This feature is not available in Cyera for Government environments.
This guide walks you through installing and configuring the Cyera Endpoint Analyzer app in your CrowdStrike Falcon tenant.
For information about Endpoint Analyzer and the data it collects, see Endpoint Analyzer overview.
Prerequisites
Before you begin, make sure you have the deployment bundle and organization OTP provided by Cyera and the required CrowdStrike capabilities and permissions.
Cyera deployment bundle
Obtain the .zip deployment bundle from your Cyera contact. You will upload this bundle to Falcon Foundry when you import and install the app.
Organization OTP
Get your organization's Cyera agent OTP.
- Sign in to the Cyera console.
- Open Endpoints Management.
- Click Download Installer.
- In the dialog, copy the value of the OTP field with the copy button. It is a UUID.
The same OTP is used by every device in your organization. You do not need one per device.
Required CrowdStrike capabilities
The following Falcon capabilities must be enabled in your tenant:
- Real Time Response (RTR) - runs the initial script on endpoints.
- Falcon Foundry - hosts the Cyera app.
- Fusion SOAR - schedules and orchestrates the deployment workflow.
If you're unsure whether these capabilities are included in your current subscription, check with your CrowdStrike account team.
Roles
You need the following roles:
- Falcon Administrator: to import, deploy, release, and approve the app's scopes.
- Active Responder with Custom Scripts: to allow the initial script to run on endpoints.
Target host group
Create or select a host group containing the machines you want to scan. The workflow targets this group. To onboard a new host later, add it to the group, and the scanner runs on it during the next scheduled execution.
The workflow automatically detects each host's platform (Windows or macOS) and runs the appropriate scanner. Hosts on other platforms are skipped.
Information to provide to Cyera
Provide your CrowdStrike Customer ID (CID) to your Cyera contact. Cyera uses the CID to securely associate the deployment workflow with your tenant, ensuring that only requests from your Falcon environment can provision the scanner.
Where to find it: In the Falcon console, go to Host setup and management > Sensor downloads. Your CID is shown in step 2 (the hexadecimal string before the dash).
Step 1 - Enable Real Time Response on your target hosts
- Go to Host setup and management > Response policies.
- Select (or create) the policy that applies to the host group you prepared.
- Enable Real Time Response and Custom Scripts so the deployment workflow can execute the Cyera agent loader on each endpoint.
Step 2 - Import and install the app
- Go to Foundry > App builder > Import app.
- Upload the
.zipbundle your Cyera contact sent you. - Click Deploy.
- After the deployment succeeds, click Release.
- Go to App catalog > Custom apps, find Cyera Endpoint Protection, and click Install.
- Review and approve the requested permissions for RTR, devices, host groups, and workflows.
Step 3 - Configure and enable the workflow
- After installing the app, go to Content management > Custom apps > Cyera Endpoint Protection.
- Open the Cyera Agent Rollout workflow.
- Configure the following:
- Host group - select the host group you prepared.
- Schedule - choose the daily run time.
- Click Save to provision the workflow.
Verification
- Trigger the workflow manually from Fusion > Workflows.
- Go to Fusion > Executions and verify the following:
-
get_download_url- Completed. - Device Query - returns your target hosts.
- Per-host loop -
cyera-agent-loaderexits with a status ofsuccesson the target hosts.
-
- Confirm with your Cyera contact that deployment results are arriving.
What you get
Once findings start arriving, Cyera classifies them and provides:
- AI Asset Inventory - AI tools installed across your endpoint fleet, including configurations, installation paths, and versions.
- Shadow AI Discovery - AI tools in use that have not been sanctioned.
- Agent Activity Analysis & Alerts - Risk analysis and alerts for local agent activity.
Upgrade to a new version
- Go to Foundry > App Catalog, find the Cyera application, and click Uninstall.
- Go to Foundry > App Manager, find the Cyera application, and click Delete.
- Repeat steps 2 and 3 using the new deployment bundle.