Deploy Lookout at scale¶
Use this script with any tool that runs PowerShell as SYSTEM: an RMM, Intune, or a Group Policy startup script. It downloads Lookout, verifies the checksum, and installs it. On a device that's already enrolled it updates Lookout without using the key, so it's safe to run on a schedule even after you revoke the key.
Install-TrimtabLookout.ps1
# Set the client's enrollment key. Store it in your tool's secure variables where possible.
$EnrollmentKey = 'ek_your_key_here'
$ServerUrl = 'https://app.trimtabsec.com'
$Package = 'https://docs.trimtabsec.com/downloads/trimtab-lookout-0.4.0.zip'
$Sha256 = '8AAD3E6BFA56B99D9F9ADE8FF7D507FC54DC2A02F8AC69B8FD88AEDD731606F0'
$ErrorActionPreference = 'Stop'
[Net.ServicePointManager]::SecurityProtocol = [Net.ServicePointManager]::SecurityProtocol -bor [Net.SecurityProtocolType]::Tls12
$zip = Join-Path $env:TEMP 'trimtab-lookout.zip'
$dir = Join-Path $env:TEMP 'trimtab-lookout'
Invoke-WebRequest -Uri $Package -OutFile $zip -UseBasicParsing
if ((Get-FileHash $zip -Algorithm SHA256).Hash -ne $Sha256) { throw 'Checksum mismatch: the download may be corrupted or tampered with.' }
Expand-Archive $zip -DestinationPath $dir -Force
$installer = Join-Path $dir 'agent\Install-ComplianceAgent.ps1'
if (Test-Path "$env:ProgramData\Trimtab\config.json") {
# Already enrolled: update Lookout and keep the device's registration.
& powershell.exe -NoProfile -ExecutionPolicy Bypass -File $installer
} else {
& powershell.exe -NoProfile -ExecutionPolicy Bypass -File $installer -ServerUrl $ServerUrl -EnrollmentKey $EnrollmentKey
}
Start-ScheduledTask -TaskName 'Trimtab Lookout Scan'
Remove-Item $zip, $dir -Recurse -Force -ErrorAction SilentlyContinue
- Create a new PowerShell component or script in your RMM.
- Paste the script above. Put the enrollment key in a site-level or client-level secure variable, and reference it instead of hard-coding it.
- Run it as SYSTEM against the client's Windows devices.
- Schedule it once, or as a recurring job so new devices are picked up automatically.
- In the Intune admin center, go to Devices → Scripts and remediations → Platform scripts → Add → Windows 10 and later.
- Upload the script with the client's key filled in.
- Set Run this script using the logged on credentials to No (runs as SYSTEM), Enforce script signature check to No, and Run script in 64 bit PowerShell Host to Yes.
- Assign it to a device group for the client.
- Save the script to a share that domain computers can read, such as
\\domain\NETLOGON\Trimtab. - Create a GPO linked to the client's computers.
- Go to Computer Configuration → Policies → Windows Settings → Scripts → Startup → PowerShell Scripts, and add the script.
- Devices install Lookout at their next restart.
After rollout
Watch the Fleet page fill in, then revoke the enrollment key so it can't be reused.