Organization Risk Overview
- No devices at risk
Configure detection rules and whitelists for your tenant.
Global rules are built-in detections that apply to all tenants (read-only).
Custom rules are tenant-specific detections that you can edit or delete.
Deploy the ZeroExfil agent to Windows endpoints in your organization.
Windows MSI installer.
Requires Administrator privileges.
msiexec /i ZeroExfilInstaller.msi TENANT=<loading...> /qn
Deploy in three waves separated by one to two weeks. Use each wave to validate telemetry and refine whitelists before expanding coverage.
.msi downloaded aboveTENANT=<loading...> /qn
.msi to a network sharemsiexec /i "\\fileserver\deploy$\ZeroExfil\ZeroExfilInstaller.msi" TENANT=<loading...> /qn
gpupdate /force
Removing the agent stops the ZeroExfil service, unloads the ZeroExfilFilter minifilter driver, removes the driver package from the Windows driver store, and deletes the HKLM\SOFTWARE\zeroexfil registry key. All steps require Administrator privileges.
From an elevated PowerShell or CMD prompt:
msiexec /x ZeroExfilInstaller.msi /qn
If the original .msi is not available, uninstall by product code:
msiexec /x {7c4a8d09-3f9b-4b6c-a128-5e2d4f8b3a71} /qn
PowerShell remote uninstall by product name:
Get-CimInstance Win32_Product -Filter "Name='ZeroExfil'" | Invoke-CimMethod -MethodName Uninstall
A reboot is recommended after uninstall to fully unload the minifilter driver. To verify removal, run fltmc filters and confirm that ZeroExfilFilter is no longer listed.
| File | Hash | Device | Size | Quarantined | Status | Action |
|---|---|---|---|---|---|---|
Loading quarantined files... |
||||||
Manage your account, tenant, members, and security preferences.
Manage requests to join this tenant.