Client Tools
Device Agent
A small tool you run during your case call — it pulls a basic inventory of your device (installed applications and core system info) and files it directly to your case. Nothing is installed permanently; nothing is left behind. Pick your platform below.
⚠ Current clients only — you must be an active Swift Investigations / Swift Cybersecurity client with a valid case number to use this tool.
Need more detail, or something on screen doesn't match? See the extended installation walkthrough in the Knowledge Base.
[*] HOW TO RUN IT
- Download the file above. It'll land in your
Downloadsfolder asSwiftDeviceAgent.zip. Right-click it and choose Extract All (or double-click it — Windows can open a zip like a folder) to get two files,SwiftDeviceAgent.batandSwiftDeviceAgent.ps1— keep them together in the same folder. - Double-click
SwiftDeviceAgent.bat. That's the whole step — no right-click menu to find, no "Run with PowerShell" to pick. - Windows will likely show a security prompt first, since this is a freshly downloaded file — either a blue "Windows protected your PC" screen (click More info, then Run anyway) or a smaller Open File - Security Warning box (click Run). Either one is standard for any new download from outside the Microsoft Store, not a sign anything is wrong.
- To skip that prompt next time, right-click
SwiftDeviceAgent.batbefore running it, choose Properties, check the box labeled Unblock near the bottom of the General tab, then click OK. - A console window opens and prepares the tool for a second, then asks for your case number — type it in exactly as your investigator gave it to you (e.g.
117331-KG44T). If it's not found, just try again — it won't lock you out, so stay on the line with your investigator until it goes through. - Confirm your name and case shown on screen are correct, then press Enter to begin the scan.
- Wait a few seconds — you'll see
[+] Report filed successfullywhen it's done. Press Enter (or just close the window) to finish. - On a locked-down work/managed computer only: if you instead see an error mentioning "execution policy," open PowerShell as Administrator, run
Set-ExecutionPolicy -Scope Process Bypass, then double-clickSwiftDeviceAgent.batagain.
Note: the security prompt above is expected for any small internal tool like this one that isn't distributed through the Microsoft Store — the steps above are the normal, safe way past it.
Need more detail, or something on screen doesn't match? See the extended installation walkthrough in the Knowledge Base.
[*] HOW TO RUN IT
- Download the file above. It'll land in your
Downloadsfolder asSwiftDeviceAgent.zip. Some browsers unzip it automatically; if it's still a.zip, double-click it in Finder/Downloads to extractSwiftDeviceAgent.commandfrom it. - Double-click
SwiftDeviceAgent.command. macOS opens Terminal automatically and runs it — no separate app needed. - If macOS blocks it with a message like "Apple could not verify 'SwiftDeviceAgent.command' is free of malware that may harm your Mac or compromise your privacy" — this is standard Gatekeeper behavior for any script that isn't from a paid Apple Developer account, not a sign anything is actually wrong. Fastest fix: open Terminal (press Cmd+Space, type
Terminal, press Enter) and run:xattr -d com.apple.quarantine ~/Downloads/SwiftDeviceAgent.command
then double-click the file again — it will now open normally. - Prefer not to use Terminal? Go to System Settings → Privacy & Security, scroll down to the Security section, and you'll see a message that the file was blocked with an Open Anyway button. Click it, confirm with your password/Touch ID, then double-click the file again.
- When prompted, type in your case number exactly as your investigator gave it to you (e.g.
117331-KG44T) and press Enter. - Confirm your name and case shown on screen are correct, then press Enter to begin the scan.
- Wait a few seconds — you'll see
[+] REPORT FILEDwhen it's done. That's it, you can close the Terminal window.
Note: this Gatekeeper warning is expected for any small internal tool like this one that isn't distributed through the Mac App Store — the steps above are the normal, safe way past it. It can appear on the extracted
.command file too, since macOS carries the download flag through the zip when it's extracted.Need more detail, or something on screen doesn't match your phone? See the extended installation walkthrough in the Knowledge Base.
[*] HOW TO INSTALL AND RUN IT
- Tap the download button above on your phone. It'll land in your Downloads or Files app/notification shade.
- Tap the downloaded
SwiftDeviceAgent.apkfile to open it. - Android will warn that installing apps from this source is blocked. Tap Settings on that prompt, then turn on Allow from this source, then go back to the install screen.
This is standard Android behavior for any app not installed through the Play Store — it does not mean anything is wrong.
- Tap Install. If Google Play Protect pops up saying it "doesn't recognize this app" and offers to scan it, tap Scan — it will come back clean — then tap Install anyway.
- Once installed, open the Swift Device Agent app from your app drawer.
- The app will ask for your case number — type it in exactly as your investigator gave it and tap Verify Case.
- Confirm your name and case shown on screen are correct, then tap Begin Device Scan.
- Wait a few seconds — you'll see Report Filed when it's done. You can then close/uninstall the app.