed endpoint, Nightfall detects the activity.

    Are terminal / CLI Git pushes supported?

    Yes. Git pushes executed directly from:

    • macOS Terminal

    • iTerm

    • Windows Git Bash / PowerShell (where supported by the endpoint agent)

    are fully supported.

    How does Nightfall handle multiple Git remotes?

    If a repository has multiple remotes configured (for example, origin and personal), Nightfall evaluates the specific remote used during the push.

    Example:

    • git push origin main → evaluated against origin destination

    • git push personal main → evaluated against personal destination

    Events accurately reflect the remote and destination URL used.

    What happens with new, empty, or scratch repositories?

    Nightfall detects Git pushes to:

    • Newly created repositories

    • Empty repositories

    • Scratch or temporary repositories

    Even if the repository has no prior history, detection is based on the destination domain and repository URL.

    How are corporate GitHub and GitLab organizations supported?

    Customers can define approved Git destinations using Domain Collections, including:

    • GitHub organizations (e.g., github.com/company-org/*)

    • GitLab cloud namespaces

    Wildcard matching is supported to simplify configuration.

    What happens if a developer pushes to a personal GitHub account?

    If the destination domain or repository does not match the approved domain list:

    • The push succeeds

    • A Git Push event is generated

    • Security teams can investigate and respond

    Are unmanaged devices monitored?

    No. Git Push Monitoring requires the Nightfall endpoint agent. Git activity from unmanaged or offline devices is not detected.

    What are the supported scenarios and capabilities with git push monitoring?

    Support Matrix - The following matrix summarizes supported scenarios with git push monitoring by Nightfall:

    Category
    Supported

    The CLI Tools picker offers: scp, curl, wget, rsync, aws s3, npm. You must select at least one or you cannot continue. Other command-line programs are not covered by this trigger.

    The policy scope is Windows only. wget and rsync cannot be enforced on Windows. rsync has no native Windows binary. PowerShell wget is an alias for Invoke-WebRequest, so the agent never sees a process to intercept. On a mixed macOS and Windows policy those two stay selectable and show a warning that they apply to Mac only.

    No. Git Push to watches git push (and IDE git that ends in a push). CLI Transfer watches the tools you check (scp, curl, and the rest). Git Push is monitor-only. CLI Transfer can block.

    No. CLI Transfer has no destination domain or host list. Scope by users, devices, OS, optional asset origin, and which tools you enable.

    No. Only file upload or download through the selected tools.

    File transfers sent with Apple AirDrop from a managed Mac. It does not watch AirPlay, Continuity, or iCloud Drive.

    No. There is no recipient or device filter. Data Source and Data Destination are not applicable.

    AirDrop events come from macOS. Include macOS in scope.

    Yes, when you enable the block action. End-user notification, if used, is titled Assets transferred via AirDrop.

    Bluetooth file transfers only. Pairing, audio, and HID use are not this trigger.

    No. Removable Media has vendor and serial filters. Bluetooth does not. Device name, type, vendor, and MAC appear on the event for investigation.

    They are not used for Bluetooth file transfer.

    Yes, when you enable the block action. End-user notification, if used, is titled Assets transferred via Bluetooth and can list the other device names.

    Is User Session Check enabled by default?

    Why is the Account Type field empty in some events?

    Does this work on the same domain (e.g., Google Drive > Google Drive)?

    Can I block only personal account usage but allow corporate usage?

    How is the Corporate Domains collection auto-populated and from where are these default domains collected?

    Do all supported browsers have the same security coverage?

    Nightfall Hooks for Claude Code

    Step-by-step instructions for deploying Nightfall's Claude Code hooks to corporate-managed employee devices via your MDM.


    Nightfall ships a managed-settings drop-in (payloads/nightfall-hooks.json) that registers the nightfall-hook-relay binary against four Claude Code events:

    ,
    copilot.microsoft.com
    ,
    m365.cloud.microsoft/chat

    Requires browser extension

    Git Push to

    Yes

    Not applicable

    Cloud syncing to

    No

    Personal Google Drive, OneDrive, Dropbox are supported with session differentiation; Does not rely on browser extension

    Print

    No

    No browser context available

    To removable media

    No

    No browser context available

    Uploads to desktop app

    No

    Desktop apps lack browser session info

    AI Agent Security

    No

    Hooks-based monitoring, no browser context

    CLI Transfer

    No

    Process interception. No browser session. Corporate/personal toggles are hidden.

    AirDrop

    No

    File transfer. Data Source and Data Destination are not applicable.

    Bluetooth

    No

    File transfer. Data Source and Data Destination are not applicable.

    You care about where data is going

    Only uploads/pastes into personal account sessions

    On

    Off

    Only uploads/pastes from corporate account sessions, regardless of destination

    On

    On

    Both constraints apply independently

    unfamiliar SaaS domains

    Device – which device performed the action

    Unexpected activity outside normal working hours may indicate suspicious behavior.

    Multiple External Destinations

    Sequential uploads to several different services.

    May indicate attempts to bypass security controls or distribute data across multiple locations.

    Personal Cloud Storage

    Uploads to personal accounts such as Google Drive (Personal) or Dropbox (Personal).

    Personal accounts are outside corporate control and represent higher exfiltration risk.

    Moderate risk indicators

    🟢 Low

    Activity appears consistent with expected usage

    ⚪ Unknown

    Insufficient context to determine risk

    Low risk

    Files uploaded or copy-pastes to a GenAI site using a personal account

    High risk

    App Intelligence

    Sidebar: Cannot monitor sidebar activity

    Chrome, Edge, Firefox, Arc, Brave, Vivaldi

    Comet, Atlas, Safari*

    git push <remote> <branch>
  • git push --force / git push -f

  • git push --tags

  • SSH Git Remotes

    ✅

    Multiple Git Remotes

    ✅

    New / Empty Repositories

    ✅

    Force Push (--force)

    ✅

    Tag Pushes

    ✅

    Approved Domain Allowlist

    ✅

    Domain Not-In Enforcement

    ✅

    Managed Endpoints

    ✅

    Unmanaged Endpoints

    ❌

    Push Blocking

    ❌

    OS

    Fully Supported

    Supported

    Not Supported

    Windows

    Chrome, Edge, Firefox

    Comet, Atlas, Safari, Arc, Brave, Vivaldi

    Git Push (CLI)

    ✅

    Git Push (IDE-integrated)

    ✅

    HTTPS Git Remotes

    Is Safari supported?

    Why is Perplexity Comet not supported on Windows?

    Why isn’t ChatGPT Atlas supported on Windows?

    Are AI browsers treated differently from traditional browsers?

    Are there any feature limitations on Arc, Brave, or Vivaldi?

    Can customers use any browsers across their organization?

    Google Chrome

    Microsoft Edge

    Firefox

    Arc

    Brave

    Vivaldi

    Perplexity Comet

    ChatGPT Atlas

    Safari

    Which CLI tools can I monitor?

    Why are wget and rsync greyed out on my CLI Transfer policy?

    Is CLI Transfer the same as Git Push or terminal git?

    Can I allow only certain remote hosts for scp or curl?

    Does Nightfall monitor every command typed in Terminal?

    What does the AirDrop trigger watch?

    Can I restrict AirDrop to specific people or devices?

    Should I include Windows in an AirDrop policy?

    Can AirDrop be blocked?

    What does the Bluetooth trigger watch?

    Can I allowlist corporate Bluetooth devices the way I do USB serials?

    Why are Data Source and Data Destination disabled for Bluetooth?

    Can Bluetooth file transfer be blocked?

    chrome://newtab

    macOS

    ✅

    Content Scanning

    PreToolUse

    Before Claude Code runs a tool (file write, bash, etc.)

    Inspect/intercept the action before it happens

    PostToolUse

    After a tool runs

    Capture the result

    UserPromptSubmit

    When the developer submits a prompt

    Inspect prompt content

    Stop

    When the agent finishes responding

    Capture the completed turn

    Every event runs the same command — nightfall-hook-relay --source claude_code - with a 15-second timeout. The payload also sets "allowManagedHooksOnly": true, which prevents users from registering their own hooks alongside the managed ones.


    Each device needs two things to happen, in order:

    1. Payload staged - the JSON file lands at a fixed staging path, delivered by your MDM's file-distribution / app-deployment feature.

    2. Install script runs - copies the staged payload into Claude Code's managed-settings.d/ drop-in directory and locks the file permissions.

    3. Developer relaunches Claude Code - Managed settings are read at startup. Any Claude Code session already running when the file lands will not pick up the hooks until it is fully quit and reopened. Hooks take effect on the next launch — there is no live reload.

    The install scripts are idempotent: re-running just re-copies the file, so it's safe to wire them to a recurring trigger.

    Platform

    Staging path (step 1)

    Target path (step 2)

    macOS

    /opt/nightfall/hooks/claude-code/nightfall-hooks.json

    /Library/Application Support/ClaudeCode/managed-settings.d/nightfall-hooks.json

    Windows

    C:\Nightfall\Hooks\claude-code\nightfall-hooks.json

    The drop-in directory managed-settings.d/ accepts multiple vendor files, so Nightfall's nightfall-hooks.json coexists with anything else already there. The install just adds one file.


    Deliver payloads/nightfall-hooks.json to /opt/nightfall/hooks/claude-code/nightfall-hooks.json using your MDM's file-distribution or app-deployment feature (e.g. wrap the JSON in a .pkg, or use Workspace ONE's Files feature).

    Wire scripts/macos/install.sh into your MDM as a System-context script. It:

    1. Verifies it's running as root (exits early if not — deploy at System scope).

    2. Confirms the staged payload exists.

    3. Creates …/ClaudeCode/managed-settings.d/ if needed.

    4. Copies the payload in, then sets chmod 644 and chown root:wheel.

    scripts/macos/audit.sh compares the deployed file against the staged payload byte-for-byte (cmp -s):

    • Exit 0 > in sync, no action.

    • Exit 1 > drift detected, run install.sh to remediate.

    (If the staging file is missing, audit exits 0 to avoid a remediation loop it can't fix.)


    Deliver payloads/nightfall-hooks.json to C:\Nightfall\Hooks\claude-code\nightfall-hooks.json using your MDM's file-distribution feature (e.g. an .msi or .intunewin).

    Wire scripts/windows/install.ps1 into your MDM as a SYSTEM-context script. It:

    1. Verifies it's running as administrator (exits early if not).

    2. Confirms the staged payload exists.

    3. Creates C:\Program Files\ClaudeCode\managed-settings.d if needed.

    4. Copies the payload in, then locks the ACL with icacls — full control for

    Administrators and SYSTEM, read-only for Users.

    scripts/windows/detect.ps1 compares the deployed file against the staged payload by SHA256:

    • Prints present, exit 0 → in sync.

    • Prints staging-missing, exit 0 → staging not deployed yet (no remediation loop).

    • Exit 1 → drift, run install.ps1 as the remediation.


    The scripts are MDM-agnostic - the same install script works regardless of vendor. Wire each into the matching MDM feature:

    MDM

    Platform

    Wire into

    Script

    Rippling

    macOS

    Custom Script (on enrollment + daily)

    scripts/macos/install.sh

    Two drift strategies:

    • Re-run on a schedule (Rippling / Jamf / Workspace ONE) - the install script is idempotent, so a periodic trigger simply re-copies and re-locks. Simplest.

    • Audit/detect → remediate (Kandji / Intune) - pair the audit/detect script with the install script so a re-install only fires when drift is detected.


    After deployment, open the Devices page in the Nightfall console. Each device shows a per-client hook status indicator. A healthy status for Claude Code means the hooks are registered and the relay is responding - the deployment is working.

    On a single device you can also confirm the file landed at the target path and that nightfall-hook-relay resolves on PATH (the endpoint agent provides it).

    • Admin-side (on the device):

      ls -l "/Library/Application Support/ClaudeCode/managed-settings.d/nightfall-hooks.json"   # exists, root:wheel, 644which nightfall-hook-relay
    • Developer-side (in a fresh Claude Code session) — this is the missing one:

      Run /hooks. You should see four hooks (PreToolUse, PostToolUse, UserPromptSubmit, Stop), each running nightfall-hook-relay --source claude_code. If the list is empty, Claude Code has not loaded the managed file — confirm you relaunched after deployment and that your Claude Code version is current (Section X).


    Delete the deployed file; the relay binary stays installed (the Nightfall agent owns its lifecycle):

    • macOS: /Library/Application Support/ClaudeCode/managed-settings.d/nightfall-hooks.json

    • Windows: C:\Program Files\ClaudeCode\managed-settings.d\nightfall-hooks.json

    If you wired the install to a recurring trigger, remove that MDM assignment first - otherwise the next check-in will re-deploy the file.


    Hooks for Claude Code are not firing? Work through the checks below in order. Each step narrows down where the chain is broken: MDM deployment → file on disk → Claude Code loads it → relay runs → event reaches Nightfall. Most "deployed but not working" cases are resolved at Step 1.

    The logic is the same on macOS and Windows; where a command or path differs, both variants are shown.

    Managed settings are read only at startup. A Claude Code session that was already open when the MDM pushed the file keeps running without the hooks — there is no live reload.

    Fix: Fully quit and reopen Claude Code, then re-test.

    • macOS: Quit with Cmd+Q (don't just close the window); confirm no claude process remains, then relaunch.

    • Windows: Close all Claude Code windows and confirm no claude process remains in Task Manager, then relaunch.

    This is the most common cause. If hooks were deployed while Claude Code was open, this step alone usually fixes it.

    In a fresh Claude Code session, run:

    You should see four hooks — PreToolUse, PostToolUse, UserPromptSubmit, Stop — each running nightfall-hook-relay --source claude_code.

    • Hooks listed → Claude Code loaded the managed file. Skip to Step 5.

    • List empty / hooks missing → Claude Code did not load the file. Continue to Step 3.

    You can also run /doctor for a built-in settings/installation diagnostic.


    Confirm the file exists at the target path with the correct ownership/permissions.

    • macOS:

      ls -l "/Library/Application Support/ClaudeCode/managed-settings.d/nightfall-hooks.json"

      Expect: file exists, owner root, group wheel, mode 644 (-rw-r--r--).

    • Windows (PowerShell):

      Get-Acl "C:\Program Files\ClaudeCode\managed-settings.d\nightfall-hooks.json" | Format-List

      Expect: file exists, ACLs locked to SYSTEM/Administrators (as set by install.ps1).

    If the file is missing: the MDM install step did not complete on this device. Confirm the payload was staged, then re-run the install script at System scope (see the macOS/Windows setup sections). If the file exists but content looks wrong, validate it parses as JSON and matches the deployed payload.

    Managed-settings drop-in directories (managed-settings.d/) and allowManagedHooksOnly require a recent Claude Code build. Pin managed devices to a current release; builds that predate this support will not register managed hooks even when the file is present and correct.

    CLI vs. VS Code extension: the Claude Code VS Code extension bundles its own CLI binary, which can be a different version than the standalone claude CLI. Verify hooks (Step 2) in whichever surface the developer actually uses, and update the CLI and the extension independently.

    After updating, fully relaunch Claude Code (Step 1) and re-check /hooks.

    Confirm the relay binary is on PATH and returns a valid response.

    • macOS:

      which nightfall-hook-relayecho '{}' | nightfall-hook-relay --source claude_code
    • Windows (PowerShell):

      Get-Command nightfall-hook-relay'{}' | nightfall-hook-relay --source claude_code

    Expect output {"continue":true} and a success exit code. If the relay is missing or errors, re-check the deployment; the relay must be installed and on PATH for the hook command to succeed.

    If /hooks shows the hooks and the relay responds, but the Devices page shows no hook activity, the events are being captured locally but not reaching Nightfall. Check the device's network egress to endpoint.nightfall.ai — TLS, DNS, proxy, or connectivity failures will drop event uploads even though hooks are working correctly. This is a network/connectivity issue, not a hooks issue.

    Collect and send to Nightfall support:

    • /hooks output (screenshot or text)

    • claude --version, and whether the developer uses the CLI or the VS Code extension

    • The Step 3 file listing

    • The Step 5 relay output and exit code

    This set pinpoints exactly which link in the chain is broken.


    • Hooks not active after deployment? The file is loaded only at app launch. A Claude Code instance open since before the MDM push keeps running without the hooks. Fully quit (Cmd+Q / confirm the process is gone) and relaunch.

    • User-consent dialog. Any managed Claude Code setting that contains hooks triggers a one-time security dialog the user must accept. Plan internal comms before rollout so employees aren't surprised.

    • Anthropic Windows path migration (March 2026). Claude Code on Windows moved managed-settings to C:\Program Files\ClaudeCode. The shipped scripts target this new path — pin managed devices to a recent Claude Code version so the path matches.

    • Multi-vendor coexistence. The managed-settings.d/ drop-in directory accepts multiple vendor files. Nightfall's nightfall-hooks.json coexists with anything else there - the install adds a single file and never overwrites others.

    • allowManagedHooksOnly: true. This locks out user-defined hooks. If a team has a legitimate need for their own Claude Code hooks, that's a policy decision to revisit before rollout.

    • Minimum / recommended version. Managed-settings drop-in directories (managed-settings.d/) and allowManagedHooksOnly require recent changes to Claude Code. Check with claude --version; pin managed devices to a recent release.

    • CLI vs. VS Code extension. The Claude Code VS Code extension bundles its own CLI binary, which may be a different version than the standalone claude CLI. Both should read system managed-settings, but verify hooks in whichever you actually use — running /hooks in that surface. Update the extension and the CLI independently.

    Event

    When it fires

    1. What gets deployed

    Purpose

    {
      "hooks": {
        "PreToolUse":       [ { "hooks": [ { "type": "command", "command": "nightfall-hook-relay --source claude_code", "timeout": 15 } ] } ],
        "PostToolUse":      [ { "hooks": [ { "type": "command", "command": "nightfall-hook-relay --source claude_code", "timeout": 15 } ] } ],
        "UserPromptSubmit": [ { "hooks": [ { "type": "command", "command": "nightfall-hook-relay --source claude_code", "timeout": 15 } ] } ],
        "Stop":             [ { "hooks": [ { "type": "command", "command": "nightfall-hook-relay --source claude_code", "timeout": 15 } ] } ]
      },
      "allowManagedHooksOnly": true
    }
    sudo ./scripts/macos/install.sh
    powershell -ExecutionPolicy Bypass -File .\scripts\windows\install.ps1
    /hooks
    claude --version

    2. How the deployment works

    Staging and target paths

    3. macOS setup

    Step 1 - Stage the payload

    Step 2 - Run the install script

    Drift checking (optional, recommended for Kandji-style audit/remediation MDMs)

    4. Windows setup

    Step 1 - Stage the payload

    Step 2 - Run the install script

    Drift checking (Intune Win32 Remediation pattern)

    5. Wiring into your MDM

    6. Validation

    7. Rollback

    8. Troubleshooting

    Step 1 — Did the developer relaunch Claude Code?

    Step 2 — Does Claude Code show the hooks as registered?

    Step 3 — Is the managed-settings file on disk and locked down?

    Step 4 — Is Claude Code a supported version?

    Step 5 — Does the relay run and respond?

    Step 6 — Hooks fire, but nothing appears in the Nightfall console?

    Still stuck?

    8. Notes & Known Issues

    Scope

    The Scope section enables you to create an asset lineage based policy in which you can track the journey of an asset from source to destination.

    • Security administrators can set precise exfiltration policies to protect sensitive files that originate from high-value SaaS locations from being exfiltrated to unsanctioned destinations

    • High performance security teams can focus their energy and resources on monitoring assets from high value SaaS domains.

    • By combining content download origin to upload destination, organizations can extend their monitoring to cover any cloud application accessed through the browser, even those without direct API integration.

    Recommended Policy Configurations


    Nightfall provides a set of reference policy configurations for common data exfiltration scenarios. Each template below describes recommended trigger types, detection rules, scope settings, and actions that you can use as a starting point when creating a new policy in the Nightfall console.


    Block employees from uploading files or pasting sensitive data into external AI assistants such as ChatGPT, Claude.ai, Microsoft Copilot, and Google Gemini.

    Scope

    • OS: macOS and Windows

    Nightfall Hooks for VS Code Copilot

    Step-by-step instructions for deploying Nightfall's VS Code Copilot hooks to corporate-managed developer devices via your MDM. For the package overview and MDM mapping table, see README.md; this guide walks through the actual setup, end to end.

    Heads up: VS Code Copilot hooks are Preview. Unlike Claude Code (one drop-in file) or Cursor (one merged file), VS Code needs two things per device: the hook file and an enterprise policy that tells Copilot to read it. Both steps are covered below.


    Nightfall ships a Copilot hook config (payloads/nightfall.json) that registers the nightfall-hook-relay binary against four VS Code Copilot events:

    C:\Program Files\ClaudeCode\managed-settings.d\nightfall-hooks.json

    Rippling

    Windows

    PowerShell Script

    scripts/windows/install.ps1

    Jamf Pro

    macOS

    Script + Policy (Recurring Check-in + Enrollment)

    scripts/macos/install.sh

    Kandji

    macOS

    Custom Script — Audit

    scripts/macos/audit.sh

    Kandji

    macOS

    Custom Script — Remediation

    scripts/macos/install.sh

    Microsoft Intune

    Windows

    Win32 Remediation - Detection

    scripts/windows/detect.ps1

    Microsoft Intune

    Windows

    Win32 Remediation - Remediation

    scripts/windows/install.ps1

    Workspace ONE

    macOS

    Script (System context, Periodic + Enrollment)

    scripts/macos/install.sh

    Workspace ONE

    Windows

    Script (SYSTEM context, Periodic + Enrollment)

    scripts/windows/install.ps1

  • Allows security teams to monitor and prevent data exfiltration not just through direct browser uploads but also through cloud storage sync applications, providing a multi-layered defense against data leaks.

  • With lineage-based policies, organizations can proactively identify and manage risks associated with sensitive content movement, ensuring compliance with data security standards and preventing potential breaches before they occur.

  • The Scope page consists of the following sections.

    • Operating Systems

    • Devices

    • Content Scanning

    • Filters

    This section allows you to select the operating systems to which the policy must be scoped. Nightfall supports the Microsoft's Windows and Apple's MAC operating systems. You can either choose any one of the operating system or both the operating systems, based on your organization's requirements. You must click the check box of the respective operating system to include it in the scope of the policy. All the devices that belong to the selected operating system(s) are monitored by Nightfall.

    By default, Nightfall monitors all the devices that belong to the selected operating system(s). However, you can choose to exclude trusted devices from being monitored. The Exclude Devices section consists of a drop-down menu. This menu lists all the devices that belong to the selected operating system(s). You can select the devices that you wish to exclude from being monitored.

    The Content Scanning section allows you to scan the downloaded content for sensitive data. You can choose the Nightfall detection rules that you wish to use for scanning the downloaded data. With this feature, you can monitor exfiltration attempts on sensitive data. For instance, you can monitor if any of the content uploaded to unsanctioned destinations contains regulated information like PCI, PII, PHI or organization's secrets like credentials, API keys, and so on. You can combine content scanning with Trigger and the Block features to prevent any exfiltration files containing sensitive data.

    To use this feature, you must first select the On option from the drop-down menu and then select the required Nightfall detectors.

    If a downloaded file contains sensitive data, it is reported in the exfiltration event. You can check the assets tab of an exfiltration event to view the sensitive data found. In the following image, you can see that a Detector called Credit Card Number is violated 20 times in one of the files uploaded to through the browser.

    The filters section provides you the flexibility to include and exclude users at a granular level. Once you select the operating system and the devices to be monitored, you can further drill down your scope by using filters. You can apply filters to only monitor assets downloaded from specific domains. Conversely, you can also choose to exclude the monitoring of assets downloaded from specific domains. Additionally, you can also apply filters to only monitor or exclude the monitoring of assets downloaded by specific high risk, like departing users, or function user groups, like HR, Finance or Engineering.

    The Asset Origin filter allows you to limit the scope of the policy to only those assets which originated from a specific source. To use the asset origin filter, you must click Add Filter and select Asset Origin.

    The Asset Origin filter provides the following options:

    • Any Domain: If you select this option, Nightfall monitors the assets originated (downloaded) from any domain, present in any of the domain collections.

    • Domain in: If you select this option, you must additionally also select the domain collections, created in the domain collections section. In this case, Nightfall monitors only those assets that originated from a domain, which is a part of any of the selected domain collection(s).

    Once you select a domain collection, it is displayed on the screen and greyed out from the drop-down menu. You can use the drop-down menu to select additional domain collections.

    • Domain Not in: If you select this option, you must additionally also select the domain collections, created in the domain collections section. In this case, Nightfall does not monitor those assets that originated from a domain, which is a part of any of the excluded domain collection(s).

    Once you select a domain collection, it is displayed on the screen and greyed out from the drop-down menu. You can use the drop-down menu to select additional domain collections.

    User Session Differentiation (also referred to as User Session Check) enables Nightfall to distinguish between personal and corporate user accounts on supported SaaS applications, cloud storage platforms, and AI web apps. This capability addresses a critical data exfiltration capability by detecting and enforcing policies when sensitive data moves from corporate contexts to personal contexts, even when both occur on the same domain.

    This feature is available on macOS and Windows.

    Traditional DLP solutions struggle to differentiate who a user is logged in as on dual-use platforms like Google Drive, Microsoft 365, or AI assistants. This creates blind spots where users can bypass controls by switching to personal accounts.

    User Session Differentiation enables:

    • Prevention of shadow exfiltration via personal accounts

    • Context-aware enforcement (corporate to corporate vs. corporate to personal)

    • Clear audit trails showing account type involved in an event

    Confident blocking of high-risk transfers without disrupting legitimate workflows.

    When enabled, Nightfall:

    • Detects whether the source and/or destination account is corporate or personal

    • Applies policy logic based on session context (not just domain)

    • Captures session metadata for investigation and audit

    As an example, if an employee:

    • Downloads a file from their corporate Google Drive

    • Uploads it to their personal Google Drive

    Nightfall can detect, alert, or block this action.

    Supported Coverage

    User Session Differentiation works across 35+ supported domains, including:

    Google Workspace

    • Drive, Docs, Gmail, Calendar, Meet, Keep

    Microsoft 365

    • OneDrive, SharePoint, Teams, Outlook, Office apps

    Cloud Storage

    • Dropbox, Box, iCloud

    AI / Shadow AI Apps

    • ChatGPT, Claude.ai, Gemini, Copilot, Perplexity

    Session context is captured for:

    • Browser file uploads

    • Clipboard copy/paste actions

    How It Works

    1. Browser Extension captures session context on supported domains

    2. Directory Sync from Okta, Entra ID, Google Directory identifies corporate accounts and domains

    3. Corporate Domains collection is populated automatically with the domains from directory sync

    4. User Session Check evaluates source and destination sessions

    5. Policy enforcement occurs based on configuration

    Corporate Domains Collection

    The Corporate Domains collection represents domains associated with corporate identities (for example, contoso.com). It is required for session differentiation.

    • Automatically populated when the endpoint agent is enabled and once the directory sync is setup

    • Happens once, based on the first OS provisioned (macOS or Windows)

    • After initial population, the collection is refreshed via an hourly job

    • You can add more domains to this collection as needed

    Note: Corporate Domains are populated immediately upon directory sync and once one or more endpoint agents are installed.

    Enabling User Session Differentiation

    Requirements

    • Endpoint agent with browser extension

    • macOS: Chrome (1.2.9.x+)

    • Windows: Chrome, Edge, Firefox (1.2.32+)

    • Directory sync enabled (Okta, Google Directory, or Entra ID)

    • Corporate Domains collection configured

    • Browser extension deployed (via MDM or manual install)

    macOS (MDM)

    • Deploy NightfallAI_Profile_with_Browser_Extensions.mobileconfig

    • Automatically installs browser extension and logs users in

    Windows

    • No additional MDM profile required

    User Session Differentiation is available in Endpoint Exfiltration policies and requires the User session check toggle to be enabled.

    Where It Appears

    The toggle is shown when:

    • Monitoring supported domains

    • Using Domain / URL-based sources or destinations

    How to Configure User Session Check

    Asset Origin (Trigger)

    1. Defines where data originates from.

    2. Supported operators:

      1. Domain in, Domain not in, Any domain

    3. Example Configurations

      1. Monitor Corporate Sources Only - Use case: Detect data originating from corporate accounts only.

        1. Source: Domain in equals Corporate Domains

        2. User session check: Enabled

      2. Exclude Corporate Sources - Use case: Focus on external or unmanaged sources.

        1. Source: Domain not in equals Corporate Domains

    Action (Destination)

    1. Defines where data is going (upload, paste, transfer).

    2. Supported actions include:

      1. Browser uploads to, Clipboard copy/paste

    3. Supported operators:

      1. Domain in, Domain not in, Any domain

    Common Policy Use-Cases

    1. Block Corporate to Personal AI Uploads

      1. Source: Domain in → Corporate Domains

      2. Action: Browser upload to → Domain in → AI Assistants

      3. User session check: Enabled

      4. Outcome: Blocks uploads when destination account is personal

    2. Allow Corporate → Corporate, Block Corporate → Personal

      1. Source: Domain in → Corporate Domains

      2. Destination: Domain in → Supported Domains

      3. User session check: Enabled

    3. Detect Personal Account Usage on Approved Apps

      1. Action: Browser uploads to → Domain in → Google Workspace

      2. User session check: Enabled

      3. Use case: Visibility into personal account usage on approved SaaS.

    4. Broad Monitoring (Any → Personal)

      1. Source: Any domain

      2. Destination: Domain in → Supported Domains

      3. User session check: Enabled

    • Specific User(s): You must choose this option to monitor the actions of specific internal users. Once you choose this option, Nightfall populates the list of users from the synced IdPs in Directory Sync. You must select the required users.

    • All Users, except for: You must select this option to exclude the monitoring of specific internal users. Once you choose this option, Nightfall populates the list of users from the synced IdPs in Directory Sync. You must select the required users.

    • Specific Group(s): You must choose this option to monitor of specific internal groups. Once you choose this option, Nightfall populates the list of internal groups from the synced IdPs in Directory Sync. You must select the required groups.

    • All Groups, except for: You must choose this option to exclude monitoring of specific internal groups. Once you choose this option, Nightfall populates the list of internal groups from the synced IdPs in Directory Sync. You must select the required groups.

    Endpoint URL and subpath filtering allows administrators and security teams to precisely control which file exfiltration events are reported or blocked by Nightfall. By creating exclusions at the file, file path, or file type (extension) level, teams can reduce noise, prevent false positives, and maintain focus on genuine data risk. This section explains:

    • How URL and subpath filtering works

    • The end‑to‑end user experience

    • Supported exclusion types

    • Practical use‑cases

    • Important behavioral details and limitations

    This functionality is available within:

    • Exfiltration Prevention → Event Details → Assets tab

    • Integrations → Endpoint → Exclusion List

    It applies to endpoint‑level exfiltration signals such as:

    • Browser uploads

    • File transfers via removable media

    • File sync

    How it works

    1. Exfiltration Event Detected An endpoint event (for example, a Browser Upload) is detected and logged under Exfiltration Prevention. Each event includes:

    • Risk level (Low / Medium / High)

    • Actor (device and user)

    • Asset involved (file name, path, size, medium)

    • Destination (e.g., drive.google.com, chat.deepseek.com)

    1. Viewing Asset Details When an event is opened:

    • Navigate to the Assets tab

    • Select the relevant asset (e.g., Customer List.xlsx)

    The Asset Details panel displays:

    • File name

    • Full local file path (e.g., /Users/anantmahajan/Downloads/Customer List.xlsx)

    • Medium (Browser)

    • Size

    1. Activating File or Path Exclusion From the Asset Details panel:

    • Click “Click to activate file & file path exclusion (macOS only)”

    A modal titled File & File Path Exclusion appears with three options:

    Exclusion Options

    1. Ignore file

    2. Excludes this exact file (specific file name + path)

    3. Ignore path

    4. Excludes all files within the selected directory and its subpaths

    5. Ignore all files with .xlsx extension

    6. Excludes all Excel files across the endpoint

    Selecting an option and clicking Continue proceeds to confirmation.

    1. Confirmation Modal

    A confirmation dialog clearly states: "Future activity involving this file will not be reported. Existing events won't be affected."

    Optional setting:

    • Apply rule to all endpoints (if enabled, the exclusion applies globally rather than device‑specific)

    Click Ignore to finalize the exclusion.

    1. Exclusion Is Applied

    Once confirmed:

    • The exclusion takes effect immediately

    • Future matching events are suppressed

    • Past events remain visible for audit and investigation

    The exclusion appears under: Integrations → Endpoint → Exclusion List

    Each entry shows:

    • Excluded item (file, path, or extension)

    • Type (File Name, File Path, or Extension)

    • Time created

    • User who created the exclusion

    • Scope (specific device or all endpoints)

    URL & Subpath Filtering Behavior

    URL Matching

    When a browser upload occurs, Nightfall evaluates:

    • The destination domain (e.g., drive.google.com)

    • The local file path on the endpoint

    If the local file matches an exclusion rule, the upload event is:

    • Not reported

    • Not blocked (unless another policy applies)

    Subpath Matching

    For Ignore path exclusions:

    • All files under the selected directory are excluded

    • Subdirectories are included automatically

    Example:

    • /Users/johndoe/Downloads/

    Excludes:

    • /Users/johndoe/Downloads/Customer List.xlsx

    • /Users/johndoe/Downloads/Exports/Q4/customers.csv

    Supported Exclusion Types

    File

    Single file only

    Known safe document repeatedly triggering alerts

    Path

    Directory + subdirectories

    Trusted export folders or generated reports

    Extension

    All files of a type

    Common Use‑Cases

    1. Suppressing Known Safe Files

      1. Scenario: A finance team routinely uploads a standardized customer spreadsheet to Google Drive.

      2. Solution: Ignore file: Customer List.xlsx

      3. Outcome:

        1. Prevents repeated high‑risk alerts for a known workflow

        2. Maintains visibility into other files

    2. Ignoring Automated Export Directories

      1. Scenario: An application exports reports into a fixed local directory before upload.

      2. Solution: Ignore path: /Users/*/Downloads/Exports/

      3. Outcome:

    3. Reducing Alert Fatigue from Common File Types

      1. Scenario: Large volumes of Excel files are shared internally and trigger frequent alerts.

      2. Solution: Ignore all files with .xlsx extension

      3. Outcome:

    4. Incident‑Driven Exception Handling

      1. Scenario: An investigation confirms a flagged upload was legitimate.

      2. Solution: Create a targeted file or path exclusion directly from the event

      3. Outcome:

    Best Practices

    1. Exclusions apply only to future activity and Existing events are never retroactively modified.

    2. Path exclusions are recursive and include subpaths.

    3. Extension‑based exclusions are global and high‑impact.

    4. Use Apply to all endpoints sparingly.

    5. Periodically review the Exclusion List for stale rules. Document the reason for exclusions internally when possible.

    URL and subpath filtering for endpoint exclusions gives security teams fine‑grained control over exfiltration monitoring. By embedding exclusions directly into the investigation workflow, Nightfall enables fast, contextual decisions without compromising visibility into real risk.

    This approach balances strong data security with practical, low‑friction operations.

    Key Features of Lineage Based Policies

    Configuring the Scope Page

    Operating Systems

    Kindly note that some of the advanced policy features like , , and automated actions are not yet available on Windows—but stay tuned, as we’re working to bring these capabilities soon!

    Devices

    If you have a long list of assets, you can search for an asset by entering the device ID of the asset.

    Content Scanning

    Filters

    You must configure the feature to use the and filters.

    Asset Origin

    User Session Check

    Internal Users

    Internal Groups

    URL and Subpath

    Users:
    All users (or scope to specific groups with elevated data access)
  • Content scanning: Enabled

  • Triggers

    Trigger

    Setting

    Browser uploads

    Domain in: AI Tools domain collection (add chat.openai.com, claude.ai, gemini.google.com, copilot.microsoft.com, perplexity.ai, and any others in use)

    Desktop app

    Enabled - covers thick-app versions of ChatGPT, Microsoft 365 Copilot (Word, Excel, PowerPoint, Teams AI)

    Detection rules

    Enable content scanning with the following detectors:

    • PII - names, SSNs, driver's license numbers, dates of birth

    • PCI - credit card numbers, routing numbers, IBAN

    • PHI - patient records and health information

    • Credentials & API keys - secrets, tokens, private keys

    • File classifiers - financial, HR, legal, M&A, source code documents

    Actions

    • Automated action: Block

    • End-user notification: Enabled - recommended message: "This file or content contains sensitive data and cannot be uploaded to external AI tools. Contact your security team if you have a business need."

    • Allow override with justification: Optional - enable if your organization wants users to self-certify a business reason before the action is allowed.

    • Mac Agent v1.2.11.x or later (desktop app monitoring)

    • Windows Agent v1.4.9.0 or later (thick app: Outlook, Teams, WhatsApp); v1.4.11.0 or later (M365 Copilot)

    • AI Tools domain collection created under Domain Collections

    • Nightfall browser extension deployed to managed browsers


    Prevent employees from copying corporate files to personal Google Drive, Dropbox, OneDrive, or Box accounts - including both browser-based uploads and locally synced folders.

    Scope

    • OS: macOS and Windows

    • Session detection: Enable corporate/personal account differentiation - this ensures the policy fires only when the destination is a personal account, not a corporate Google or Microsoft account

    • Users: All users

    Triggers

    Trigger

    Setting

    Browser uploads

    Domain in: Personal Cloud Storage domain collection (drive.google.com, dropbox.com, onedrive.live.com, box.com)

    Cloud syncing

    Enabled - select Google Drive, OneDrive, Dropbox, Box

    Detection rules

    Enable content scanning with:

    • PII, PCI, PHI, Credentials & API keys - broad sensitive data coverage

    • File classifiers - financial, legal, HR, M&A, source code

    Actions

    • Automated action: Block

    • Admin alert: Enabled - route to your security team's notification channel

    • End-user notification: Enabled - "Corporate files cannot be transferred to personal cloud storage accounts."

    • Mac Agent v1.2.10.x or later

    • Windows Agent v1.4.9.0 or later

    • Directory sync configured (required for corporate/personal account differentiation)

    • Personal Cloud Storage domain collection created


    Use case: Block secrets - API keys, passwords, and cryptographic private keys - from being uploaded or pasted to any external destination.

    Scope

    • OS: macOS and Windows

    • Users: All users; consider prioritizing engineering and DevOps groups for immediate rollout

    Triggers

    Trigger

    Setting

    Browser uploads

    Any domain

    Clipboard paste

    Any destination

    Desktop app

    Detection rules

    Enable content scanning with:

    • API keys & secrets - AWS, Azure, Google, Stripe, Okta, Slack, GitHub, and 50+ service-specific key formats

    • Passwords & credentials - username/password patterns in text and code

    • Cryptographic keys - RSA private keys, EC private keys (PEM-encoded)

    Actions

    • Automated action: Block

    • End-user notification: Enabled - "A secret or API key was detected. This content cannot be shared externally. Rotate the key immediately if it was already exposed."

    Note: This template has a low false-positive rate because credential detectors are highly specific. Block mode is safe to enable from the start.

    • Mac Agent v1.2.11.x or later

    • Windows Agent v1.4.9.0 or later

    • Nightfall browser extension deployed


    Use case: Prevent proprietary source code from being pushed to personal or unauthorized repositories, or uploaded to external destinations via browser or cloud sync.

    Scope

    • OS: macOS (git push monitoring is macOS-only)

    • Users: Engineering and DevOps groups

    • Content scanning: Enabled

    Triggers

    Trigger

    Setting

    Git push

    Enabled - monitors pushes to remote repositories not in your approved list

    Browser uploads

    Domain in: Personal Code Repos domain collection (add personal GitHub, GitLab, Bitbucket URLs; e.g., github.com personal paths)

    Cloud syncing

    Detection rules

    Enable content scanning with:

    • File classifiers - source code classifier for language-agnostic detection

    • Custom regex (optional) - add patterns for internal project identifiers, copyright headers, or proprietary module names

    Actions

    • Automated action: Block

    • Admin alert: Enabled

    • Mac Agent v1.2.10.x or later (git push monitoring)

    • Nightfall browser extension deployed

    • Personal Code Repos domain collection created

    • Directory sync configured (for group-based scoping)


    Use case: Detect and block patient health information (PHI) from leaving the endpoint across all exfiltration channels - a foundational policy for HIPAA-covered organizations.

    Scope

    • OS: macOS and Windows

    • Users: All users - or scope to clinical, operations, and data teams if starting with a pilot

    • Content scanning: Enabled

    Triggers

    Use all available triggers in independent policies:

    • Browser uploads

    • Cloud syncing

    • Clipboard paste

    • Desktop app (thick app monitoring)

    • Removable media

    • Printer

    • Git push

    Detection rules

    Enable content scanning with:

    • PHI - patient health information combining personal identifiers with medical context (diagnoses, medications, provider details, insurance data)

    • PII - names, SSNs, dates of birth (supplements PHI detection)

    Actions

    • Automated action: Block

    • Admin alert: Enabled - route to compliance and security teams

    • End-user notification: Enabled - "This content contains protected health information (PHI) and cannot be shared externally. Contact your compliance team for assistance."

    • Allow override with justification: Enabled - log all overrides for HIPAA audit trail

    • Mac Agent v1.2.11.x or later (for full trigger coverage including print and thick apps)

    • Windows Agent v1.4.11.0 or later

    • Directory sync configured


    Use case: Block sensitive files from being copied to USB drives, external hard drives, and other removable storage devices.

    Scope

    • OS: macOS and Windows

    • Users: All users

    • Content scanning: Enabled

    Triggers

    Trigger

    Setting

    Removable media

    Enabled

    Detection rules

    Enable content scanning with:

    • PII - personal identifiable information

    • PCI - payment card data

    • PHI - health information

    • Credentials & API keys

    • File classifiers - HR, financial, legal, M&A documents, source code

    Actions

    • Automated action: Block - the file transfer is blocked at the point of write to the removable device

    • End-user notification: Enabled - "Files containing sensitive data cannot be transferred to removable storage devices."

    Note: This trigger does not require domain collections. No additional collection setup is needed beyond enabling content scanning.

    • Mac Agent v1.2.10.x or later

    • Windows Agent v1.4.9.0 or later

    • Coverage for ~1,200+ removable media vendors


    Use case: Protect payment card data and financial records from exfiltration across browser, clipboard, desktop app, and cloud sync channels - supports PCI DSS compliance requirements.

    Scope

    • OS: macOS and Windows

    • Users: Finance, accounting, and billing teams - scope to these groups for initial rollout; expand to all users after validation

    • Content scanning: Enabled

    Triggers

    Trigger

    Setting

    Browser uploads

    Any domain

    Clipboard paste

    Any destination

    Desktop app

    Detection rules

    Enable content scanning with:

    • PCI - credit card numbers (Visa, Mastercard, Amex, Discover, JCB, UnionPay), routing numbers, IBAN, SWIFT codes

    • File classifiers - financial documents

    Actions

    • Automated action: Block

    • Admin alert: Enabled - route to security and compliance teams

    • Mac Agent v1.2.11.x or later

    • Windows Agent v1.4.9.0 or later

    • Directory sync configured (for group-based scoping)

    • Nightfall browser extension deployed


    Use case: Prevent strategically sensitive documents - M&A materials, legal contracts, HR records, and internal financial reports - from being uploaded to external destinations.

    Scope

    • OS: macOS and Windows

    • Asset origin filter: Optionally restrict to assets originating from corporate domains (files downloaded from internal tools or corporate Google Workspace/SharePoint)

    • Users: Leadership, finance, legal, HR, and strategy teams - scope via directory sync groups

    Triggers

    Trigger

    Setting

    Browser uploads

    Any domain (or refine with a High-Risk Destinations domain collection)

    Cloud syncing

    Enabled

    Desktop app

    Detection rules

    Enable content scanning with:

    • File classifiers - M&A, legal, financial, HR, regulatory documents

    • Custom keywords (optional) - add internal project codenames, product names, or division identifiers relevant to your organization

    Actions

    • Automated action: Block

    • Admin alert: Enabled

    • Allow override with justification: Recommended - many IP-related transfers have legitimate business reasons; log justifications for audit

    • Mac Agent v1.2.11.x or later

    • Windows Agent v1.4.9.0 or later

    • Directory sync configured (for group-based scoping)

    • Nightfall browser extension deployed


    Use case: Detect and block sensitive content copied from internal tools and pasted into personal email, consumer AI assistants, social platforms, or other unsanctioned destinations - using corporate/personal account differentiation.

    Triggers

    Trigger

    Setting

    Clipboard paste

    Destination: Domain in Unsanctioned Destinations domain collection

    Build your Unsanctioned Destinations domain collection to include:

    • Personal email: mail.google.com, outlook.live.com, yahoo.com

    • Consumer AI: chat.openai.com, claude.ai, gemini.google.com

    • Social media: twitter.com, linkedin.com, facebook.com, reddit.com

    • Personal cloud: drive.google.com, dropbox.com

    Use corporate/personal session detection to ensure the policy fires only when the destination session is a personal (non-corporate) account on supported domains.

    Detection rules

    Enable content scanning with:

    • PII, PCI, PHI - broad regulated data coverage

    • Credentials & API keys

    • File classifiers - financial, legal, HR, M&A

    Scope

    • OS: macOS and Windows

    • Session detection: Enable corporate/personal account differentiation (requires directory sync and Corporate Domains collection)

    • Users: All users

    Actions

    • Automated action: Block

    • End-user notification: Enabled - "This content contains sensitive data and cannot be pasted into personal accounts or external services."

    • Allow override with justification: Enabled - allows employees to self-certify a business justification; logged for review

    • Mac Agent v1.2.11.x or later

    • Windows Agent v1.4.9.0 or later

    • Directory sync configured

    • Corporate Domains collection configured (for personal vs. corporate account filtering)

    • Unsanctioned Destinations domain collection created


    Each policy recommendation above is a starting point. Common adjustments:

    • Narrow the scope - start with a specific user group (e.g., finance or engineering) before rolling out to all users, to validate detection accuracy before broad enforcement.

    • Start in detect-only mode - leave the automated action unset and enable admin alerts only. Review policy incidents for 1–2 weeks before switching to Block.

    • Add custom detectors - supplement built-in detectors with custom LLM based file or prompt based classifiers specific to your organization's sensitive data.

    • Tune domain collections - review and expand domain collections regularly as new AI tools, cloud apps, and risky destinations emerge. You can automate this via the apps discovered categorized by risk in App Intelligence. Expand the list of domains or apps to monitor and block via the domain collections.

    Policy Recommendations

    Use case

    Configuration

    Prerequisites

    Recommendation 2: Block Exfiltration to Personal Cloud Storage

    Use case

    Configuration

    Prerequisites

    Recommendation 3: Prevent Credential and API Key Leaks

    Configuration

    Recommendation 4: Source Code Exfiltration Prevention

    Configuration

    Prerequisites

    Recommendation 5: PHI Data Protection (HIPAA)

    Configuration

    Prerequisites

    Recommendation 6: Removable Media Data Loss Prevention

    Configuration

    Prerequisites

    Recommendation 7: Financial Data Protection (PCI DSS)

    Configuration

    Prerequisites

    Recommendation 8: Corporate IP Protection via File Upload

    Configuration

    Prerequisites

    Recommendation 9: Clipboard Paste to Personal Accounts and Risky Destinations

    Configuration

    Prerequisites

    Custom Policies

    Event

    When it fires

    Purpose

    UserPromptSubmit

    When the developer submits a prompt

    Inspect prompt content

    PreToolUse

    Before Copilot runs a tool (file write, terminal, etc.)

    Inspect/intercept the action before it happens

    Every event runs the same command - nightfall-hook-relay --source vscode_copilot - with a 15-second timeout. The relay binary is resolved by name on the system PATH, so the one config file works unchanged on both macOS and Windows.


    • Nightfall endpoint agent is installed on every target device. The agent auto-installs and keeps nightfall-hook-relay updated, and adds it to the system PATH. The hooks call the binary by name, so without the agent the hooks resolve to nothing.

    • MDM scope selected - the device group / Blueprint / Smart Group / assignment that will receive the deployment.

    • VS Code + Copilot extension are reasonably current on managed devices, and ideally pinned during the pilot (hooks are Preview).

    • You have the pieces from this package for your platform: the hook payload (payloads/nightfall.json), the matching policy source (payloads/nightfall-vscode-copilot.mobileconfig on macOS, payloads/hookFilesLocations.json on Windows), and the scripts in scripts/macos/ or scripts/windows/.


    VS Code Copilot won't read the hook file unless chat.hookFilesLocations is set as an enterprise policy. So each device needs two things to happen:

    1. Drop the hook file - the install script copies nightfall.json to a fixed file path.

    2. Set the policy - the policy script registers that file path in chat.hookFilesLocations (a Configuration Profile on macOS, a registry policy on Windows).

    Both the install scripts and the policy scripts are idempotent, so they're safe to wire to a recurring trigger.

    Platform

    Staging path

    Hook file target (step 1)

    macOS

    /opt/nightfall/hooks/vscode/nightfall.json

    /Library/Application Support/Copilot/hooks/nightfall.json

    Windows

    `C:\Nightfall\Hooks\vscode

    ightfall.json`

    Platform

    Policy mechanism

    What it sets

    macOS

    Configuration Profile (com.microsoft.VSCode)

    chat.hookFilesLocations → /Library/Application Support/Copilot/hooks/nightfall.json: true

    Windows

    Registry under HKLM\Software\Policies\Microsoft\VSCode

    Both policy mechanisms are additive: macOS profile layering preserves other vendors' Configuration Profiles for the com.microsoft.VSCode domain, and the Windows policy script merges Nightfall's entry into any existing chat.hookFilesLocations. Nightfall never clobbers another vendor's hook-file registration.


    Deliver payloads/nightfall.json to /opt/nightfall/hooks/vscode/nightfall.json using your MDM's file-distribution or app-deployment feature (e.g. wrap the JSON in a .pkg, or use Workspace ONE's Files feature).

    Wire scripts/macos/install.sh into your MDM as a System-context script. It:

    1. Verifies it's running as root (exits early if not - deploy at System scope).

    2. Confirms the staged payload exists.

    3. Creates /Library/Application Support/Copilot/hooks/ if needed.

    4. Copies nightfall.json into place.

    Wire scripts/macos/install-policy.sh into your MDM (also System-context). It installs payloads/nightfall-vscode-copilot.mobileconfig via sudo profiles install, which sets chat.hookFilesLocations so Copilot reads the file dropped in Step 2. The profile uses a stable PayloadIdentifier (ai.nightfall.hooks.vscode), so re-installs update in place. Alternatively, on profile-aware MDMs (Jamf, Kandji, Workspace ONE), upload the .mobileconfig directly as a Configuration / Custom Settings Profile instead of running the script.

    scripts/macos/audit.sh compares the deployed hook file against the staged payload byte-for-byte (cmp -s):

    • Exit 0 > in sync, no action.

    • Exit 1 > drift detected, run install.sh to remediate.

    (If the staging file is missing, audit exits 0 to avoid a remediation loop it can't fix.) The policy install is naturally idempotent and can simply be re-run on any trigger.


    Deliver payloads/nightfall.json to C:\Nightfall\Hooks\vscode\nightfall.json using your MDM's file-distribution feature (e.g. an .msi or .intunewin).

    Wire scripts/windows/install.ps1 into your MDM as a SYSTEM-context script. It:

    1. Verifies it's running as administrator (exits early if not).

    2. Confirms the staged payload exists.

    3. Creates C:\ProgramData\Copilot\hooks if needed.

    4. Copies nightfall.json into place.

    Wire scripts/windows/install-policy.ps1 into your MDM (also SYSTEM-context). It merges Nightfall's entry into chat.hookFilesLocations under HKLM\Software\Policies\Microsoft\VSCode, preserving any entries other vendors have already registered. The merged value mirrors payloads/hookFilesLocations.json.

    Alternatively, import VS Code's ADMX template and set the policy via the Intune UI, or push the same value via an OMA-URI Custom Configuration Profile.

    scripts/windows/detect.ps1 compares the deployed hook file against the staged payload by SHA256:

    • Prints present, exit 0 > in sync.

    • Prints staging-missing, exit 0 > staging not deployed yet (no remediation loop).

    • Exit 1 → drift, run install.ps1 as the remediation.

    The policy merge script is idempotent and can be re-run on any trigger.


    The scripts are MDM-agnostic - the same scripts work regardless of vendor. Note that VS Code has two install scripts per platform (file drop + policy), so most rows below pair them:

    MDM

    Platform

    Wire into

    Script

    Rippling

    macOS

    Custom Script — file drop

    Two drift strategies for the file drop:

    • Re-run on a schedule (Rippling / Jamf / Workspace ONE) - the install script is idempotent, so a periodic trigger simply re-copies the file. Simplest.

    • Audit/detect → remediate (Kandji / Intune) - pair the audit/detect script with the install script so a re-install only fires when drift is detected.

    The policy scripts are idempotent regardless of strategy (profile install updates in place via the stable PayloadIdentifier; registry merge re-applies the same entry), so wire them to the same trigger as the file drop.


    After deployment, open the Devices page in the Nightfall console. Each device shows a per-client hook status indicator. A healthy status for VS Code Copilot means the hooks are registered and the relay is responding - the deployment is working.

    On a single device you can also confirm:

    • The hook file landed at the target path.

    • chat.hookFilesLocations includes that path - check the installed Configuration Profile (macOS) or the registry key under HKLM\Software\Policies\Microsoft\VSCode (Windows).

    • nightfall-hook-relay resolves on PATH (the endpoint agent provides it).

    If the file is present but hooks don't fire, the policy is almost always the missing piece - Copilot silently ignores hook files at paths not listed in chat.hookFilesLocations.


    Remove both pieces; the relay binary stays installed (the Nightfall agent owns its lifecycle):

    1. Delete the hook file:

      1. macOS: /Library/Application Support/Copilot/hooks/nightfall.json

      2. Windows: C:\ProgramData\Copilot\hooks\nightfall.json

    2. Remove the policy entry for Nightfall's path from chat.hookFilesLocations:

      1. macOS: remove the ai.nightfall.hooks.vscode Configuration Profile.

      2. Windows: remove the Nightfall path entry under HKLM\Software\Policies\Microsoft\VSCode (leave other vendors' entries intact).

    If you wired the install/policy scripts to a recurring trigger, remove those MDM assignments first — otherwise the next check-in will re-deploy.


    • VS Code Copilot hooks are Preview. The configuration format and behavior may change. Pin to specific VS Code and Copilot extension versions during pilot.

    • Two-step deployment is mandatory. Dropping the file without setting chat.hookFilesLocations does nothing — Copilot won't read an unregistered hook file. This is the most common cause of a "deployed but not working" report.

    • Multi-vendor coexistence. Both policy mechanisms are additive - macOS profile layering and the Windows registry merge preserve other vendors' hook-file registrations. Nightfall adds a single path entry and never overwrites others.

    • Copilot CLI and Copilot coding agent (cloud) are out of scope - hook coverage doesn't apply there.

    • Claude Code spillover into VS Code. By default VS Code Copilot may also read ~/.claude/settings.json. If you observe Claude's user-level hooks firing inside VS Code and want to suppress that, add "~/.claude/settings.json": false to the policy.

    1. What gets deployed

    {
      "hooks": {
        "UserPromptSubmit": [ { "type": "command", "command": "nightfall-hook-relay --source vscode_copilot", "timeout": 15 } ],
        "PreToolUse":       [ { "type": "command", "command": "nightfall-hook-relay --source vscode_copilot", "timeout": 15 } ],
        "PostToolUse":      [ { "type": "command", "command": "nightfall-hook-relay --source vscode_copilot", "timeout": 15 } ],
        "Stop":             [ { "type": "command", "command": "nightfall-hook-relay --source vscode_copilot", "timeout": 15 } ]
      }
    }
    sudo ./scripts/macos/install.sh
    powershell -ExecutionPolicy Bypass -File .\scripts\windows\install.ps1

    2. Before you start

    3. How the deployment works (two steps)

    File paths

    Policy values (step 2)

    4. macOS setup

    Step 1 - Stage the hook file

    Step 2 - Drop the file into place

    Step 3 - Install the policy

    Drift checking (optional, recommended for Iru-style audit/remediation MDMs)

    5. Windows setup

    Step 1 - Stage the hook file

    Step 2 - Drop the file into place

    Step 3 - Set the policy

    Drift checking (Intune Win32 Remediation pattern)

    6. Wiring into your MDM

    7. Validation

    8. Rollback

    9. Notes & known issues

    Enabled - covers messaging apps and email clients

    Enabled - detects source code written to personal sync folders

    Enabled

    Cloud syncing

    Enabled

    Enabled

    PostToolUse

    After a tool runs

    Capture the result

    Stop

    When the agent finishes responding

    Capture the completed turn

    `C:\ProgramData\Copilot\hooks

    ightfall.json`

    chat.hookFilesLocations → `C:\ProgramData\Copilot\hooks

    ightfall.json: `true

    scripts/macos/install.sh

    Rippling

    macOS

    Custom Script — policy install

    scripts/macos/install-policy.sh

    Rippling

    Windows

    PowerShell Script — file drop

    scripts/windows/install.ps1

    Rippling

    Windows

    PowerShell Script — policy merge

    scripts/windows/install-policy.ps1

    Jamf Pro

    macOS

    Script + Policy — file drop

    scripts/macos/install.sh

    Jamf Pro

    macOS

    Script + Policy — policy install

    scripts/macos/install-policy.sh (or upload the .mobileconfig directly as a Configuration Profile)

    Kandji

    macOS

    Custom Script — Audit (file)

    scripts/macos/audit.sh

    Kandji

    macOS

    Custom Script — Remediation (file)

    scripts/macos/install.sh

    Kandji

    macOS

    Custom Script — Policy install

    scripts/macos/install-policy.sh (or upload the .mobileconfig as a Kandji Custom Profile)

    Microsoft Intune

    Windows

    Win32 Remediation — Detection

    scripts/windows/detect.ps1

    Microsoft Intune

    Windows

    Win32 Remediation — Remediation

    scripts/windows/install.ps1

    Microsoft Intune

    Windows

    Custom Configuration Profile / ADMX — policy

    scripts/windows/install-policy.ps1 (or import VS Code's ADMX and set the policy via UI)

    Workspace ONE

    macOS

    Script — file drop

    scripts/macos/install.sh

    Workspace ONE

    macOS

    Script — policy install

    scripts/macos/install-policy.sh (or upload the .mobileconfig as a Custom Settings Profile)

    Workspace ONE

    Windows

    Script — file drop

    scripts/windows/install.ps1

    Workspace ONE

    Windows

    Script — policy merge

    scripts/windows/install-policy.ps1 (or set OMA-URI under HKLM\Software\Policies\Microsoft\VSCode via a Profile)

    Result:

    1. Corporate → corporate transfers allowed

    2. Corporate → personal transfers blocked

    Use case: Identify any data entering personal accounts.

    Eliminates alert noise from automated processes

  • Still monitors uploads from other locations

  • Significant noise reduction

  • Should be used carefully due to broad scope

  • Fast remediation

  • No policy rewrites required

  • Suppress noisy file types like .log or .xlsx

    Directory Sync
    Content Scanning
    Filters
    Internal Users
    Internal Groups

    App Intelligence

    Identify, classify, and assess risk for SaaS and AI applications used across your environment.

    Table of Contents

    1. Overview

    2. Key Concepts

    3. Navigating the App Intelligence Interface


    App Intelligence gives your security team a complete, continuously updated view of every SaaS application and AI tool your employees are actually using — not just the ones on your approved list.

    In most organizations, employees use five to fifteen times more applications than IT formally manages. This includes AI assistants like ChatGPT and Claude, personal cloud storage, file-sharing services, and agentic AI tools that act on behalf of users. Until now, this activity has been largely invisible to security teams.

    App Intelligence changes that. Using data movement APIs provided by Apple and Microsoft, Nightfall's lightweight agent detects paste and file upload activity to automatically discover these applications, assign a risk score, categorize them by functional type, and surface early adopters — with none of the latency associated with traditional DLP tools.


    Nightfall classifies every detected app into one of twelve categories. Categories reflect the nature of the product and its typical data exposure potential — they form the foundation of how risk is calculated. Your team can use categories to filter, prioritize, and focus on the parts of your app landscape that matter most.

    Category
    Risk Level
    Description
    Examples

    A note on cloud productivity suites: Nightfall classifies by the actual product surface an employee uses, not the parent company brand. For example, Google Workspace Mail and Google Docs are classified as Business SaaS because their primary function is collaboration and editing. Google Drive is classified as Cloud Storage / Sync because its primary function is file storage and bulk sync. The same principle applies to Microsoft 365, AWS, and Salesforce subdomains.

    Every app in App Intelligence displays one of four risk labels: Low, Medium, High, or Critical. These reflect Nightfall's assessment of how much data exposure risk the app represents in your environment.

    Label
    What It Means

    Risk is calculated in two steps. First, every app starts with a baseline risk level inherited from its category — for example, File Sharing apps start at Critical and Core Systems start at Low. Second, Nightfall adjusts the score for the specific app within that category: if an app is consumer-focused, allows anonymous access, or is less governed than its peers, the risk increases. If the app is unusually well-governed for its category — for example, enterprise-only access with mandatory SSO — the risk may decrease.


    Access App Intelligence from the Discovery section of the left-hand navigation menu.

    The App Intelligence list view, showing 5,892 total apps discovered across the organization.

    The page is divided into two main sections:

    App Insights (Top Panel) The insights panel gives you a quick summary of what's happening across your app landscape. It shows:

    • Total Apps discovered, AI Apps in use, and Total Users observed

    • Top AI Apps by Adoption — the GenAI tools growing fastest in your environment over the last 30 days, shown as a percentage of users

    • Top Apps by Data Volume — the apps handling the most data, with user counts and data sizes

    App List (Bottom Panel) The full table of all discovered applications. Each row shows:

    Column
    Description

    Use the filter bar above the app list to narrow results by:

    • Time range (e.g., Last 30 Days)

    • App Name — search by name or keyword

    • Domain — filter to a specific domain

    • Category — show only GenAI, Cloud Storage, etc.

    Clicking any app in the list opens its detail page.

    The App Details view for Wisprflow (wisprflow.ai), an AI agent platform classified as High risk.

    The detail view includes:

    • Summary stats — total users, when first and last seen

    • App Risk panel — a plain-language explanation of why Nightfall assigned this risk level, covering category, identity boundaries, and data exposure

    • Destination List — a breakdown of every subdomain or endpoint within the app where data was sent, including per-destination user counts, data volume, and activity timestamps. This helps you understand whether a tool is being used for its core purpose or whether data is flowing to admin panels, APIs, or documentation portals.


    Goal: Understand which apps are active in your environment and identify where to focus first.

    Steps:

    1. Navigate to Discovery → App Intelligence in the left sidebar.

    2. Review the App Insights panel at the top of the page. Note:

      • How many Total Apps have been discovered.

      • Which AI Apps


    Goal: Understand why an app received a high risk score and gather the information your team needs to take action.

    Steps:

    1. Filter the App List by Risk = High and sort by Users to surface the most widely adopted high-risk apps first.

    2. Click on an app to open its Detail View.

    3. Read the App Risk explanation on the right side. This gives you Nightfall's reasoning in plain language — for example, whether the tool is an AI agent that can access data on behalf of users, or whether it lacks standard enterprise governance controls.


    Goal: Understand the risk signals behind a specific app and determine whether action is needed.

    Steps:

    1. Identify an app of interest in the App List — for example, an AI Agents tool or a GenAI service you don't recognize.

    Wisprflow appears in the App List as an AI Agents tool with a High risk rating, 28 users, and 2.2 GB of data sent — with activity as recently as 5 hours ago.

    1. Click the app row to open its Detail View.

    2. In the App Risk panel, read Nightfall's risk explanation. For an AI Agents tool, this will typically explain that the platform is designed to build and deploy autonomous agents that can access and move data across multiple systems — and why this elevates the risk classification above the category baseline.

    3. Check Total Users and compare it to First Seen. If a large number of users adopted the tool quickly, that's a signal of fast organic growth that may have outpaced governance review.


    A security team at a mid-size technology company suspects employees are using unauthorized GenAI tools but has no visibility into which ones or how widely.

    They open App Intelligence, filter by Category = GenAI, and sort by Users. Within minutes, they can see that three GenAI tools not on the approved list have been adopted by dozens of employees. They use the details view to assess each tool's risk score and destination activity, then route the highest-risk findings to the IT governance team with the context they need to take action.


    An insider risk analyst receives an alert about unusual data movement patterns. They open App Intelligence and sort by Last Seen to find recently active apps. They spot an AI Agents platform that was first seen a month ago but has seen a spike in data volume in the last 24 hours.

    Clicking into the app detail, they see the risk explanation highlights that the tool is designed to build autonomous agents capable of accessing data across multiple systems — and that several API-level destinations are active. The analyst notes their findings and escalates to the security team for deeper investigation.


    An IT Policy Owner needs to audit which high-risk apps are active in the environment as part of a quarterly governance review. Rather than sifting through all discovered apps manually, they filter the App List to Risk = High or Critical, sort by Users, and work through the results.

    Using the risk scores and destination breakdowns, the owner quickly identifies which apps need immediate attention from the security team and which are low-risk tools that don't require escalation. Within a single session they have a clear picture of their app risk landscape to bring into the governance review.


    A data security engineer reviewing App Intelligence notices a file-sharing site with Critical risk that has been used by multiple employees to send data externally. Rather than just flagging it for review, they want to act immediately.

    From the app's detail page, they click Add to Collection and add the domain to their organization's block list collection — the same list already enforced by Nightfall's exfiltration control policies. The domain is now blocked from receiving corporate data without any separate policy configuration required. For a second app — an approved cloud storage tool that was mistakenly triggering alerts — they add it to the allow list collection instead, suppressing false positives going forward.

    App Intelligence becomes the discovery layer that feeds directly into enforcement, closing the loop between visibility and protection.


    A CISO preparing for an upcoming compliance review needs a clear picture of all AI tools in use across the organization, including what data types are being transmitted. They use the Top AI Apps by Adoption insight to see which GenAI tools are most widely used, then filter the app list to Category = GenAI to review risk levels across the full set.

    For any GenAI tool with a High risk rating, they open the detail view to review the risk explanation and destination breakdown. This gives them the documentation they need to demonstrate that the organization has visibility into AI tool usage and the risk signals associated with each one.


    How often is the app data refreshed? App Intelligence data is refreshed hourly. The "Last updated" timestamp in the top right corner of the page shows when the data was last synced.


    How does Nightfall discover which apps employees are using? Nightfall uses data movement APIs provided by Apple and Microsoft to detect paste and file upload activity on enrolled devices — not network traffic or keystrokes. This lightweight approach means App Intelligence can identify which apps employees are sending data to without the performance impact or latency of traditional DLP tools. No additional configuration is required; new apps are detected automatically.


    How exactly is an app's risk score calculated? Nightfall uses a two-step process. First, every app starts with a baseline risk level inherited from its category — for example, File Sharing apps start at Critical and Core Systems start at Low. Second, Nightfall evaluates the specific app within its category: if it's consumer-focused, allows anonymous access, or is less governed than peers, the risk increases. If the app is unusually well-governed for its category — mandatory SSO, enterprise-only access — the risk may decrease. This category-based assessment is then combined with usage signals including behavioral patterns and identity boundary data to produce the final label.

    When reviewing individual events in Forensic Search, scoring goes a step further. If your organization has completed MDM integration, Nightfall can determine whether a user is sending data to a corporate or personal account at a given destination — for example, distinguishing between a managed Google Workspace account and a personal Gmail account at the same domain (mail.google.com). This account context is factored into the event-level risk score in Forensic Search, giving you a more precise signal when investigating specific user activity.


    Can I override the risk level Nightfall assigns? Not in v1. The ability to apply custom risk overrides is planned for a future release.


    Why do some apps show a high Destination Count? Destination Count reflects the number of distinct subdomains or endpoints Nightfall has observed data flowing to within a single app's domain. For many apps, destinations are specific enough to tell you something meaningful about how the app is being used.

    GitHub is a good example: each destination corresponds to a specific repository. A SecOps admin reviewing GitHub's destination list can research individual repos to determine whether employees are pushing data to a corporate repository, a public open-source project, or a personal account — a meaningful distinction when assessing data exposure risk. The same principle applies to other developer tools, cloud storage platforms, and any app where the destination encodes context about the recipient or purpose.


    Will App Intelligence block apps or take enforcement actions? App Intelligence itself is a visibility tool — it does not block apps directly. However, you can act on what you find by using the Add to Collection button in any app's detail view. This lets you add the app's domain to a domain collection, which feeds directly into Nightfall's exfiltration control policies. Adding a domain to a block list collection will prevent data from being sent to that destination; adding it to an allow list collection explicitly permits it and suppresses false positives. Automated enforcement actions beyond this are planned for a future release.


    Does App Intelligence cover desktop apps like Slack or Zoom? Not yet — but coming soon! The current release focuses on web apps and GenAI tools accessed through the browser. Coverage for native desktop applications is on the roadmap for an upcoming release.


    What should I do first if I'm new to App Intelligence? Start with the App Insights panel to understand the shape of your environment — how many apps are active, which AI tools are growing fastest, and where the most data is flowing. Then filter the App List to Risk = High or Critical, sort by Users, and work through the results. This gives you a focused view of the apps that carry the most risk and the widest reach across your organization.


    For additional help, contact Nightfall support or reach out to your Customer Success Manager.

    Risk — focus on High or Critical apps

    Add to Collection — a button that lets you add the app's domain directly to a domain collection. Domain collections are the allow lists and block lists that power Nightfall's exfiltration control policies. Adding an app here is how you translate App Intelligence findings into active data protection — for example, blocking a risky file-sharing site or explicitly allowing an approved storage tool.
    have the greatest adoption (Top AI Apps by Adoption chart).
  • Which apps have the most users over the last 30 days (Top Apps by User Count, 30d).

  • In the App List, sort by Risk to bring the highest-risk apps to the top. Look for any apps labeled Critical or High that you don't recognize.

    Example showing a small tenant environment. Deepseek is flagged as Critical risk — a GenAI tool with elevated data exposure signals.

  • Sort by Last Seen to find apps with very recent activity, then cross-reference with First Seen to spot newly adopted tools your team may not be aware of.

  • Use the Category filter and select GenAI and AI Agents to see all AI tools in use. This is a fast way to understand your organization's AI footprint.

  • Review the Destination List to understand how the app is being used. Are employees accessing only the main product domain, or is data also flowing to API endpoints or admin subdomains? Higher destination counts can indicate more complex, potentially automated workflows.
  • Note the Total Users and First Seen date. If adoption is recent and growing, that context is useful when escalating to your IT or security governance team.

  • If your team decides to act on what you've found, use the Add to Collection button to add the app's domain to a domain collection. Choose a block list collection to prevent data from flowing to the app, or an allow list collection to explicitly permit it within your exfiltration control policies.

  • Review the Destination List to see exactly where data is flowing within the app's ecosystem. For example, if you see traffic to both the main product domain and an API subdomain, it suggests programmatic or automated use — not just manual browser sessions.
  • Cross-reference the Data Volume against the number of users. Disproportionately high data volume relative to user count can indicate automated workflows, bulk uploads, or exfiltration-style behavior.

  • Click Show Events on a destination row to see the individual users and corresponding events associated with that site. This is one of the most powerful features in App Intelligence — it lets you move from aggregate risk signals to the specific people and actions driving them.

  • Share your findings with your IT or security governance team, including the risk score, user count, data volume, any API-level destinations observed, and the specific user activity surfaced via Show Events.

  • Core System

    Low

    Business systems of record with strict identity controls and low exfiltration risk.

    Workday, NetSuite, SAP, Salesforce CRM

    🟢 Low

    Minimal concern; typically well-governed, established tools with strong identity boundaries.

    🟡 Medium

    Worth monitoring; may involve less-governed surfaces or moderate data exposure potential.

    🔴 High

    App Name

    The detected application, grouped under its canonical domain

    Domain

    The primary domain associated with the app

    Destination Count

    Overview

    Key Concepts

    App Categories

    Risk Scoring

    Navigating the Interface

    The App Intelligence Page

    Filtering and Search

    The App Details View

    Tutorials

    Tutorial 1: Getting Your First Look at App Usage

    Tutorial 2: Reviewing a High-Risk App's Details

    Tutorial 3: Investigating a High-Risk App and Its User Activity

    Use Case Examples

    Use Case 1: Discovering Shadow AI Adoption

    Use Case 2: Identifying a New High-Risk Agentic Tool

    Use Case 3: Prioritizing App Review During Quarterly Governance

    Use Case 4: Turning App Findings Into Exfiltration Controls

    Use Case 5: Understanding Your GenAI Footprint Before a Compliance Review

    Frequently Asked Questions

    Tutorials
    Tutorial 1: Getting Your First Look at App Usage
    Tutorial 2: Reviewing a High-Risk App's Details
    Tutorial 3: Investigating a High-Risk App and Its User Activity
    Use Case Examples
    Frequently Asked Questions

    Business SaaS

    Low

    Enterprise productivity and collaboration tools.

    Slack, Notion, Figma, Canva, Asana, Loom

    Internal Apps

    Low

    Internal or private applications, staging/QA environments, and SSO-only portals.

    Internal dashboards, staging portals, *.internal domains

    Public Web

    Low

    General consumer or informational websites not primarily designed for file transfer.

    YouTube, Wikipedia, Medium, Amazon

    Social / Messaging

    Medium

    External messaging or social platforms where users can send or post corporate data.

    WhatsApp Web, Telegram, Discord, LinkedIn, X/Twitter

    Cloud Providers / Infra

    Medium

    Cloud consoles and infrastructure administration surfaces.

    AWS Console, GCP Console, Azure Portal, Cloudflare

    GenAI

    High

    LLMs, AI assistants, and AI-powered creation tools that may ingest internal data.

    ChatGPT, Claude.ai, Gemini, Perplexity, DeepSeek

    Developer Tools

    High

    Platforms hosting source code, configuration, logs, or automation pipelines.

    GitHub, GitLab, Replit, Databricks, Netlify

    Unknown

    High

    Domains that cannot be reliably classified (e.g., raw IPs or unrecognized destinations).

    Unclassified IPs, localhost, unresolved domains

    AI Agents

    Critical

    Autonomous or semi-autonomous systems that act on behalf of users to access and move data.

    Wisprflow, Glean, n8n, Zapier Desktop Runner

    Cloud Storage / Sync

    High

    Cloud-based file storage and synchronization platforms with high exfiltration risk due to bulk file movement and multi-device sync.

    Google Drive, Dropbox, Box, iCloud, OneDrive

    File Sharing

    Critical

    Public or anonymous file-sharing services with minimal identity boundaries.

    WeTransfer, file.io, Snapdrop, Pastebin

    Requires attention; elevated data risk or boundary concerns detected.

    🚨 Critical

    Immediate review recommended; significant risk signals across multiple dimensions.

    Number of distinct subdomains or destinations observed

    Category

    App type classification

    Risk

    Nightfall's computed risk level

    Users

    Number of users or unique devices observed accessing this app

    Data Volume

    Total data transmitted to this destination

    First Seen

    When Nightfall first detected activity to this app

    Last Seen

    Most recent observed activity

    MCP Gateway

    MCP Gateway sits between your AI clients (Cursor, Claude Code, Claude connectors, ChatGPT, VS Code, Windsurf) and the remote MCP servers those clients call (GitHub, Linear, Notion, an internal HTTPS service). People stop pasting vendor URLs and personal tokens into mcp.json. They point one Nightfall URL. You decide which servers and tools exist, whose credentials are in play, and you get a log of what was asked.

    The tab is double-gated. Nightfall has to enable the product for your organization, and the person needs MCP Gateway read access. If the backend is not provisioned yet, the console says MCP Gateway isn't enabled for your organization. Use Check again after your Nightfall rep turns it on.

    When to use the gateway

    Use MCP Server Visibility when the question is "what is already running on laptops," including local stdio servers and shadow installs nobody approved. Visibility does not broker credentials or sit on the call path.

    Use MCP Gateway when you want a sanctioned remote path that you can shrink, revoke, and audit. Typical jobs:

    Job
    What the gateway does

    Do not use the gateway to inventory local filesystem or stdio MCP. That is . The gateway also does not stop someone from typing a vendor URL into a local Cursor or Claude Code config. It governs the traffic that uses the Setup URL.

    Enabling a server is not all-or-nothing. Pick the smallest control that matches the risk. These four actions do not overlap.

    If you need this
    Use
    What clients see
    What you keep

    Leave a catalog row disabled (do not click Enable) when the server is not sanctioned yet. Uncertified catalog rows cannot be enabled in place; add them as custom only if you accept that risk.

    New tools discovered on refresh start enabled. After Refresh tools, open the Write and Delete groups and disable anything you do not want in agents. The org-wide Tools tab is a read-only index (name, server, description). You change enablement on the server, not on that tab.

    Block vs disable tools: Block is the whole vendor. Disable is one capability. If Linear is approved but delete_* is not, disable those tools. If Linear should not be reachable at all this week, Block.

    A disabled or blocked tool is how you hide a capability from clients today. Endpoint DLP that mentions MCP collections is a different surface: .

    Two MCP roles exist. Settings lists them as Mcp Gateway Admin and Mcp Gateway User. In the gateway they show as MCP Admin and MCP User.

    MCP Admins see every sub-tab, in this order:

    1. Audit

    2. Server Catalog

    3. Enabled Servers

    4. Tools

    MCP Users (members) see Enabled Servers and Setup only. They land on Enabled Servers. They can connect their own OAuth or PAT. They cannot enable servers, invite people, or open Audit.

    People who only have MCP Gateway access (and no other Nightfall products) get a standalone MCP Gateway app at /mcp-gateway, with the same sub-tabs their role allows. Everyone else uses AI Governance > MCP Gateway. The dropdown label looks like MCP Gateway: Setup.

    If your role is still loading, the UI stays open (admin-capable) until the server says you are a member. Server-side checks still apply.

    1. An admin enables a server from the catalog or adds one by URL.

    2. Each person points Cursor, Claude Code, Windsurf, or VS Code at the tenant MCP endpoint URL from Setup.

    3. The client opens a browser. Nightfall asks them to Approve or Deny access to the gateway.

    4. If the upstream server needs GitHub (or similar), they click Connect

    Two different "Connect" moments: the browser page Connect to Nightfall MCP Gateway is client-to-gateway. Connect on a server row is gateway-to-upstream (GitHub, Linear, and so on).

    The gateway is a Nightfall-hosted remote MCP server. Clients that speak streamable HTTP and OAuth use the URL from Setup.

    It does not proxy local stdio servers (a filesystem server on a developer's machine, for example). Those stay on . The gateway is for remote HTTP MCP: GitHub, Linear, Notion, an internal service you expose over HTTPS, and the like.

    It aggregates tools. MCP prompts and resources are not served through the gateway in this release.

    There is no separate gateway password. Sign-in is Nightfall SSO (or whatever identity you already use on the platform). When a client connects, the browser redirects to Nightfall for authentication and consent.

    The workspace path in the Setup URL routes traffic to your tenant. Access still requires a Nightfall sign-in and membership. A URL by itself is not a credential.

    Every call through the gateway uses two different secrets:

    1. The client's gateway token. Issued after Approve on Connect to Nightfall MCP Gateway. It proves the person to Nightfall. It is scoped to your tenant and is not sent to GitHub, Linear, or any other backend.

    2. The backend credential. The user's OAuth tokens or PAT for that upstream server. Nightfall stores those encrypted and injects them when calling the backend. Clients never see them.

    Admins can see that a connection exists, how many people are connected, and connection health (Connected, Token expired, Not connected). They cannot see token or key values. OAuth client secrets on Set OAuth client are write-only; you will not see the secret again.

    For OAuth backends, each person's Connect flow talks to the provider. Nightfall does not see that password. After approval, calls from that person's clients use that person's identity at the backend, so the provider's own permissions and audit trail match a real user.

    If a backend is down, calls fail with the backend error. Repeated calls to a failing server are short-circuited so clients fail fast instead of hanging. Other enabled servers keep working.

    Custom Remote URL values must be public http(s) MCP endpoints. Private, link-local, and cloud-metadata addresses are rejected. Use Add custom server for internal servers only when they are reachable from Nightfall's hosted service over HTTPS.


    You have MCP Admin or System Administrator privileges in Nightfall. The tab is visible. You want one working client today.

    Open AI Governance > MCP Gateway > Setup. The card title is Connect your MCP client.

    You should see MCP endpoint URL and Copy. If you see Your MCP endpoint is unavailable right now, provisioning is not finished. If you see Couldn't load your MCP endpoint, retry. If you still get the "isn't enabled" screen, your Nightfall rep has more work to do.

    Go to Server Catalog. Description in the product: curated servers you can enable; anything else is Add custom server.

    1. Search by name, or filter Certification to Certified / Uncertified.

    2. Certified rows have Enable. Uncertified rows do not. The tooltip says to add those manually via Add custom server.

    3. Click Enable. Set Alias (max 24 characters; letters, numbers, hyphens, underscores). Tools will appear as <alias>__<tool>.

    Columns: Alias, Canonical name, URL, Auth, Status, Validation, Connected.

    Auth values you may see: None, OAuth (DCR), OAuth (static), OAuth (CIMD), PAT.

    Validation values: Pending, Config valid, Config valid - manual OAuth, Awaiting first user OAuth, Tools discovered, Tools discovery failed, Reconnect required.

    Use Validate or, on the server page, Validate now. Refresh tools pulls a new tool list. View check results shows the raw checks.

    Setup has four client tabs. Use the snippet the console generates (it already has your URL). The shapes are:

    Cursor (~/.cursor/mcp.json or project .cursor/mcp.json):

    Reload Cursor's MCP server list, or restart Cursor.

    Claude Code (no config file):

    It registers immediately. No restart.

    Windsurf (~/.codeium/windsurf/mcp_config.json). Note serverUrl, not url:

    Reload Cascade's MCP list from Windsurf settings.

    VS Code (workspace .vscode/mcp.json or user profile). Note servers and "type": "http":

    Run MCP: List Servers to confirm.

    The client opens Connect to Nightfall MCP Gateway. Sign in if asked. Approve. If the window is wrong, Deny and close the tab. Switch account if you are in the wrong Nightfall user.

    Then invoke a tool. Open Audit. You should see User, Server, Tool, Method, Event, Status, Time.


    You have MCP User. You do not see Catalog, Tools, Users, or Audit.

    1. Open Setup. Copy the snippet for your client. Same four clients as above.

    2. Approve the Nightfall consent page when the browser opens.

    3. Open Enabled Servers. Member copy: MCP servers your company has enabled. Connect your own credentials where required.

    4. Blocked servers are hidden from you. If the list is empty: No servers enabled for your company

    Disabled tools are hidden from MCP clients. Tools discovered later start enabled.


    Use this for an internal remote MCP server, or an uncertified catalog entry.

    1. Server Catalog > Add custom server.

    2. Alias and Remote URL (https://host/mcp). Invalid URLs get Enter a valid http(s) URL.

    3. Add. Toast: Added "<alias>". It now appears under Servers.

    If the catalog table itself is empty, you can still add by URL.

    Uncertified catalog rows cannot be enabled in place. The product tells you to add them as custom if you need them now. Ask your Nightfall account team if you want an entry certified.

    Tool lists refresh when you enable a server, after a user's first connection, on Refresh tools, and in the background. New tools start enabled. Disable the ones you do not want clients to see.


    1. Admin enables the certified GitHub catalog entry (or adds it as custom if that is how you run it).

    2. If the provider needs a static OAuth app, an admin uses Set OAuth client / Update OAuth client. Credentials are write-only. You will not see the secret again.

    3. Each member clicks Connect and finishes GitHub's consent.

    4. Admins see N connected

    Set OAuth client is also on the server detail Setup card when the product has setup guidance for that server.


    Auth type PAT:

    • Credential scope: Shared plus Paste PAT (shared): one token, injected for everyone.

    • Credential scope: Per-user plus each person Set my PAT: no fallback to a shared token.

    PAT auth header on the server detail page defaults to Default (Authorization: Bearer) unless an admin changes it.

    Admins can paste a PAT on a None auth server to switch it to PAT.


    You approved GitHub, then legal says pause it, or the vendor is in an incident. You do not want to rebuild the alias and OAuth app next week.

    1. Open Enabled Servers.

    2. Block. The confirm dialog warns if people are still connected. Status becomes Blocked. Members no longer see the row. Clients lose every tool from that alias.

    3. Unblock when the pause is over.

    Use Remove only when the server should not return and stored credentials should die with it. The dialog says this cannot be undone.

    Rename changes the alias, which changes the <alias>__<tool> names clients already have. Do that on purpose, not as a substitute for Block.


    GitHub (or Linear, Notion, any catalog server) ships read, write, and delete in one package. Most teams want search and list, not delete_* or admin.

    1. Open the server (row click). Breadcrumb: Enabled Servers › {alias}.

    2. On the Tools card, use the Write, Delete, and Unspecified groups. Columns: Tool Name, Description, Enabled (admin) or Enabled for me (member).

    3. Select the tools you do not want in agents. Bulk Disable.

    Admins can also see Disabled for me when a member hid a tool only for themselves. That does not protect the company. Org risk belongs on the admin Enabled column.

    After Refresh tools, walk Write and Delete again. New tools start enabled.

    The Tools tab (admin, org-wide) is an index only: Exposed name, Server, Description. Search there. Change enablement on the server. If the index is empty: Refresh tools on a server from the Servers tab.


    Users (admin): Console users with MCP Gateway access. Invite people from your company directory without exposing them in the admin user list.

    1. Invite users.

    2. Directory search or Upload CSV (one email per line).

    3. Assign MCP Admin or MCP User.

    4. Outcomes you may see: already invited, already has this role, or a cross-company conflict.

    The table: Email, Role, Created, Status (ACTIVE, or EXPIRES IN N DAY(S)).

    Edit changes Admin ↔ User. Delete removes MCP Gateway access only. Other Nightfall access stays. You cannot edit or remove yourself.

    Pending invitations appear in the table. There is no revoke action on a pending invite in the current console.

    MCP-only users are not a replacement for Nightfall Settings → Users & Roles. Invite here when you want gateway access without a full console seat.


    Audit (admin). Default window is the last 7 days.

    Columns: User, Server, Tool, Method, Event, Status, Time. Search by server or tool name. Status values are humanized: success, failure, error, denied, blocked.

    Open a row for Request, Identifiers (User, Session, Event ID, Request URL), and Request payload.

    Export to CSV → Send Download Link. You get email within 15 minutes.

    You can deep-link with ?userId= on the Audit URL. There is no "View logs" button on user rows yet.

    Members who hit Audit see You don't have access to audit logs.

    This tab is a call log. It does not show a separate "would block" or policy-reason column. To take a capability away, Block the server or Disable the tool (see What you can turn off).

    Audit stores who called, which server and tool, method, event, status, identifiers, and the request arguments (capped at 8 KiB). Backend tool responses are not stored.

    When someone leaves: Delete their MCP Gateway access on Users (or remove them from Nightfall). Revoke or reconnect is per server via Connect / disconnect on Enabled Servers. Their next client call should fail once access is gone. Re-inviting them later starts a fresh sign-in.


    These clients use custom connectors, not the four Setup file snippets. Copy the MCP endpoint URL from Setup first.

    You need a Claude Team or Enterprise plan for an org-wide connector. Only an Owner or Primary Owner can add it to the organization.

    1. In Claude, open Organization settings > Connectors (or Admin settings > Connectors).

    2. Add / Add custom connector. If asked for a type, choose Custom then Web.

    3. Name it something people will recognize, for example Nightfall MCP Gateway.

    Each member still selects Connect on that connector, signs in to Nightfall, and Approve. Adding the connector does not grant access by itself.

    In a conversation, turn the connector on with + then Connectors. Tools show as <alias>__<tool>. Some backends still need Connect on Enabled Servers in Nightfall (GitHub is the usual case).

    To make the gateway the only Claude path: add only this connector, and do not add direct Linear/Notion/GitHub connectors for the same services. On Team and Enterprise, members cannot add org connectors themselves. Claude Code still reads a local config file a user can edit.

    On Pro or Max, a person can Add custom connector themselves with the same URL and empty OAuth fields.

    If tools are missing in chat: the connector may be off for that conversation, Nightfall sign-in may be incomplete, or the backend still needs Connect in the Nightfall console. HIPAA-ready Claude Enterprise plans can block custom connectors org-wide; that is a Claude admin setting, not Nightfall.


    ChatGPT can attach the same Setup URL as a custom MCP app on Business, Enterprise, and Edu workspaces (developer mode). Individual paid plans can do this in developer mode as well.

    1. A ChatGPT admin turns on developer mode / custom MCP connectors under workspace permissions (exact labels vary by ChatGPT plan).

    2. Settings > Apps & Connectors > Create. Name it Nightfall MCP Gateway. Set the connector URL to the MCP endpoint URL from Setup. Authentication: OAuth. Leave static client fields empty.

    3. Scan tools and complete Nightfall sign-in when prompted. Publish when you are ready.

    ChatGPT can further restrict which of the gateway's tools that app may call. Nightfall still decides which servers and tools exist at all. Prefer doing tool governance in Nightfall so Cursor, Claude, and ChatGPT see the same set.

    On Enterprise/Edu, refresh the app's action list when you enable new Nightfall servers. On Business, published apps may be frozen; you may need to recreate the app to pick up new tools.

    Members authenticate individually on first use. Publish only the gateway app for services you already route through Nightfall; do not also enable ChatGPT's direct connector for the same GitHub or Linear instance if you want a single path.


    Server info can include Alias, Canonical name, Remote URL, MCP URL, Transport, Additional headers, PAT auth header, Created, Last validated, Last tools refresh, Validation, Check results, OAuth client ID, Scopes, and Discovered OAuth endpoints.

    Remove server and Validate now sit in the header next to Connect.

    If the alias is wrong: Server not found.


    URL shape: /mcp/authorize with request_id and short_code from the client.

    • Missing params: This link is invalid. Restart from the MCP client.

    • Loading: Signing you in...

    • Main: Connect to Nightfall MCP Gateway. Copy explains that an MCP client is requesting access; decline if you did not start it.

    • Logged in as {email}. Switch account

    Questions on that page go to your Nightfall admin or .


    What you see
    What to do

    Command palette (when you have access): Go to MCP Gateway Setup, Go to Enabled Servers, Go to Server Catalog, Go to Gateway Tools, Go to Gateway Audit, Go to Gateway Users.


    is the inventory of what endpoints already run, including servers nobody approved. The gateway is only the servers you enable here, plus the credentials and the call log.

    A usual split: find shadow MCP on Visibility, decide what is allowed, enable that set on the gateway, point clients at Setup, and use Audit (and Visibility notifications) for everything else.

    File-configured clients (Cursor, Claude Code, VS Code, Windsurf) can still be pointed at a vendor URL instead of Setup. This tab does not override those files. Claude.org connectors and ChatGPT workspace apps are admin-controlled on the higher plans.

    Users
  • Setup

  • on Enabled Servers and finish that provider's sign-in.
  • The client lists tools as <alias>__<tool> (for example github__search).

  • Each invocation shows up on Audit.

  • Some OAuth servers ask for a client id and secret in the wizard. Those fields are optional here. You can leave them blank and use Set OAuth client on the server later.

  • Success toast: Enabled "<alias>". It now appears under Servers.

  • . Ask an MCP Admin.
  • For OAuth servers, click Connect. Allow popups. If you see Popup blocked, allow popups and click Connect again.

  • Connection states: Connected, Token expired, Not connected.

  • For PAT servers, use Set my PAT.

  • On a server's tool list you can turn Enabled for me off for tools you do not want in your client. Admins can also disable a tool for everyone.

  • on the row, not the token.

    Confirm in a client: those names are gone from the tool list and a call to them fails.

    Paste the MCP endpoint URL from Setup. Leave OAuth Client ID and Client Secret empty. The gateway registers Claude dynamically.
  • Add.

  • .
    Deny
    /
    Approve
    .
  • After deny: Access declined. Close the tab.

  • Failure: Couldn't complete this request. Close the tab and connect again.

  • IT cannot see or revoke the GitHub / Linear tokens sitting in every developer's client

    Broker those credentials. Admins see that a connection exists and can cut it. They never see the secret.

    You cannot answer "who called delete_issue last week, with what arguments"

    Audit records user, server, tool, status, and request payload.

    Someone left and their AI connectors still work until each vendor token expires

    Remove MCP access (or the Nightfall user). The next client call fails. Revoke the upstream connection so the provider is told to invalidate its token.

    GitHub MCP is useful for search, dangerous for write and delete

    Keep the server enabled. Disable the write and delete tools. Clients stop listing them and cannot call them.

    A vendor is having an incident, or you want Linear gone from every client today

    This server must stop for everyone, but you may bring it back

    Block on Enabled Servers

    Members lose the row. Tools vanish from the aggregator.

    Alias, URL, auth setup, stored credentials

    {
      "mcpServers": {
        "nightfall": {
          "url": "<MCP endpoint URL from Setup>"
        }
      }
    }
    claude mcp add --transport http nightfall <MCP endpoint URL from Setup>
    {
      "mcpServers": {
        "nightfall": {
          "serverUrl": "<MCP endpoint URL from Setup>"
        }
      }
    }
    {
      "servers": {
        "nightfall": {
          "type": "http",
          "url": "<MCP endpoint URL from Setup>"
        }
      }
    }

    MCP Gateway isn't enabled for your organization

    Nightfall rep. Then Check again.

    Still not enabled - check back again shortly.

    Provisioning still running.

    Your MCP endpoint is unavailable right now

    What you can turn off

    Who sees what

    How a call actually travels

    Scope

    Credentials Management

    Scenario: Getting Started

    1. Confirm the tenant is live

    2. Enable a catalog server

    3. Check Enabled Servers

    4. Point a client at Setup

    5. Approve the gateway, then call a tool

    Scenario: an employee connects their own client

    Scenario: add a server that is not in the catalog

    Scenario: GitHub (or any upstream OAuth) for each person

    Scenario: shared PAT vs per-user PAT

    Scenario: pull a server out of every client (Block or Remove)

    Scenario: allow a server, hide the dangerous tools

    Scenario: invite MCP people without making them full Nightfall admins

    Scenario: investigate a tool call

    Scenario: Claude Cowork, claude.ai, or Claude Desktop

    Scenario: ChatGPT custom connector

    Server detail

    Consent page (what users see in the browser)

    If something fails

    How this relates to MCP Server Visibility

    MCP Server Visibility
    Creating an AI Agent Security Policy
    MCP Server Visibility
    support@nightfall.ai
    MCP Server Visibility

    Block the server. Config stays. Tools disappear. Unblock when you are ready.

    You are done with a server and want credentials wiped

    Remove. This cannot be undone.

    Contractors should use the gateway without a full Nightfall admin seat

    Invite them as MCP User on the Users tab.

    Claude or ChatGPT should not also have a direct GitHub connector

    Publish only the Nightfall URL as the org connector. Do tool governance once, here.

    This server must go away for good

    Remove

    Gone.

    Nothing. Tools cache and credentials are deleted.

    The server stays. These tools must not exist for anyone (delete, admin, write)

    Disable on the server's Tools card (admin Enabled column). Bulk select works.

    Disabled tools drop out of listings and cannot be invoked. Other tools stay.

    The server, other tools, everyone's connections

    The server is fine for the company. I do not want this tool in my client

    Turn off Enabled for me

    Only that person's client loses the tool

    Org-wide enablement. Admins still see Disabled for me

    Wait for tenant provisioning to finish.

    Catalog Enable disabled, uncertified tooltip

    Use Add custom server.

    Popup blocked

    Allow popups, click Connect again.

    Token expired

    Connect again on that server.

    Tools missing in the client

    Server blocked, tool disabled, or you still need Connect / Set my PAT. Validation may be Tools discovery failed or Awaiting first user OAuth.

    No tools cached on the Tools tab

    Refresh tools on Enabled Servers.

    Client cannot authenticate

    Confirm you pasted the URL from Setup. Cursor uses url, Windsurf uses serverUrl, VS Code uses servers + type: http, Claude Code uses the CLI.

    Endpoints - Device List Page

    Overview

    The Device List page is the fleet view for the Nightfall endpoint agent. It shows every macOS and Windows device that has checked in to your Nightfall tenant, along with the agent state, MDM profile state, browser-extension state, and any active policy exceptions for each device.

    Use this page to:

    • Confirm a fresh rollout reached every device you targeted.

    • Find devices that need attention (agent in error, macOS permissions missing, MDM profile out of date, extension not installed).

    • Confirm the Nightfall browser extension is loaded and enabled on the browsers your users actually run.

    • Triage a single device by opening the side panel for full status detail.

    • Remove a device that is decommissioned or no longer in scope.

    Where to find it. Configuration → Integrations → Mac or Windows Endpoints.


    At the top of the page you will see:

    • Device Information heading, with the line "The Nightfall endpoint agent has been deployed to the following devices. After installation, the agent automatically receives updates to ensure it stays secure and up to date."

    • A 60-day cleanup notice: "Devices that have been disconnected for more than 60 days are automatically removed from this list." Once a device is removed, the only way to bring it back is for that device to reconnect and check in.

    • Total device count. Shown immediately above the table as N devices (or 1 device). This number reflects all filters and search applied to the page.


    When a new macOS agent version ships with new security features that require an updated MDM profile, an orange button labeled MDM Profile Update Required (Mac Only) appears in the filter row.

    Clicking the button opens the MDM Profile Update Required modal:

    • Headline: "Profile update required for devices."

    • Body: "Agent version X.Y.Z includes new security features that require an updated MDM profile. Devices will continue to function but may have limited capabilities until the profile is updated."

    • Devices Requiring Update count, sourced from the agent's profile-version handshake against the latest published profile.

    • What's New in This Profile

    If you do not see this banner, your fleet's profiles are at the expected version and no action is needed.


    Four single-click chip filters sit in the filter row. Click a chip to apply, click again to clear. Clicking a chip replaces any other filters you have set.


    The Add Filters dropdown gives you the full filter set. Filters compose with AND across types.

    Filter selections are stored in the URL so you can bookmark or share a filtered view.


    Columns appear in this order. Click the header tooltip (the small info icon) to see the in-product description.

    • Tooltip: "Operating system reported by the device at last check-in."

    • Renders the OS logo (Apple or Windows). Hover the cell to see the OS version reported by the device.

    • Tooltip: "Hostname and unique device identifier."

    • Two-line cell: device hostname (bold) above the unique device ID. Hover to see both spelled out. This column is sortable.

    • Tooltip: "Primary user signed in to this device (from MDM or directory sync)."

    • The user-account email Nightfall received from your MDM or directory sync. Shows — when no user is associated.

    • Tooltip: "Connection state and last-seen timestamp."

    • Pill badge plus a relative timestamp below it (for example, "3 minutes ago"). Hover the cell to see the absolute timestamp.

    • Tooltip: "The agent updates automatically - no manual action required. If a device hasn't been online recently, the version shown here may be outdated."

    • The version string the agent last reported. If the version is older than the latest published version for that OS, an amber warning triangle appears next to it. Hover the triangle to see "Outdated version. Latest: X.Y.Z."

    • Tooltip: "macOS system permissions and agent runtime errors detected on this device."

    • Two states:

      • All granted (green check). No missing macOS permissions and no agent runtime errors. Hovering reveals what was checked: on macOS, the three permissions (Full Disk Access, Screen Recording, Accessibility) plus "No agent errors"; on Windows, "No issues detected" plus "No agent errors."

    For each missing permission, the tooltip shows:

    The three macOS permissions tracked here are:

    • Full Disk Access. Required to scan files outside the user's home directory.

    • Screen Recording. Required for screen-based exfiltration detection.

    • Accessibility. Required for thick-app and clipboard monitoring.

    For each agent error, the tooltip shows "Agent error: name." The six error codes are:

    • User Agent Not Connected. The user-space agent component is not running or cannot reach the system extension.

    • Driver Missing. The Nightfall kernel or system driver is not present on the device.

    • Driver Not Loaded. The driver is installed but did not load. Usually a reboot or an MDM payload approval is needed.

    • User Data Missing.

    Profile status sub-line (macOS). When MDM profile state is available, it appears under the permissions summary as one of: Up to Date, Out of Date, or Not Installed. This pairs with the MDM Profile Update Required banner described in 3 above.

    • Tooltip: "Browsers with the Nightfall extension installed and any attached profiles."

    • Shows up to three browser icons inline, each with a status dot. A +N chip appears when more than three browsers report state.

    Hover the cell for the full list. Each row pairs the browser, the status text, and the status dot.

    Supported browsers. Chrome, Edge, Firefox, Safari, Arc, Atlas, Brave, Chrome Beta, Comet, Vivaldi. Safari and Atlas were added in agent v1.2.13.x on macOS and v1.4.35.x on Windows.

    • Tooltip: "Whether the agent runs without end-user UI."

    • Green On badge: the agent is running in stealth mode (no tray icon, no notifications).

    • Gray Off badge: the agent runs visibly to the end user.

    • Not Available: the device runs an older agent build that does not report stealth state.

    • Tooltip: "Active policy overrides currently applied to this device."

    • None when zero active exceptions exist.

    • N active (violet) when one or more exceptions are scoped to this device. Click the link to jump to the Policy Exception tab in the side panel.

    This column is visible only when policy exceptions are enabled on your tenant.

    • A trash icon at the end of each row. Click to open the single-device delete confirmation. See 7.


    • Sort. Click the Device Name & ID column header to toggle ascending or descending sort. This is the only sortable column on this page.

    • Row select. A checkbox in each row. A header checkbox selects every row on the current page. The header checkbox shows a partial-select indicator when some rows on the page are selected.

    • Bulk delete. When at least one row is selected, a red Delete N Device(s) button appears in the filter row. Clicking it opens the bulk delete confirmation.

    • Are you sure you want to remove this device?

    • Removing this device will take it off the monitored list. If the device reconnects to your Nightfall tenant, it will automatically reappear.

    • What happens next?

      • This device will no longer appear in the monitored list.

    • Are you sure you want to remove these N devices?

    • Removing these devices will take it off the monitored list. If the devices reconnect to your Nightfall tenant, they will automatically reappear.

    • Disclaimer: This action does not block, disable or uninstall the Nightfall agent from the devices.

    • Primary: Remove Devices.

    Bulk delete is capped at 100 devices per call. If you need to remove more, do it in batches.


    Click any row to open the side panel. It has three tabs in this order: Summary, Browser Extension, Policy Exception. The Policy Exception tab is visible only when policy exceptions are enabled on your tenant. Navigate between devices on the current page using the arrows at the top of the panel.

    Nine fields in this order:

    1. Operating System. OS logo plus version.

    2. User Email. Or — if not associated.

    3. Agent Status. The same pill described in §6.4.

    4. Last Connection.

    Lists every browser on this device that has the Nightfall extension installed.

    For each browser:

    • Browser icon and name.

    • Connected (green dot) or Disconnected (red dot). Disconnected typically means the browser is closed; reopen the browser and the extension reconnects.

    • Per-profile count (for browsers that support profiles, like Chrome). Green dot = every profile has the extension enabled; amber = some profiles do; red = none do.

    • Click the row to expand the per-profile table: Profile name, profile email,

    If the device has no browser-extension data yet, the tab reads "No browser extension data available." If it has data but no extensions are installed, it reads "No browser extensions detected."

    Lists every active policy override scoped to this device, with policy name, scope, and expiration. From here you can view or revoke an exception. This tab is available when policy exceptions are enabled on your tenant.



    Most columns work the same on macOS and Windows. The ones that do not:

    The Phase 2 Windows parity for the Device List page shipped in Windows agent v1.4.35.x.


    How long until a device shows up after I install the agent?

    On the agent's first successful heartbeat, the device appears. Heartbeats run on a short interval after install, so a device that completes install while online typically appears within a minute.

    When does a device flip from Online to Disconnected?

    When no heartbeat has been received from the agent for more than six hours. The threshold is set tenant-wide and applies equally to macOS and Windows.

    When is a device removed from this list?

    After 60 consecutive days disconnected. The agent record is deleted from the page; if that device comes back online and checks in, it reappears with a fresh record.

    A user changed Mac. Will the old device still appear?

    Yes, until 60 consecutive disconnected days pass. If you want to remove the old device sooner, delete it from this page. The agent on the new Mac will appear once it checks in.

    Does deleting a device uninstall the agent?

    No. Delete only takes the device off the monitored list. The agent keeps running on the device, and if it heartbeats again, the device reappears. To remove the agent itself, run the uninstall through your MDM or follow the manual uninstall steps.

    Why can a removed device come back automatically?

    Delete sets the device record to "removed" in the Nightfall backend. The agent on the device does not know about the deletion. On its next heartbeat the backend creates a new record, which causes the device to show up again. If you want a permanent removal, uninstall the agent through your MDM or device management workflow.

    How many devices can I delete at once?

    Up to 100 per bulk delete. If you have more, run a few batches.

    Why does the "Disconnected" filter chip include Offline too?

    The "Stale Devices" chip is meant as a one-click view for any device that is not actively reachable. Offline is a reserved status today; selecting Stale Devices covers both states so you do not miss anything when the platform expands.

    Why is the Agent Errors filter showing six options but the Permissions / MDM column says "N issues"?

    "N issues" counts every missing macOS permission and every active agent error code on that device. The Agent Errors filter only filters on the agent error side; if you need to filter on missing permissions, use the Missing Permissions filter instead.

    A device has an error code like "ES Client Unauthorized" and stays in Error after a reboot. What now?

    This usually means the system extension or kernel driver was denied at the OS layer. On macOS, that is typically a missing Allow Endpoint Security Client approval in your MDM configuration profile. Push the corrected profile via your MDM. If you do not run macOS through MDM, approve manually in System Settings → Privacy & Security.

    The MDM Profile Update Required banner appeared, but the devices I patched still show "Profile out of date."

    The agent re-reports profile version on its next heartbeat. If the profile reached the device but the column has not updated, wait one heartbeat cycle. If it still shows out of date after that, confirm in your MDM that the profile is delivered and approved on the affected device.

    Why does Stealth show "Not Available" on some devices?

    Older agent builds do not report stealth state. Update the agent to the current build; the column populates on the next heartbeat.

    I see a browser as "Disconnected" in the side panel even though the extension is installed. Why?

    Browser extensions only heartbeat when the browser is open. A closed browser shows as Disconnected. Open the browser and the status returns to Connected within a few seconds.

    Why is Safari extension state showing up on some devices but not others?

    Safari extension tracking was added in macOS agent v1.2.13.x. Devices on older agent builds will not report Safari state until they update.

    Can I force-install the extension from this page?

    The Device List page reports state; it does not push the extension. Force-install runs through your browser-management mechanism (Google Workspace policy for Chrome, MDM-delivered policy for Edge, Firefox, Brave, Arc, Atlas, Comet, and Vivaldi). Safari is manual install only.

    The Permissions / MDM column shows "All granted" but the user can't paste in Claude. What gives?

    "All granted" only confirms macOS system permissions and agent runtime health. If a paste is blocked, the cause is usually a Detection & Response policy match, not a permissions issue. Open the Detection & Response page and filter by that user to find the violation.

    Where does the CSV export go?

    The "Export to CSV" button generates a CSV reflecting the current filters and search, then emails a download link to the address you are signed in with. The link expires after the standard Nightfall report retention window.

    Can I export only the devices I have selected?

    The CSV export reflects the current filters and search, not the per-row selection. To export a subset, filter to that subset first, then export.

    Why does the column tooltip mention "from MDM or directory sync" for User Email, but my device shows —?

    A device shows — when Nightfall has not received a user mapping. The two paths that populate this field are: MDM-pushed user assignment in the install payload, and identity-provider sync (Okta, Microsoft Entra ID, Google Workspace). If you have neither configured for that device, the column stays blank.

    Why is the Stealth column populated for some devices and not others?

    The agent only reports stealth state from v1.2.12.x onward. Devices on older builds will show "Not Available" until they update to the supported version range.

    What is the Nightfall Diagnostics tab I sometimes see in the side panel?

    That tab is gated to Nightfall support staff. If you see it, it is because your account is impersonating into a support session. There is no customer-facing configuration in it.


    For power users:


    The following browsers are recognized: Chrome, Firefox, Edge, Safari, Edge, Arc, Brave, OpenAI Atlas, Perplexity Comet, Vivaldi.

  • Search. A search box, placeholder "Search devices". When any filter is active, the placeholder changes to "Search filtered devices". Search matches against the device ID prefix.

  • Export to CSV. Opens an "Export as CSV" modal. The full export is delivered by email to your signed-in address. The modal reads "A download link for your report will be sent to your-email-address." The primary action is "Send Download Link."

  • lists the capabilities the new profile enables.
  • How to Update lists four steps: download the profile, upload it to your MDM (Kandji, Jamf, Intune, and so on), push it to affected devices, and let the agent re-apply on next check-in.

  • Primary action: Download Updated Profile.

  • N issue(s) (amber alert triangle). One or more missing permissions, agent errors, or both. Hovering reveals each item.
    The agent could not resolve the logged-in user's identity.
  • Browser Extension Not Connected. The agent expects a browser extension that is not currently reporting in.

  • ES Client Unauthorized. macOS denied the Endpoint Security client. Reapprove the system extension through your MDM.

  • If the device reconnects, it will be added back automatically.

  • This action does not block, disable or uninstall the Nightfall agent from the device.

  • Primary: Remove Device. Secondary: Cancel.

  • Relative time since last heartbeat, or
    —
    if never connected.
  • Agent Version. Current reported version.

  • Missing Permissions. None when complete, or the list of missing macOS permissions in amber.

  • Profile Status. Up to Date, Out of Date, Not Installed, or Unknown.

  • Stealth Mode. On, Off, or Not Available.

  • MAC Addresses. Every MAC address the device reports. Hidden if the device reports none.

  • Enabled
    or
    Disabled
    state.

    Chip

    What it matches

    Needs Attention

    Any of: connection status is Error; any required macOS permission is missing (Full Disk Access, Screen Recording, or Accessibility); MDM profile is Not Installed; the Nightfall extension is not installed on Chrome, Edge, Firefox, Safari, Arc, or Brave.

    Stale Devices

    Connection status is Disconnected or Offline.

    Update Available

    Filter

    Values

    Notes

    OS

    macOS, Windows

    Agent Status

    Status

    Color

    Meaning

    Online

    Green

    The agent is heartbeating to Nightfall normally.

    Disconnected

    Missing {permission}:
    macOS requires {permission} to monitor file operations and detect
    sensitive data exfiltration.
    Guide users to: System Settings → Privacy & Security → {permission}
    → Enable Nightfall

    Dot color

    State

    Green

    Extension installed and connected.

    Amber

    Browser installed but the Nightfall extension is not installed yet.

    Red

    Symptom

    What to check first

    Status is Disconnected.

    The device may be off, asleep, or off-network. If it has been disconnected for under six hours, wait. If longer, confirm the device is online and that the Nightfall agent service is running. If the device is decommissioned, delete it from the list.

    Status is Error.

    Open the side panel, look at the agent error code under Permissions / MDM, and follow the matching action (driver reload, reapprove system extension, restart the agent service).

    Status is Missing full disk access (macOS).

    Surface

    macOS

    Windows

    OS column

    Apple logo

    Windows logo

    Agent Status: Missing full disk access

    Proto field

    UI label

    Notes

    os

    OS

    MAC_OS, WINDOWS.

    device_name

    2. Page summary

    3. MDM Profile Update Required banner (macOS only)

    4. Quick filters

    5. Add Filters

    6. Column reference

    6.1 OS

    6.2 Device Name & ID

    6.3 User Email

    6.4 Agent Status

    6.5 Agent Version

    6.6 Permissions / MDM

    6.7 Browser Extensions

    6.8 Stealth

    6.9 Policy Exceptions

    6.10 Delete

    7. Sorting, selection, and bulk actions

    Single-device delete confirmation

    Bulk delete confirmation

    8. Device detail side panel

    8.1 Summary

    8.2 Browser Extension

    8.3 Policy Exception

    9. What to do when…

    10. Platform support matrix

    11. Frequently Asked Questions (FAQ)

    12. Field reference

    Supported Browsers

    Agent is on a version older than the latest published version for that OS.

    No MDM Profiles

    MDM profile status is Not Installed or Out of Date. (macOS only.)

    Online, Disconnected, Error, Offline

    Agent Version

    Up to Date, Out of Date

    Compared against the latest published version per OS.

    Stealth Mode

    Active, Inactive

    Profile Status

    Up to Date, Out of Date, Not Installed

    macOS only. Hidden on Windows.

    Missing Permissions

    Full Disk Access, Screen Recording, Accessibility

    macOS only. Hidden on Windows. Multi-select.

    Agent Errors

    User Agent Not Connected, Driver Missing, Driver Not Loaded, User Data Missing, Browser Extension Not Connected, ES Client Unauthorized

    Multi-select.

    Browser Extensions

    Chrome, Edge, Firefox, Safari, Arc, Brave, each with "Installed" or "Not Installed"

    Multi-select. Pairs of browser + installed state.

    Red

    The agent has not sent a heartbeat for more than six hours. The device may be powered off, asleep, off-network, or the agent service may be stopped.

    Error

    Red

    The agent is reachable but has reported one or more runtime errors (see the Permissions / MDM column for the specific error codes).

    Missing full disk access

    Amber

    macOS-only. The agent is running but cannot scan files because Full Disk Access has not been granted in System Settings.

    Starting

    Gray

    The agent is in the middle of starting up. This state is brief and usually resolves on the next check-in.

    Offline

    Gray

    Reserved status. Treat the same as Disconnected for action.

    NA

    Gray

    The status was not reported. Usually means an older agent build that pre-dates the current status fields.

    Error reading extension state.

    Gray

    Browser not installed on this device, or status unknown.

    Guide the user to System Settings → Privacy & Security → Full Disk Access → enable Nightfall. The agent re-checks within one heartbeat.

    N issue(s) with missing permissions.

    macOS permissions cannot be force-enabled by the agent itself. Either guide the user through System Settings, or push the permission via your MDM payload.

    Profile not installed (macOS).

    Use the MDM Profile Update Required banner to download the latest profile and push it via your MDM.

    Profile out of date (macOS).

    Same path: pull the latest profile and push it to the affected devices. The agent works with the old profile but may lack newer capabilities.

    Extension not installed on a supported browser.

    Force-install via Google Workspace policy (Chrome) or your MDM's browser-extension payload (Edge, Firefox, Brave, Arc, Atlas, Comet, Vivaldi). Safari is manual install only.

    Extension installed but Disconnected in the side panel.

    Usually the browser is closed. Reopen the browser; the extension reconnects on launch. If it persists with the browser open, reinstall the extension.

    Stealth = Off on a device you expected to be stealth.

    Stealth mode is set at agent install time and is not flipped by a config push. Re-deploy the agent with stealth selected to convert.

    Agent version is outdated.

    No action needed. The agent self-updates on its next check-in. The amber triangle clears automatically.

    Yes

    Not applicable

    Permissions / MDM column: macOS permissions

    Full Disk Access, Screen Recording, Accessibility tracked

    Not tracked

    Permissions / MDM column: agent errors

    All six error codes

    All six error codes

    Permissions / MDM sub-line: profile status

    Yes

    Not applicable

    Stealth column

    Reported (On / Off)

    Reported (On / Off)

    Browser Extensions: Safari

    Yes (added in v1.2.13.x)

    Not applicable

    Browser Extensions: authoritative install state

    Agent reports

    Agent uses an on-disk scan to verify the extension is actually loaded (since v1.4.22)

    MDM Profile Update Required banner

    Yes

    Not applicable

    Profile Status filter

    Yes

    Hidden

    Missing Permissions filter

    Yes

    Hidden

    Device Name

    Hostname.

    device_id

    Device ID

    Unique device identifier assigned by the agent.

    user_email

    User Email

    From MDM or directory sync.

    connection_status

    Agent Status

    CONNECTED → Online; DISCONNECTED → Disconnected; ERROR → Error; MISSING_FULL_DISK_ACCESS → Missing full disk access; STARTING → Starting; OFFLINE → Offline; unspecified → NA.

    last_connection

    Last Connection

    Used to render the relative time below the status pill.

    agent_version

    Agent Version

    Compared to latest published version per OS to drive the outdated triangle.

    os_version

    OS Version

    Shown on hover over the OS column.

    extension_installation_statuses

    Browser Extensions

    One entry per browser. BROWSER_INSTALLED (browser present, no extension), EXTENSION_INSTALLED (extension present), ERROR, BROWSER_NOT_INSTALLED, UNKNOWN.

    BrowserExtensionStatus.extension_connected

    Per-browser Connected/Disconnected

    True when at least one profile in that browser is heartbeating.

    BrowserProfile.name / .email / .enabled

    Per-profile row in the side panel

    policy_overrides_count

    Policy Exceptions

    0 → None; >0 → "N active" link.

    stealth_mode

    Stealth

    STEALTH_MODE_STATUS_ACTIVE → On; STEALTH_MODE_STATUS_INACTIVE → Off; STEALTH_MODE_STATUS_UNKNOWN → Not Available.

    profile_status

    Profile Status

    PROFILE_STATUS_UP_TO_DATE, PROFILE_STATUS_OUT_OF_DATE, PROFILE_STATUS_NOT_INSTALLED, PROFILE_STATUS_UNKNOWN. macOS only.

    missing_permissions

    Missing Permissions

    AGENT_PERMISSION_FULL_DISK_ACCESS, AGENT_PERMISSION_SCREEN_RECORDING, AGENT_PERMISSION_ACCESSIBILITY. macOS only.

    errors

    Agent Errors

    USER_AGENT_NOT_CONNECTED, DRIVER_MISSING, DRIVER_NOT_LOADED, USER_DATA_MISSING, BROWSER_EXTENSION_NOT_CONNECTED, ES_CLIENT_UNAUTHORIZED.

    mac_addresses

    MAC Addresses

    One per row in the Summary tab.