> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux/cytool-for-linux.md).

# Cytool for Linux

Cytool is a command-line tool that is integrated into the Cortex XDR agent that enables you to query and manage both basic and advanced functions of the agent. For most commands, unless stated otherwise, changes that you make using Cytool are active until the agent receives the next heartbeat communication (every five minutes) from Cortex XDR.

The following table displays the Cytool options available on Linux endpoints. Where there is a password required for admin commands, this is the same password as was defined as the Uninstall Password.

{% hint style="info" %}

### Note

Since Cortex XDR agent 7.6, the `pmd` process includes and replaces the `trapsd` process.
{% endhint %}

| Command Option      | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| ------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `adaptive_policy`   | <p>Adaptive policy agent commands.</p><p>Usage: <code>cytool adaptive\_policy \[\<interval> \<collect\_stats> \<recalc> \<query>]</code></p><p>where:</p><ul><li><strong><code>interval</code></strong> —Sets a recalculation interval override (in seconds), or reset an override. Options are: <code>seconds</code>, <code>policy</code></li><li><strong><code>collect\_stats</code></strong> —Initiates a collection of internal statistics.</li><li><strong><code>recalc</code></strong> —Triggers a recalculation of the adaptive policy.</li><li><strong><code>query</code></strong> —Query the current interval and APEX.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| **`anti_malware`**  | <p>Perform Anti Malware related operations.</p><p>\[version \<query>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | cache \<print, status>]</p><p>Usage: <strong><code>cytool anti\_malware </code></strong><em><strong><code>\<version></code></strong></em> <em><strong><code>\<cache></code></strong></em></p><p>where:</p><ul><li>version — Input: <strong><code>query</code></strong></li><li>cache — Input: <strong><code>print</code></strong> <strong><code>status</code></strong></li><li>la, wf, and ltee are for internal use.</li></ul> |
| `cert_enforcement`  | <p>Perform Certificate enforcement related operations.</p><p>Usage: <code>cytool cert\_enforcement \<operation></code></p><p>Where \<operation> is one of the following:                                </p><ul><li>query                       Display current enforcement status</li><li>disable                     Forcibly disable enforcement</li><li>policy                      Set enforcement by policy</li><li>import \<certificate file path>     Import a proprietary certificate in PEM format as root CA</li><li>import clear                       Clear all custom root CA certificates.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| `checkin`           | <p>Initiate check-in to the server.</p><p>Usage: <strong><code>cytool checkin</code></strong></p><p>To verify the check in, view the check-in time on the Cortex XDR agent console.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| `connectivity_test` | <p>Perform a connectivity test to Cortex XDR servers.</p><p>Usage: <code>cytool connectivity\_test \[request\_count]</code></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| `dump`              | <p>Enable/disable dump generation or restore policy settings.</p><p>Usage:</p><ul><li><code>cytool dump enable</code></li><li><code>cytool dump disable</code></li><li><code>cytool dump restore</code></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| `endpoint_tags`     | <p>Usage: <strong><code>cytool endpoint\_tags </code></strong><em><strong><code>\<action></code></strong></em></p><p>where \<action> can be:</p><ul><li>add—To add tags to the endpoint tags.</li><li>remove—Remove the given tags from the list of endpoint tags.</li><li>list—Displays the available endpoint tags.</li></ul><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Tags should be passed as one string separated by comas.</p><p>Linux does not support tag names with spaces as command line arguments to the shell installer.</p><p>Instead, tags can be set in the <code>/etc/panw/cortex.conf</code> configuration file, that supports all Linux installers.</p></div><p>For example:</p><ul><li><code>cytool endpoint\_tags add "tag1\[,tag2,...,tagN]"</code></li><li><code>cytool endpoint\_tags remove "tag1\[,tag2,...,tagN]"</code></li><li><code>cytool endpoint\_tags list</code></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| `enum`              | <p>Enumerate protected processes.</p><p>Usage: <strong><code>cytool enum</code></strong></p><p>For example:</p><p><code>root\@ubuntu: cytool enum ----------------------------------- Cortex XDR list of protected processes: ----------------------------------- PID CMD UID 1098 /usr/sbin/cron -f 0 1131 /usr/sbin/rsyslogd -n 104</code></p><p>To view processes for all users including those initiated by the operating system, specify the <code>/a</code> option.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>If you change the action mode for protected processes in the Exploit Security Profile in Cortex XDR, you must restart the protected processes for the security policy to be enforced on the processes and its forked processes; only then you will see them on this list.</p></div>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| `event_collection`  | <p>Stop or start event collection status (EDR/DSE).</p><p>\<query, enable, disable, logstat></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| `health`            | Shows the agent status, protection level and connectivity.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| `-h --help`         | Displays the available help information                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| `import suex`       | Import pre-downloaded content or local support exceptions. Used for solving specific problems with a support representative.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| `isolate stop`      | Release machine from network isolation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| `last_checkin`      | Display last successful check-in time.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| `log`               | <p>Set the log level for the desired process.</p><p>Usage: <strong><code>cytool log set\_level \<log\_level> \<components></code></strong></p><p>where:</p><ul><li><p><code>\<log\_level></code> is an integer value corresponding to the log level:</p><ul><li>0—Disable logging</li><li>1—Fatal</li><li>2—Critical</li><li>3—Error</li><li>4—Warning</li><li>5—Notice</li><li>6—Information</li><li>7—Debug</li><li>8—Trace</li></ul></li><li><code>\<components></code> is <strong><code>all</code></strong> or one or more of the following agent components: <strong><code>authorized</code></strong>, <strong><code>pmd</code></strong>, <strong><code>cortex xdr</code></strong>, <strong><code>kproc-ctrl</code></strong>.</li></ul><p>For example:</p><p><strong><code>cytool log set\_level 2 all</code></strong></p><p>Then use the <strong><code>cytool log collect</code></strong> command to generate a support file.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| `log collect`       | Generate support file archive of all logs in a TGZ file.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| `persist`           | <p>The Cortex XDR agent stores policy and security event information such as the list of trusted signers, local verdicts, and one-time actions in local databases on the endpoint. To troubleshoot policy issues and security events. Use cytool persist operations to import, export, and view information stored in the local database.</p><p>Usage: <strong><code>cytool persist \<action></code></strong></p><p>where \<action>:</p><ul><li><strong><code>list</code></strong>—List the local databases on the endpoint.</li><li>\*\*\`export \[</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| `queryall`          | The cytool queryall command displays a list of imported certificates, for troubleshooting purposes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| `reconnect`         | <p>Try reconnecting if communication with server has been disabled, or force registration with a new Distribution ID.</p><p>Usage:</p><p><code>cytool reconnect \[force \<distribution\_id]></code></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| `runtime`           | <p>Stop or start product components.</p><p>Usage: <code>cytool runtime \<action> \<component></code></p><p>where:</p><ul><li><p><strong><code>\<action></code></strong>—Change startup runtime action for an agent component.</p><p>Options are: <strong><code>start</code></strong>, <strong><code>stop</code></strong>, <strong><code>query</code></strong>. The query option displays the startup status for each component.</p></li><li><p><strong><code>\<component></code></strong>—Target components for which to set the runtime action, or <code>all</code> components.</p><p>To change the runtime action for multiple components, list them with spaces separating each component.</p><p>Options: <strong><code>cortex xdr</code></strong>, <strong><code>authorized</code></strong>, <strong><code>pmd</code></strong>, <strong><code>kproc-ctrl</code></strong></p></li></ul><p>For example:</p><p><code>cytool runtime query Name PID User Status Command cortex xdr 1055 User1 Running /Library/Application Support/PaloAltoNetworks/Traps/bin/cortex xdr.app/Contents/MacOS/cortex xdr authorized 927 \_traps\_panw Running /Library/Application Support/PaloAltoNetworks/Traps/bin/authorized pmd 909 root Running /Library/Application Support/PaloAltoNetworks/Traps/bin/pmd kproc-ctrl 159 root Loaded com.paloaltonetworks.driver.kproc-ctrl cytool runtime stop all Name PID User Status Command authorized N/A N/A STOPPED N/A pmd N/A N/A STOPPED N/A cortex xdr N/A N/A STOPPED N/A kproc-ctrl N/A N/A Unloaded N/A cytool runtime start all Name PID User Status Command system call failed for command='/usr/bin/su -l Traps -c "/bin/launchctl start cortex xdr.plist"', returned status code=768 authorized 1883 \_traps\_panw Running /Library/Application Support/PaloAltoNetworks/Traps/bin/authorized pmd 1889 root Running /Library/Application Support/PaloAltoNetworks/Traps/bin/pmd cortex xdr N/A N/A FAILED TO START N/A kproc-ctrl 160 root Loaded com.paloaltonetworks.driver.kproc-ctrl</code></p> |                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| `scan`              | <p>Perform Scan operations on the endpoint.</p><p>Options: <code>start</code>, <code>stop</code>, <code>query</code></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| `startup`           | <p>Enable, disable, or query the startup state of Cortex XDR agent components.</p><p>Usage: <strong><code>cytool startup </code></strong><em><strong><code>\<action></code></strong></em> <em><strong><code>\<component></code></strong></em></p><p>where:</p><ul><li><p><strong><code>\<action></code></strong>—Change startup action for an agent component.</p><p>Options are: <strong><code>enable</code></strong>, <strong><code>disable</code></strong>, <strong><code>query</code></strong>.</p><p>The query option displays the startup status for each component.</p></li><li><strong><code>\<component></code></strong>—Target component for which to set the startup action. To change the startup action for multiple components, list them with spaces separating each component. Options are: <strong><code>cortex xdr</code></strong>, <strong><code>authorized</code></strong>, <strong><code>pmd</code></strong>, <strong><code>kproc-ctrl</code></strong></li></ul><p>For example:</p><p><code>root\@ubuntu: sudo ./cytool startup disable cortex xdr pmd Process name Startup status cortex xdr Disabled authorized Enabled pmd Disabled kproc-ctrl Loaded root\@ubuntu: sudo ./cytool startup enable all Process name Startup status cortex xdr Enabled authorized Enabled pmd Enabled kproc-ctrl Loaded</code></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |                                                                                                                                                                                                                                                                                                                                                                                                                                 |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent/8.6-eol/cortex-xdr-agent-for-linux/troubleshooting-resources-for-linux/cytool-for-linux.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
