Home Troubleshooting & FAQs

Troubleshooting & FAQs

Solutions to common problems, error messages, and technical issues with the StrongKeep platform.
Sir Stonk
By Sir Stonk
4 articles

An application has been blocked or quarantined

Applies to: Endpoint protection (Cortex XDR anti-malware) What you're seeing A programme on your computer won't open, has been closed mid-use, or shows a notification saying it has been blocked or quarantined. This may happen immediately after installing new software, or unexpectedly to software you've been using for a while. You might see: - A Cortex XDR popup notification saying a file or process was blocked - The programme closes by itself, or simply does not run - A file disappears from your Downloads or Applications folder - A new incident appearing in your StrongKeep dashboard If you weren't trying to run anything when the alert appeared, don't panic: a block means the protection did its job. The application was stopped before it could cause harm. The steps below help you work out what happened and what (if anything) to do next. Step 1: Confirm it was StrongKeep that blocked it On your own device (any staff member): Click the Cortex XDR shield icon in your menu bar (Mac) or system tray near the clock (Windows) and choose Open Console. The console shows: - Protection status (it should say PROTECTED) - A table of recent security events: the Time it happened, the Process (which programme was involved), the Module (which protection layer reacted), and the Mode (what action was taken, for example Terminate) If the programme you're having trouble with appears in that table, StrongKeep's protection blocked it. If the table is empty, the problem is probably something else (the programme may be crashing on its own, or blocked by a different tool). In the StrongKeep dashboard (your StrongKeep administrator): Go to Protection > Anti-malware to see all incidents across your organisation's devices. Each incident has a plain-English title (for example, "Suspicious malware detected and blocked on John's MacBook Pro, involving Terminal and login processes"), a severity rating (High, Medium, or Low), and the affected device. Click into the incident to see an Initial Assessment: an AI-generated explanation in plain English of what was detected, what action was taken, and what to check next. The File Artefacts and Timeline tabs show exactly which files and processes were involved. If you do not see the file in the Cortex XDR Console or on StrongKeep Dashboard: The file is not being blocked by StrongKeep. It may be some other reason that is preventing the tool from being run. Step 2: Quick self-check 1. Was this software installed recently? Freshly downloaded programmes are more likely to be flagged, especially if the download came from an unfamiliar site rather than the official vendor page. 2. Did someone else install it, or did it appear without your action? If you didn't install it and don't recognise it, the block may well be correct. Proceed with caution. 3. What does the incident say? The Initial Assessment on the incident page explains what triggered the alert. A High severity incident involving system processes deserves more caution than a Low severity flag on a file you just downloaded from a vendor you trust. 4. Is this a critical business tool? If it's software your work depends on (a practice management system, a device driver, a clinical imaging tool), you can request a review and an exception. See below. What you can do right now If the software is legitimate and you need it for work: 1. Ask your StrongKeep administrator to open the incident in the dashboard (Protection > Anti-malware, then click the incident). 2. Click Create Support Ticket on the incident page. This sends the incident details straight to the StrongKeep team with the full context attached. 3. Alternatively, email support@strongkeep.com with: the name and version of the software, where you downloaded it from (the website URL), what you use it for, and the incident ID from the dashboard if you have it. The StrongKeep team will review the file. If it's confirmed safe, they add an allow-rule scoped to your organisation so the software can run, and restore any quarantined file to its original location. Legitimate software does occasionally get flagged, particularly less common or recently released programmes; this is called a false positive and is normal for behaviour-based protection. [VERIFY: Clement: confirm typical turnaround for EDR exception requests] If you don't recognise the blocked programme, or the incident is High severity: Leave it alone and tell your StrongKeep administrator. If you suspect something is actively wrong (multiple alerts, files changing, unfamiliar activity), use the red Activate Help button under "Suspect an attack?" in the StrongKeep dashboard, or contact support immediately. In all cases, do not try to disable or bypass the protection yourself. The agent is designed to resist removal and tampering, because disabling endpoint protection is one of the first things an attacker attempts. If you believe the block is an error, the right path is the support ticket, not a workaround. What StrongKeep is doing and why StrongKeep's endpoint protection (built on Palo Alto Networks Cortex XDR, the same technology used by large enterprises and governments) checks software in two main ways: - Before a file runs, it is checked against Palo Alto Networks' global threat intelligence and an on-device analysis engine. Known-bad and suspicious files are blocked or quarantined before they execute. - While programmes run, Behavioural Threat Protection watches for harmful patterns of behaviour (for example, a process trying to encrypt many files, or tamper with login mechanisms) and terminates the process if it crosses the line. This catches threats that have never been seen before and would slip past traditional antivirus. The trade-off is that occasionally a legitimate programme behaves in a way that resembles those harmful patterns and gets stopped. These false positives can be resolved quickly with an allow-rule, and the file can be restored. StrongKeep operates with a protective default: block first, verify second. This is intentional for the threat environment that clinics and SMEs face, where a single ransomware incident is far more disruptive than a short wait for an exception. When to contact support Contact support@strongkeep.com (or use Create Support Ticket on the incident page) if: - A business-critical application has been blocked and you need it restored urgently - You're seeing repeated blocks of the same programme across several devices, for example after a system update - You're unsure whether a quarantined file was something you knowingly installed - An incident is marked High severity and the Initial Assessment doesn't match anything you or your team did If you suspect an active attack, use the Activate Help button in the dashboard sidebar.

Last updated on Jun 16, 2026

A website is being blocked

Applies to: Web Firewall (DNS filtering, powered by Control D) What you're seeing You try to visit a website and it won't load. Because the Web Firewall works at the network level, a blocked site usually does NOT show an obvious "blocked by StrongKeep" message. Instead you'll see a generic browser error such as: - "This site can't be reached" or "Safari can't find the server" - DNS_PROBE_FINISHED_NXDOMAIN or ERR_CONNECTION_REFUSED - A page that half-loads: the main site works but a button, form, or embedded content does nothing (this happens when a site pulls content from a second web address that is blocked, while the main address is not) Other sites load fine, and the problem follows your device across different Wi-Fi networks. Step 1: Confirm it was StrongKeep that blocked it Your StrongKeep administrator can check in under a minute: 1. In the StrongKeep dashboard, go to Protection > Web Firewall. 2. The Activities tab shows everything blocked in the last 30 days, grouped into categories: Malware Sites, Scam / Phishing Sites, and Newly Registered Sites, each with a count of blocked attempts and the devices affected. 3. Click into a category to see the exact web addresses blocked and which devices tried to reach them. You can also Download Report for a full list. If the address you're trying to reach appears in one of those lists, the Web Firewall blocked it. If it doesn't appear anywhere, the problem is likely something else: the site itself may be down, or the block may be coming from the anti-malware protection instead (see our article on blocked applications). Step 2: Quick self-check 1. Is your device protected by our web firewall? Open the Control D Utility App and check that it is on. 1. You can temporarily disable it if you wish to test whether it is the Control D web firewall that is blocking your access to the site. If the site still doesn't work after disabling the web firewall, then StrongKeep's protections are not the reason why the site is unavailable. 2. One device or all devices? If only one device is affected, check that device's status on the Web Firewall page (it should show Active). If all staff are blocked from the same site, it's a category block, which is normal behaviour rather than a fault. 3. Other non-protected devices? If the site works fine on other devices that do not have the web firewall protection (e.g., your personal mobile phone or tablet) on the same WIFI network, 4. Which category caught it? This matters: - Newly Registered Sites is the most common source of false alarms. Brand-new websites are blocked by default because many attacks start on domains registered just hours earlier. A legitimate new supplier, clinic system, or SaaS tool can get caught simply for being new. - Malware Sites and Scam / Phishing Sites blocks are usually correct. Treat these with more caution. 5. Is it the whole site or one piece of it? If a page loads but something on it doesn't work, look in the category lists for related addresses (for example cdn.example.com or api.example.com rather than example.com itself). What you can do right now On your own device (any staff member): 1. Open the Control D Utility App and click "Disable". 2. Test whether the site can be visited. 1. If so, then it was being blocked by StrongKeep. Enable the Control D Utility App again and inform your StrongKeep system administrator to file a "bypass" request for this domain (example.com) if you are certain that it is non-malicious. 2. If you are unable to visit the site even with Control D disabled, then the site is unavailable for other reasons (e.g., site is down, VPN, hardware firewall) In the StrongKeep dashboard (your StrongKeep administrator): 1. Open the category page under Protection > Web Firewall and find the blocked address. 2. Click Add Bypass Rule to allow it for your organisation. 3. Allow a little time for the change to reach your devices, then reload the page. If it still doesn't load, restart the browser, or wait a few minutes and try again. Only bypass sites you recognise. If the address was blocked under Malware or Scam / Phishing, or you're not sure what it is, don't bypass it yourself: ask StrongKeep support to review it first. A site that looks like your bank or a supplier but is brand new could be exactly what the filter is designed to stop. If you're a staff member: Send your StrongKeep administrator the full web address that's failing (copy it from the browser address bar) and a one-line reason you need it. They can either add the bypass themselves or pass it to StrongKeep support. If you'd rather have StrongKeep review it: Email support@strongkeep.com with the subject "Web Firewall exception request: [your company name]", the full address, and the reason it's needed. The team will check the site's reputation before unblocking. What StrongKeep is doing and why The Web Firewall checks every web address your devices try to reach, before any connection is made, and blocks three categories by default: - Malware sites: addresses known to spread viruses or malicious software. A single visit can infect a device without any download or click. - Scam and phishing sites: pages built to trick people into giving away passwords, payment details, or patient and customer information. Phishing remains one of the most common ways attackers get into organisations. - Newly registered sites: brand-new web addresses. Attackers register fresh domains precisely because no reputation system has flagged them yet, so StrongKeep applies extra caution to anything very new. Because this happens at the network level, it protects every browser and app on the device, but it also means a blocked site fails with a plain connection error rather than a branded warning page. The dashboard exists to make those quiet blocks visible. Most established business tools (Microsoft 365, Google Workspace, mainstream SaaS) are unaffected. The trade-off is that genuinely new, legitimate sites occasionally need a bypass rule, which takes a minute to add. When to contact support Email support@strongkeep.com (or WhatsApp for existing customers) if: - You added a bypass rule and the site still won't load after waiting and restarting the browser - The blocked address sits under Malware or Scam / Phishing and you believe it's wrongly categorised - The block is affecting a clinical system or patient-care workflow and you need urgent resolution - A device shows Not configured or its status has been stuck on "Last seen" for days (the firewall may not be protecting it at all) - You're seeing unexpected blocks across your entire organisation at once If you suspect an active attack rather than a blocked site, use the red Activate Help button in the dashboard sidebar.

Last updated on Jun 11, 2026

My computer is slow since StrongKeep was installed

Applies to: Endpoint protection (Cortex XDR) | Windows and macOS What you're seeing Your computer feels slower than before StrongKeep was installed. This might show up as: - Programmes taking longer to open - The system fan running more than usual, especially in the morning or after logging in - Common applications running sluggishly - The machine feeling unresponsive for the first few minutes after start-up Quick self-check Before concluding the cause is StrongKeep, it helps to rule out a few other factors: 1. When was StrongKeep installed? If your device was only recently onboarded, then the anti-malware solution (Cortex XDR) is likely still doing an initial calibration scan which might take a few days. Once that is done, you should find that performance returns to normal. 2. When does the slowness happen? If it's worst in the first 10 minutes after log-in and then improves, that's consistent with a scan running at start-up, which is expected and temporary. If it's constant throughout the day, something else may be contributing. 3. Has anything else changed recently? A Windows or macOS update, a new application, or a change in how many browser tabs you keep open can all affect performance independently of StrongKeep. 4. Is it one device or several? If three or more staff report the same thing after a StrongKeep install, that's worth escalating. If it's one machine, the cause is more likely to be specific to that device. 5. Is Cortex operating very heavily on your device? Use the Task Manager application (Windows) or Activity Monitor (Mac) to check the CPU / Memory usage from Cortex-XDR. If it is no different from other apps, then it is unlikely to be the cause of any slowdown. What you can do right now Report it to your StrongKeep administrator or support team. A support engineer can check the scan schedule and, where appropriate, adjust it to run at times when the machine is less likely to be in active use. Email support@strongkeep.com with: - Your device type (e.g. Windows laptop, Mac) - When the slowness happens (morning only, all day, after specific actions) - Any specific applications that feel particularly affected Do not disable or uninstall the agent to test whether it improves performance. This leaves your device unprotected. The right path is to have support investigate and tune the settings. What StrongKeep is doing and why The endpoint agent monitors processes and files in real time, which does use CPU and memory. StrongKeep's policies are calibrated for the typical devices used in clinics and small businesses, and should not cause noticeable slowdowns on reasonably modern hardware. Older machines (particularly those more than five or six years old) or machines with very little free storage may feel more impact. It's worth knowing that Microsoft Defender, if it's still active on your machine alongside StrongKeep, can double the scanning load. StrongKeep is designed to disable Defender's real-time protection automatically on install, but this doesn't always complete correctly. Your support team can check this. When to contact support - Slowness is affecting workflows or operations - Multiple devices in the same organisation are affected - Performance hasn't improved after a week - You suspect another antivirus may still be running alongside StrongKeep Contact support@strongkeep.com

Last updated on Jun 15, 2026