Endpoint Enrollment

Deploy the
MDR Agent

To enroll a device into 24/7 PinpointMDR monitoring, download and run the agent for your operating system below. It installs as a persistent service and begins streaming telemetry to our SOC within minutes — no session code or manual connection required.

Only install this agent on devices you own or are authorized to enroll. The agent runs as a persistent managed service and streams telemetry to the PinpointMDR SOC.
Available Downloads

Choose Your Operating System

macOS
Mac
macOS 12 Monterey and later
↓  ~8.4 MB  ·  .DMG

Download the macOS agent disk image. Open the .dmg, run the installer, and the device enrolls automatically into monitoring.

Requires macOS 12.0 or later  ·  Apple Silicon & Intel

↓  Download for Mac
Linux
Linux
Ubuntu 20.04 LTS and later
↓  ~5.1 MB  ·  .SH

Download the Linux agent shell script. Open a terminal, make the file executable, and run it to install and enroll the device.

Requires Ubuntu 20.04+ or Debian 11+  ·  x86_64

↓  Download for Linux
📱
Enrolling a mobile device?
For iOS and Android, your analyst will send a direct enrollment link via email or SMS, or push the agent through your MDM.
How It Works

Up and Running in Minutes

01
Request Enrollment

Request enrollment through your portal, email, or account manager. We'll provision your organization and issue an enrollment token.

02
Download the Agent

Select your operating system above and download the agent installer for the device you want to enroll.

03
Install & Enroll

Run the installer. The agent contacts the PinpointMDR cloud, authenticates with your enrollment token, and registers the device.

04
Monitoring Active

The device appears in your portal and begins streaming telemetry to the SOC. Detection, hunting, and response coverage is now live 24/7.

Your Privacy & Security

Safe, Secure & Transparent

We take endpoint enrollment seriously. Every agent connection is encrypted, audited, and fully under your control. You can see exactly what the agent collects, and can pause collection or uninstall at any time.

🔒
256-bit AES Encryption

All agent-to-SOC traffic is end-to-end encrypted. No telemetry is stored or transmitted outside the PinpointMDR environment.

👁
Full Visibility

You see every enrolled device and its detection status in real time, and can reclaim control or uninstall the agent instantly.

Persistent, Managed Service

The agent runs continuously as a managed service, keeping every enrolled endpoint under 24/7 detection coverage. Remove any device from monitoring anytime via the portal.

📋
Full Audit Logging

Every agent event and detection is logged with timestamps, analyst ID, and details. Available to you on request.

Frequently Asked Questions
Does the agent stay installed permanently?

Yes — unlike a one-off support tool, the MDR agent installs as a persistent background service so it can monitor continuously. You can uninstall it at any time from your OS or the PinpointMDR portal.

Can the agent be installed on my device without my knowledge?

Absolutely not. A device is only enrolled when you or your administrator intentionally install the agent and apply a valid enrollment token. No agent is ever deployed without an authorized install.

What happens when I want to stop monitoring?

The agent keeps running and reporting telemetry until you uninstall it or remove the device from your portal. Uninstalling stops all collection immediately.

Is my data shared or stored?

The agent collects security telemetry — process, network, and login events — not your personal files. Telemetry is retained per your retention policy for detection and audit purposes.

What if I'm suspicious of a request to install this?

Always verify with our office at (303) 555-0100 before installing. Legitimate analysts will never pressure you or ask you to disable security controls.

Need Immediate Help?

Talk to an Analyst Right Now