Download
Install DefenseClaw on macOS, Linux or Windows with one command, or get the enterprise packages for a fleet of machines.
DefenseClaw installs for your own account with one command, and you don't need
administrator rights. The installer downloads the latest release, checks every
file against the release's checksums.txt and installs uv if you don't have
it. uv provides the Python runtime, so you don't need anything else.
Install for your OS
Pick your system. The site detects it and remembers your choice.
Requires a Mac with Apple silicon (arm64). Intel Macs are unsupported,
and the installer stops before it changes anything.
curl -LsSf https://github.com/ cisco-ai-defense/ defenseclaw/ releases/ latest/ download/ install.sh | bashTo install, guard one agent and run first-time setup in a single step:
curl -LsSf https://github.com/ cisco-ai-defense/ defenseclaw/ releases/ latest/ download/ install.sh | bash -s -- --connector claudecode --quickstartMenu-bar app (preview, optional). Download DefenseClawMac-<version>-macos-arm64.dmg
from the latest release;
it needs macOS 14 or newer.
After that, the installer and defenseclaw upgrade keep an installed app up to
date, but they don't install it for you. See macOS app.
Requires Linux on x86_64 or arm64.
curl -LsSf https://github.com/ cisco-ai-defense/ defenseclaw/ releases/ latest/ download/ install.sh | bashTo install, guard one agent and run first-time setup in a single step:
curl -LsSf https://github.com/ cisco-ai-defense/ defenseclaw/ releases/ latest/ download/ install.sh | bash -s -- --connector claudecode --quickstartIf the installer says ~/.local/bin isn't on your PATH, run the line it
prints, then open a new shell.
Requires Windows on x64, with Windows PowerShell 5.1 or PowerShell 7.
Windows on ARM64 isn't certified, even with x64 emulation, so the installer
stops there. Run it as the user who uses DefenseClaw, not as an administrator.
irm https://github.com/ cisco-ai-defense/ defenseclaw/ releases/ latest/ download/ install.ps1 | iexTo install, guard one agent and run first-time setup in a single step:
& ([scriptblock]::Create((irm https://github.com/ cisco-ai-defense/ defenseclaw/ releases/ latest/ download/ install.ps1))) -Connector claudecode -QuickstartThe installer adds %USERPROFILE%\.local\bin to your user PATH. If it tells
you to open a new terminal, do that before you run defenseclaw. The
native Windows guide covers the Windows lanes and
troubleshooting.
If you used the plain install command, run defenseclaw init next. The
install-and-setup command has already done that step. The
5-minute quickstart takes you from there to
your first blocked tool call.
Which agents work on my OS?
The support matrix shows each agent on macOS, Linux and Windows, and what was verified for this release.
On a computer your organization manages
Where an administrator has deployed DefenseClaw enterprise, the per-user
installer and defenseclaw upgrade refuse to run: the organization installs
and updates DefenseClaw through its MDM.
Managing many machines?
The standalone enterprise packages install DefenseClaw as operating-system
services that belong to the administrator, so users can't turn the protection
off. Your MDM or configuration management delivers them. (Cisco Secure Client
customers use the Secure Client profile
instead.) Every file is on the
latest release
page. <version> is the release number without the v.
The release files for each platform:
# Windows x64: the Setup program and its payload manifest
DefenseClawSetup-Enterprise-Standalone-x64.exe
DefenseClawSetup-Enterprise-Standalone-x64.payload-manifest.json
# macOS (Apple silicon)
defenseclaw-enterprise-<version>-darwin-arm64.pkg
defenseclaw-enterprise-<version>-darwin-arm64.tar.gz
# Linux: RPM, DEB (preview) or archive, for amd64 or arm64
defenseclaw-enterprise-<version>-linux-amd64.rpm
defenseclaw-enterprise-<version>-linux-arm64.rpm
defenseclaw-enterprise-<version>-linux-amd64.deb
defenseclaw-enterprise-<version>-linux-arm64.deb
defenseclaw-enterprise-<version>-linux-amd64.tar.gz
defenseclaw-enterprise-<version>-linux-arm64.tar.gzStart with Deploy to a fleet. It walks through picking a profile, your agents and your MDM.
Verify the download
The one-line installers check every file they download against the release's
checksums.txt. If cosign 2.0 or later is installed, they also verify the
Sigstore signature on checksums.txt. Either check failing stops the install
before it changes anything.
For a file you download yourself, such as the .dmg or an enterprise package,
download checksums.txt and checksums.txt.bundle from the same release.
Then, in the download folder, verify the signature and the file's hash:
FILE=name-of-the-downloaded-file
REPO=https://github.com/cisco-ai-defense/defenseclaw
cosign verify-blob --bundle checksums.txt.bundle \
--certificate-identity "$REPO/.github/workflows/release.yaml@refs/heads/main" \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
checksums.txt
grep " $FILE\$" checksums.txt | sha256sum -c -On macOS, use shasum -a 256 -c - in place of sha256sum -c -.
On Windows, compare the file's hash with its line in checksums.txt:
$File = 'DefenseClawSetup-Enterprise-Standalone-x64.exe'
(Get-FileHash ".\$File" -Algorithm SHA256).Hash.ToLower()
Select-String -Path .\checksums.txt -Pattern (' ' + [regex]::Escape($File) + '$')Upgrade, roll back or uninstall
defenseclaw upgrade # install the latest release; config and data are kept
defenseclaw upgrade --version X.Y.Z # install a specific release
defenseclaw rollback # restore the install the last upgrade replaced
defenseclaw uninstall # remove connector hooks; keep ~/.defenseclaw and the binariesRunning the one-line installer again also upgrades or repairs an install and keeps your configuration. Upgrade explains what an upgrade does, and Install → Uninstall lists every uninstall option, including how to remove everything.