View Traps Startup Components on the Endpoint
Table of Contents
4.2 (EoS)
Expand all | Collapse all
-
- Set Up the Endpoint Infrastructure
- Activate Traps Licenses
-
- Endpoint Infrastructure Installation Considerations
- TLS/SSL Encryption for Traps Components
- Configure the MS-SQL Server Database
- Install the Endpoint Security Manager Server Software
- Install the Endpoint Security Manager Console Software
- Manage Proxy Communication with the Endpoint Security Manager
- Load Balance Traffic to ESM Servers
-
- Malware Protection Policy Best Practices
- Malware Protection Flow
- Manage Trusted Signers
-
- Remove an Endpoint from the Health Page
- Install an End-of-Life Traps Agent Version
-
-
- Traps Troubleshooting Resources
- Traps and Endpoint Security Manager Processes
- ESM Tech Support File
-
- Access Cytool
- View the Status of the Agent Using Cytool
- View Processes Currently Protected by Traps Using Cytool
- Manage Logging of Traps Components Using Cytool
- Restore a Quarantined File Using Cytool
- View Statistics for a Protected Process Using Cytool
- View Details About the Traps Local Analysis Module Using Cy...
- View Hash Details About a File Using Cytool
View Traps Startup Components on the Endpoint
Use the cytool startup query command
to view the status of startup components on the endpoint. When a
service or driver is disabled, Cytool displays the component as Disabled.
When a driver is enabled, Cytool displays the component as System.
When a service is enabled, Cytool displays the component Startup as Automatic.
- Open a command prompt as an administrator and navigate to the Traps folder (see Access Cytool).
- To view the current startup behavior of Traps drivers
and services, use the following command:Windows:
C:\Program Files\Palo Alto Networks\Traps>cytool startup query Service Startup cyverak System cyvrmtgn System cyvrfsfd System cyserver Automatic CyveraService Automatic
Mac:PANM2637HQ:bin jdoe$ sudo ./cytool startup query Password: Process name Startup status traps_agent Enabled trapsd Enabled authorized Enabled pmd Enabled kproc-ctrl Loaded