← Blue Lantern Security

Monitor Devices: Hourly Security Posture for Every Mac and Windows Machine

Blue Lantern Security's device agents are lightweight programs for macOS and Windows that check a machine's security posture about once an hour: disk encryption, endpoint protection, firewall, automatic updates, remote access, backups, and more. Only pass/fail results leave the device. Each report is scored Healthy, At Risk, or Critical in your Monitoring Hub, and the results feed the attestation report insurers ask for.

Set up device monitoring

Access: included with a Seat License at $15 per monitored user per month. Device monitoring is seat-only; each agent is assigned to a seated member. Download the macOS agent or Windows agent after signing in. See current pricing.

Cyber insurance applications and customer questionnaires ask the same things: is every disk encrypted, is endpoint protection running, are backups in place, is remote access closed? Device monitoring answers those questions with evidence from the machines themselves, updated every hour, instead of a checkbox someone filled in from memory.

What does the agent check?

The agent evaluates a baseline posture pack locally, using osquery, and reports the results. Checks come in two kinds: scored controls that pass or fail, and inventories reported for context that never affect the verdict.

macOS

Scored controls Reported for context
FileVault disk encryption enabled Time Machine backup destination configured and completed within 7 days
System Integrity Protection enabled macOS software updates pending
Gatekeeper app assessment enabled Device managed by MDM
Remote access and sharing services disabled (Screen Sharing, File Sharing, Remote Login, Remote Management, and others) Local administrator accounts
Automatic login and guest login disabled Third-party launch daemons and agents
Known EDR or antivirus agent running Remote-access and tunneling tools installed
Application firewall on, with stealth mode
Automatic update checks not disabled
No third-party root certificates in the system trust store
No unsigned or ad-hoc-signed launch daemons or agents
No third-party kernel extensions loaded

Windows

Scored controls Reported for context
BitLocker enabled on the system drive and all capable drives Startup items
UEFI Secure Boot enabled Local administrator accounts
Antivirus enabled with up-to-date signatures; known EDR or antivirus agent running Device managed by MDM
User Account Control enabled Consumer cloud file-sync clients installed
Remote Desktop disabled; SMBv1 not enabled Remote-access and tunneling tools installed
Automatic logon disabled Removable storage writes blocked by policy
Volume Shadow Copy service not disabled
Windows Firewall and automatic updates reported healthy by Security Center
No non-default SMB file shares exposed
No unsigned or untrusted startup items
Built-in Guest account disabled
Backup mechanism present (a known backup agent or OneDrive folder backup)
Local password policy requires length of at least 8 and complexity

How the verdict is decided: any high or critical failure marks the device Critical. Lower-severity failures mark it At Risk. All controls passing marks it Healthy. Each failed check comes with an explanation and the setting to change, so the fix is a click away rather than a research project. The full, current check list for each platform is on the macOS agent and Windows agent pages.

How do I deploy the agent?

  1. Create a Device Monitor key in the Monitoring Hub, with the seat assignment set to the person who uses the machine. The key is shown once.
  2. Download the agent. The macOS package is signed and notarized. The Windows installer is signed with an EV code-signing certificate, and a SHA-256 checksum is shown next to the download so you can verify it.
  3. Install and enroll. On macOS, run the enroll command in Terminal; on Windows, run the enroll script from an elevated PowerShell. Each prompts for the device key.
  4. Watch the reports come in. The agent scans about once an hour, and each run appears in the Monitoring Hub under the Device monitor type, with the hostname as the target and the full posture report a click away.

Pair device monitoring with an alert rule on Critical or At Risk verdicts to hear about posture drift, such as someone turning off the firewall or a backup that stopped running, without watching the dashboard.

Already running CrowdStrike Falcon?

Connect it read-only from Integrations. Falcon sensor health lands beside the rest of your security data: whether each sensor has checked in recently, and whether a prevention policy is applied so the sensor blocks threats rather than only observing. A health run per device appears in the Monitoring Hub after each daily scan.

What leaves the device?

  • Pass/fail results and inventory facts only. No file contents and no browsing data are collected.
  • The device key is scoped to posture scans. It cannot run other tools or read any account data. Revoke it and the agent stops.
  • The key is stored with restrictive permissions: root-only on macOS, and a SYSTEM/Administrators-only ACL on Windows. It is never logged.
  • Reports are evaluated server-side. The agent's own summary is never trusted for the verdict.

Common questions

Is this an antivirus or EDR?

No. The agent does not detect or block malware. It verifies that your protections are in place and configured, including that a known EDR or antivirus product is actually running. Think of it as the evidence layer for the controls you already pay for.

How often does it check?

About once an hour. The Monitoring Hub shows each device's latest report, and the attestation report summarizes devices reporting in the last 7 days.

Does it work with MDM?

Yes. MDM enrollment is reported as an inventory fact, and the agent runs alongside any management tool. It does not change settings on the machine; it reports them.

What about Linux?

The current agents are built for macOS and Windows. Linux is not covered today.

Why do insurers care about these checks?

Disk encryption, endpoint protection, backups, MFA, and closed remote access are the controls most cyber-insurance applications ask about directly. Blue Lantern Security's attestation report compiles device, identity, and mail posture results into a document you can hand to a broker. See how to get started with small business security for where these controls fit in a plan.

Set up device monitoring

Related guides

Sources and further reading