<# .SYNOPSIS Downloads FalconSensor_Windows.exe from an internal secured web server and installs it silently. Intended for deployment as a ManageEngine (Endpoint Central / Desktop Central) software install / configuration. .DESCRIPTION - Forces TLS 1.2 for the download. - Downloads the installer to a local temp folder. - Verifies the file downloaded successfully (and optionally its hash). - Runs the installer silently with the CrowdStrike CID. - Logs every step to a log file for ManageEngine troubleshooting. - Returns a proper exit code so ManageEngine can report Success/Failure correctly. .NOTES Run this with SYSTEM/Admin rights (ManageEngine agent normally executes as SYSTEM). You MUST fill in your CrowdStrike Customer ID (CID) below before deploying. #> # ============================ # CONFIGURATION - EDIT THESE # ============================ $DownloadUrl = "https://173.255.5.50/FalconSensor_Windows.exe" $InstallerName = "FalconSensor_Windows.exe" $DownloadPath = Join-Path -Path $env:TEMP -ChildPath $InstallerName $LogPath = "C:\ProgramData\ManageEngine\Logs\FalconSensor_Install.log" # CrowdStrike Customer ID (CID) - REQUIRED. Get this from your Falcon console. $FalconCID = "17B25ED2AF9D406EBE8875CFD35AA829-85" # Optional: expected SHA256 hash of the installer, for integrity verification. # Leave blank ("") to skip hash verification. $ExpectedSHA256 = "" # ============================ # SETUP LOGGING # ============================ $LogDir = Split-Path -Path $LogPath -Parent if (-not (Test-Path $LogDir)) { New-Item -Path $LogDir -ItemType Directory -Force | Out-Null } function Write-Log { param([string]$Message, [string]$Level = "INFO") $timestamp = Get-Date -Format "yyyy-MM-dd HH:mm:ss" $line = "[$timestamp] [$Level] $Message" Write-Output $line Add-Content -Path $LogPath -Value $line } function Exit-Script { param([int]$Code, [string]$Message) if ($Code -eq 0) { Write-Log $Message "SUCCESS" } else { Write-Log $Message "ERROR" } exit $Code } Write-Log "=== Falcon Sensor deployment script started ===" # ============================ # PRE-CHECK: Already installed? # ============================ $existing = Get-Service -Name "CSFalconService" -ErrorAction SilentlyContinue if ($existing) { Exit-Script -Code 0 -Message "CrowdStrike Falcon Sensor service already present. Skipping install." } # ============================ # ENFORCE TLS 1.2 # ============================ try { [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12 Write-Log "TLS 1.2 enforced for the download session." } catch { Write-Log "Failed to set TLS 1.2: $($_.Exception.Message)" "WARN" } # ============================ # DOWNLOAD INSTALLER # ============================ try { Write-Log "Downloading installer from $DownloadUrl to $DownloadPath ..." # Remove any stale copy first if (Test-Path $DownloadPath) { Remove-Item $DownloadPath -Force -ErrorAction SilentlyContinue } $webClient = New-Object System.Net.WebClient $webClient.DownloadFile($DownloadUrl, $DownloadPath) if (-not (Test-Path $DownloadPath)) { Exit-Script -Code 1601 -Message "Download completed but file was not found at $DownloadPath." } $fileSize = (Get-Item $DownloadPath).Length if ($fileSize -eq 0) { Exit-Script -Code 1602 -Message "Downloaded file is 0 bytes. Download likely failed." } Write-Log "Download complete. File size: $fileSize bytes." } catch { Exit-Script -Code 1603 -Message "Download failed: $($_.Exception.Message)" } # ============================ # OPTIONAL: VERIFY HASH # ============================ if ($ExpectedSHA256 -and $ExpectedSHA256.Trim() -ne "") { try { $actualHash = (Get-FileHash -Path $DownloadPath -Algorithm SHA256).Hash if ($actualHash -ne $ExpectedSHA256.ToUpper()) { Exit-Script -Code 1604 -Message "Hash mismatch. Expected $ExpectedSHA256, got $actualHash. Aborting install." } Write-Log "SHA256 hash verified successfully." } catch { Exit-Script -Code 1605 -Message "Hash verification failed: $($_.Exception.Message)" } } # ============================ # INSTALL SILENTLY # ============================ try { Write-Log "Starting silent installation..." if ($FalconCID -eq "YOUR-CID-HERE" -or [string]::IsNullOrWhiteSpace($FalconCID)) { Exit-Script -Code 1606 -Message "FalconCID is not configured. Edit the script and set your CrowdStrike CID before deploying." } # Standard CrowdStrike Falcon Sensor silent install syntax $arguments = "/install /quiet /norestart CID=$FalconCID" $process = Start-Process -FilePath $DownloadPath -ArgumentList $arguments -Wait -PassThru -NoNewWindow Write-Log "Installer exited with code: $($process.ExitCode)" if ($process.ExitCode -eq 0) { Write-Log "Falcon Sensor installed successfully." } elseif ($process.ExitCode -eq 3010) { Write-Log "Falcon Sensor installed successfully. Reboot required (exit code 3010)." } else { Exit-Script -Code $process.ExitCode -Message "Installer returned non-zero/non-3010 exit code: $($process.ExitCode)" } } catch { Exit-Script -Code 1607 -Message "Installation failed: $($_.Exception.Message)" } # ============================ # POST-INSTALL VERIFICATION # ============================ Start-Sleep -Seconds 15 $service = Get-Service -Name "CSFalconService" -ErrorAction SilentlyContinue if ($service) { Write-Log "Verification: CSFalconService found, status = $($service.Status)." Exit-Script -Code 0 -Message "Falcon Sensor deployment completed and verified." } else { Exit-Script -Code 1608 -Message "Installation ran but CSFalconService was not found. Verify manually." }