Documentation Troubleshooting Security software exclusions
TROUBLESHOOTING

Security software exclusions

Security software can mistake the Overseer agent for a threat and block it. This page explains why that happens, how to recognise it, and the kinds of exclusion that let the agent work.

Why security software and the agent collide

The Overseer agent is the lightweight service Overseer installs on each computer. To do its work it behaves in ways that security software is built to distrust:

  • it runs as a Windows service with system rights;
  • it keeps a long-lived outbound connection to your Overseer instance;
  • it receives PowerShell over that connection and runs it;
  • it downloads installers and runs them without anyone at the keyboard.

Security software judges programs by what they do. Unless you tell it that the agent is expected, it may block the agent outright, block it some of the time, or cut its connection.

Signs that security software is in the way

  • A computer has the agent installed but stays waiting to be identified.
  • A computer shows as offline although it is switched on and connected.
  • Actions fail as a script starts, on some computers and not on others, or on some days and not on others.
  • Sessions stop working straight after the agent is updated, because the new files are unfamiliar to the security software.
  • The agent's own log on the computer shows a connection that closes as soon as it opens, or a script that starts and then goes quiet.

A quick test is to pause the security software on one affected computer and press Deployment detection. Detection is read-only. If it now completes, add exclusions and switch the protection back on.

What to exclude

Add the narrowest exclusion your security software supports, in this order of preference.

  • By publisher. Where the security software can trust programs by the publisher that signed them, trust the publisher of the Overseer agent. This covers later agent versions without further changes.
  • Folders. Exclude the Overseer agent's install folder and the folder the agent runs scripts from.
  • Processes. Exclude the agent's processes, including any helper process the agent starts to run scripts.
  • Script activity. Allow PowerShell that the agent's processes start. If a strict script-scanning mode blocks scripts now and then, exempt the agent's script folder from that mode.

Some security software needs the folder and the process exclusions together. With only the folder excluded, a newly installed or newly updated agent can be unable to fetch what it needs to run scripts, and the computer stalls at identification or at the start of a session.

Check after agent updates. Security software that scores behaviour can flag a new agent version it has not seen before. Mark the detection as a false positive in your security console.

Network filtering and inspection

The agent has to reach the address of your Overseer instance and hold the connection open.

  • Inspection of encrypted traffic. A firewall or security agent that opens encrypted traffic breaks the agent's long-lived connection. Exempt the address of your Overseer instance from inspection. The agent detects inspection and reports it to Overseer, so you can see which computers are affected.
  • Inspection certificates. Where a site inspects traffic as a rule, deploy the site's inspection certificate with a task so that Windows trusts it. Place that deployment first in deployment ordering, so later items can download.
  • DNS filtering. A DNS filter can fail to resolve an address without listing it as blocked. The effect is the same: the agent cannot connect. Add the address of your Overseer instance to the filter's allow list.
  • Firewalls. Allow outbound connections from the computer to the address of your Overseer instance.

PowerShell policy

Tasks and scripts in Overseer are PowerShell, so a rule that forbids PowerShell scripts stops every one of them. If your directory sets the PowerShell execution policy, script execution must be allowed for both the computer and the user. A policy of RemoteSigned lets Overseer's scripts run.

To see the policy in effect on a computer, run:

Get-ExecutionPolicy -List

Confirming the exclusions work

  1. 1Apply the exclusions to one affected computer, or to a small group.
  2. 2Open the computer and press Deployment detection.
  3. 3Open the session and confirm that its actions report results.
  4. 4Press Re-run on a session that failed earlier and confirm that it completes.
  5. 5Apply the exclusions to the rest of the client's computers.

Next steps

Common issuesThe problems people meet most often, grouped by area, and what to check. Troubleshooting guideWhere to look first when something goes wrong, and how to narrow it down. Installing the agentFour ways to put the Overseer agent on a Windows computer.
Was this article helpful?
← Common issues Troubleshooting guide →

In development. Launch inquiries welcome.

This documentation describes Overseer as it is being built. If you would like to hear when it launches, get in touch.

Ask about launch