Skip to content

Files and schedule

Locations

Path Contents
C:\Program Files\Trimtab\agent\ Lookout's scripts
C:\Program Files\Trimtab\rules\ Check definitions, standards, and Windows lifecycle data
C:\Program Files\Trimtab\report\ The template for local reports
C:\ProgramData\Trimtab\config.json The Bridge address, device ID, and the device credential (encrypted)
C:\ProgramData\Trimtab\output\ The 30 most recent results
C:\ProgramData\Trimtab\output\outbox\ Results waiting to upload (normally empty)

C:\ProgramData\Trimtab is readable only by SYSTEM and Administrators. The device credential is encrypted with Windows DPAPI and only works on that device.

Scheduled tasks

Both tasks run as SYSTEM with highest privileges:

Task Runs
Trimtab Lookout Scan powershell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -File "C:\Program Files\Trimtab\agent\Invoke-ComplianceScan.ps1" -Upload -Quiet -OutputDir "C:\ProgramData\Trimtab\output"
Trimtab Lookout Upload powershell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -File "C:\Program Files\Trimtab\agent\Send-QueuedResults.ps1" -OutputDir "C:\ProgramData\Trimtab\output"

These are the paths and commands to allow in application control tools.

Network

Lookout makes outbound HTTPS requests to https://app.trimtabsec.com only:

Request When
POST /api/v1/enroll Once, during installation
POST /api/v1/results After each scan, and for queued results