Skip to content

Deploy Lookout at scale

Use this script with any tool that runs PowerShell as SYSTEM: an RMM, Intune, or a Group Policy startup script. It downloads Lookout, verifies the checksum, and installs it. On a device that's already enrolled it updates Lookout without using the key, so it's safe to run on a schedule even after you revoke the key.

Install-TrimtabLookout.ps1
# Set the client's enrollment key. Store it in your tool's secure variables where possible.
$EnrollmentKey = 'ek_your_key_here'
$ServerUrl     = 'https://app.trimtabsec.com'
$Package       = 'https://docs.trimtabsec.com/downloads/trimtab-lookout-0.4.0.zip'
$Sha256        = '8AAD3E6BFA56B99D9F9ADE8FF7D507FC54DC2A02F8AC69B8FD88AEDD731606F0'

$ErrorActionPreference = 'Stop'
[Net.ServicePointManager]::SecurityProtocol = [Net.ServicePointManager]::SecurityProtocol -bor [Net.SecurityProtocolType]::Tls12

$zip = Join-Path $env:TEMP 'trimtab-lookout.zip'
$dir = Join-Path $env:TEMP 'trimtab-lookout'
Invoke-WebRequest -Uri $Package -OutFile $zip -UseBasicParsing
if ((Get-FileHash $zip -Algorithm SHA256).Hash -ne $Sha256) { throw 'Checksum mismatch: the download may be corrupted or tampered with.' }

Expand-Archive $zip -DestinationPath $dir -Force
$installer = Join-Path $dir 'agent\Install-ComplianceAgent.ps1'
if (Test-Path "$env:ProgramData\Trimtab\config.json") {
    # Already enrolled: update Lookout and keep the device's registration.
    & powershell.exe -NoProfile -ExecutionPolicy Bypass -File $installer
} else {
    & powershell.exe -NoProfile -ExecutionPolicy Bypass -File $installer -ServerUrl $ServerUrl -EnrollmentKey $EnrollmentKey
}
Start-ScheduledTask -TaskName 'Trimtab Lookout Scan'
Remove-Item $zip, $dir -Recurse -Force -ErrorAction SilentlyContinue
  1. Create a new PowerShell component or script in your RMM.
  2. Paste the script above. Put the enrollment key in a site-level or client-level secure variable, and reference it instead of hard-coding it.
  3. Run it as SYSTEM against the client's Windows devices.
  4. Schedule it once, or as a recurring job so new devices are picked up automatically.
  1. In the Intune admin center, go to Devices → Scripts and remediations → Platform scripts → Add → Windows 10 and later.
  2. Upload the script with the client's key filled in.
  3. Set Run this script using the logged on credentials to No (runs as SYSTEM), Enforce script signature check to No, and Run script in 64 bit PowerShell Host to Yes.
  4. Assign it to a device group for the client.
  1. Save the script to a share that domain computers can read, such as \\domain\NETLOGON\Trimtab.
  2. Create a GPO linked to the client's computers.
  3. Go to Computer Configuration → Policies → Windows Settings → Scripts → Startup → PowerShell Scripts, and add the script.
  4. Devices install Lookout at their next restart.

After rollout

Watch the Fleet page fill in, then revoke the enrollment key so it can't be reused.