Uninstalling macOS xAgent software

Prev Next

This section describes how to uninstall the Endpoint Security (HX) xAgent software running on your macOS endpoints.

Important

If your organization uses JAMF or BigFix with the remove-helper option, uninstalling the agent will not remove the system extension.

Note

Uninstalling the agent with the remove-helper option, when your organization uses JAMF or BigFix activates a local permission prompt requiring the approval of a user with administrative rights.

To uninstall macOS xAgent software:
  1. Launch the Terminal and enter the following command to run the uninstall script.

    sudo /Library/FireEye/xagt/uninstall.tool

    Enter the administrator password when prompted.

  2. Enter the following command to verify that no xagt processes are running.

    ps aux | grep xagt

    Note

    If xagt processes are running on the endpoint, perform one of the following steps:

    • If all the agent artifacts still remain on the endpoint, run the uninstall script again.

    • If all the agent artifacts have been removed from the endpoint, manually terminate the xagt processes.

To uninstall the system extension:

  1. Log in to the terminal as an administrator.

  2. Run the uninstall script.

  3. Enter the following command:

    uninstall.tool--remove-helper

  4. Confirm that the system extension should be removed.

  5. Drag the system extension to the trash to complete the uninstallation of the agent.