Library

Accelerate your workflows.

Prebuilt automations, scripts, and monitors, ready to deploy into your fleet.

Windows Patching Automation

Automate Windows OS and third-party patching on your schedule—no code needed. Delay patches for stability, apply best-practice retries, and handle updates to apps like Chrome and Zoom with ease.

macOS Patching Automation

Easily schedule and manage macOS updates—no coding required. Delay patches for stability, apply retries for failed installations, and receive alerts for repeated failures.

Linux Patching Automation

Automate Linux OS and third-party updates across various distributions—no coding required. Schedule or trigger on-demand, retry failed patches, and get alerts for repeated failures.

macOS Setup Automation

Automate new Mac deployments with one click—apply custom tags, install updates, add local admins, manage power settings, and trigger AV, VPN, or Office 365 automations. Save time, reduce errors, and standardize your onboarding process.

Windows Setup Automation

Eliminate the hassle of setting up new Windows devices with this fully customizable and repeatable automation that ensures consistent configurations across endpoints.

Windows Security Check Automation

Ensure your Windows systems are secure and up-to-date with this automated weekly security check. Covers antivirus updates, scans, firewall, disk health, and more. Alerts you to potential issues so you can focus on other priorities.

Windows Admin Compliance & Remediation

Automatically detect and disable unauthorized local admins on Windows devices. This automation runs manually or on a schedule, ensuring compliance and security. Pairs best with the “Admin Users Monitor” for seamless enforcement.

Linux Setup Automation

Automate Linux onboarding with one click—install updates, add an admin user, upload SSH keys, apply AV and Managed tags, and finalize settings with a reboot. Simplify device deployment, ensure consistency, and save time.

Linux Security Check Automation

Automate your Linux security and maintenance tasks with this weekly check. Updates packages, checks disk health, audits security settings, and more, ensuring robust and optimized Linux environments.

Install Sentinel One (S1) Automation

Effortlessly deploy SentinelOne on Windows by tagging devices with “S1.” Leverage Level’s custom for the Sentinel Token for flexible configuration and receive alerts for any installation failures—perfect when paired with a monitor for S1.

Install Prey Automation

Easily deploy Prey for Windows with this automation. Run manually or trigger it automatically by tagging a device. If the installation fails, an alert is generated for quick troubleshooting.

Install Huntress Automation

Effortlessly deploy Huntress on Windows by tagging devices with Huntress. Leverage custom fields in Level for the Huntress Token for flexible configuration and receive alerts for any installation failures—ideal when paired with our Security Monitor.

Install Cove Backup Automation

Automate the installation of Cove Backup on Windows devices with a single click. This automation can be run manually or triggered automatically by tagging a device with “Backup.” If the installation fails, an alert will be generated for quick trouble

Cross-Platform Patching Automation

Seamlessly patch Windows, macOS, and Linux systems on a schedule—or on demand—without writing any code. Automatically retry failed updates, receive alerts for repeated failures, and keep all your endpoints consistently up to date.

Axcient x360Recover Install Automation

Easily install Axcient x360Recover on Windows, macOS, or Linux—whether you’re using a local server or the cloud. Configure custom fields for quick setup, trigger the install via tag or manual start, and receive alerts for any failed installations.

macOS Unauthorized Admins Script

Compare detected macOS admin accounts to your authorized list, instantly identifying any unexpected privilege assignments. Ideal for script-based monitoring and compliance automation in Level.

macOS Monitor - System Time Check

Ensures macOS endpoints maintain the correct time zone, network time sync, and NTP server configuration. Fixes issues automatically and alerts you when inconsistencies occur, helping prevent authentication, logging, and scheduling conflicts.

macOS Monitor - Device Standards Script

Automatically verify that macOS devices meet minimum CPU, RAM, and storage requirements using Level’s custom fields. Use this script within a script-based monitor to detect non-compliant devices and trigger alerts.

macOS Lock Device Script

Instantly log out and lock down all local user accounts on a macOS device, including root, to prevent unauthorized access while maintaining remote management through Level.

macOS Get Local Admins Script

Identify and list active admin users on macOS endpoints by verifying account expiration and lock status, ensuring quick oversight of privileged accounts for improved security and compliance.

macOS Endpoint Intelligence Gathering

A one-click script to collect key system and network details on a macOS device, including system info, local and public IPs, Wi-Fi networks, and ARP tables. Ideal for security audits and lost/stolen device tracking.

macOS Disk Cleanup Script

Frees up disk space by removing outdated temp files, cache folders, old downloads, system logs, and more. Keeps your Mac running smoothly with an automated cleaning process you can schedule or trigger on demand through Level.

macOS Device Erase Script

Securely erase a macOS endpoint with a single command. This script removes user profiles, applications, browser data, credentials, Wi-Fi networks, SSH keys, and keychains.

macOS Delete/Disable Users Script

Disable or remove unwanted macOS user accounts with a single script. Leverage Level’s “UsersToDelete” variable for easy batch operations and pair it with script-based monitors or automations to maintain secure, compliant endpoints.

Windows Unlock Device Script

Effortlessly re-enable local and domain user accounts on a Windows device. Ideal for restoring normal operations after a security lockdown, unexpected lockouts, or account maintenance routines.

Windows Unauthorized Admins Script

Identify and alert on unauthorized Windows admin accounts by comparing detected users to an authorized admin list. Perfect for script-based monitors, ensuring your environment remains compliant and secure.

Windows Unauthorized Admin Login Script

Detects and alerts on unauthorized administrator logins within the last hour. Uses a custom field in Level to define authorized admins. Pair with a script-based monitor to automatically generate alerts for unauthorized access attempts.

Windows Monitor - Security Center Script

Checks antivirus and firewall settings on Windows devices via Security Center, flagging any disabled or missing security products. Ideal for a script-based monitor that triggers alerts or automatic remediation if an issue is found.

Windows Monitor - Firewall Script

Checks if at least one Windows Firewall profile is enabled, returning success if a profile is active or an alert otherwise. Ideal for script-based monitors that notify you when firewall protection is missing.

Windows Monitor - AV Script

Verifies that an antivirus recognized by Windows Security Center is active, alerting if no protection is detected or real-time scanning is disabled. Perfect for a script-based monitor and automated remediation in Level.

Windows Lock Device Script

Quickly logs out all user sessions and disables local or domain accounts on a Windows device. Ideal for emergency lockdown scenarios, stolen hardware, or security compliance efforts to protect systems from unauthorized access.

Windows Get Local Admins Script

Quickly identifies which user accounts are actively enabled in the local Administrators group on Windows systems. Use this script to maintain secure user privileges and ensure compliance with least-privileged access policies.

Windows Failed Admin Login Script

Detects and alerts on failed login attempts for administrator accounts within the last hour. Pair with a script-based monitor in Level to automatically generate alerts for potential unauthorized access attempts.

Windows Event Log Monitor Script

Searches Windows event logs for specific event IDs, severities, and sources. If matching events are found within the defined timeframe, it triggers an alert, making it easier to catch critical or error-level events in real time.

Windows Disk Cleanup Script

Frees up Windows storage by removing temp data, old downloads, and leftover update files. It logs actions, saves you time, and reclaims valuable disk space. Integrate with Level for quick or scheduled maintenance.

Windows Device Erase Script

Securely erase a Windows endpoint with a single command. This script removes user profiles, browser data, saved credentials, system restore points, event logs, and even wipes all fixed drives.

Windows Delete/Disable Users Script

Quickly remove or disable unwanted local user accounts on Windows devices, using a dynamic script variable for batch processing. Ideal for script-based monitors or automated compliance workflows in Level.

Windows Create Restore Point Script

Automatically create a Windows System Restore Point before or after critical actions. Ideal for scheduled automations, such as patching or security checks, ensuring a rollback option is available when needed.

Upgrade to Windows 11 Script

Effortlessly transition Windows 10 systems to Windows 11. This script downloads and launches the official Microsoft Installation Assistant, automates the upgrade process, and cleans up afterward—perfect for seamless OS migrations at scale.

Remove Bloatware Windows PowerShell Script

Quickly remove unnecessary Microsoft Store apps from Windows devices while preserving essential applications. This PowerShell script ensures a clean system by maintaining an audit log and allowing custom whitelist configurations.

OsQuery Monitor - Uptime Script

Tracks system uptime via OsQuery. Ideal for scripting an alert if a device surpasses a set runtime threshold, helping IT Pros and MSPs know when a reboot or maintenance might be necessary.

Linux Unauthorized Admins Script

Cross-check detected Linux admin accounts against your authorized list and quickly alert on any unexpected privileges. Ideal for script-based monitoring and automated compliance checks in Level.

Linux Monitor - System Time Check Script

Time drift can cause issues with logging, scheduling, and security across Linux environments, often leading to missed backups and failed authentication checks. This script helps IT Professionals and MSPs maintain consistent time settings, protecting

Linux Monitor - Firewall Script

Checks for active firewall configurations (UFW, iptables, nftables) in Linux environments. Alerts if no firewall is detected, ensuring critical security measures remain in place. Perfect for script-based monitoring and automated remediation in Level.

Linux Lock Device Script

Terminated active user sessions and locked down all Linux accounts, including root, to prevent unauthorized access while preserving remote control via Level.

Linux Get Local Admins Script

Quickly identifies active local admin accounts in the sudo group on Linux systems by checking account expiration and lock status, helping IT pros maintain security visibility and compliance.

Linux Endpoint Intelligence Gathering

A one-click script to collect key system and network details on a Linux device, including system info, local and public IPs, Wi-Fi networks, and ARP tables. Ideal for security audits, network troubleshooting, and lost/stolen device tracking.

Linux Disk Cleanup Script

Automates disk cleanup on Linux by removing cache files, purging old logs, and pruning Docker and Kubernetes leftovers. Reclaims valuable storage, logs its actions, and supports on-demand or scheduled runs through Level’s platform.

Linux Device Erase Script

Securely erase a Linux endpoint with a single command. This script removes all user data, system configurations, and even the root filesystem, making the device completely inoperable.

Linux Delete/Disable Users Script

Easily lock or remove Linux user accounts using a simple comma-separated list. Ideal for script-based monitors or automated compliance workflows in Level, ensuring unauthorized users are swiftly disabled or deleted.

Windows MFA Monitor

A script-based monitor that checks Windows MFA settings hourly. If multi-factor authentication is improperly configured, it raises an alert—and automatically resolves once MFA is enabled.

Veeam Backup Monitor Policy

Ensure Veeam backup reliability with automated monitoring. This policy tracks service status, verifies backup completion, and alerts on failures—keeping your data protection strategy running smoothly.

Uptime Monitoring Policy

A cross-platform policy that tracks device uptime on Windows, macOS, and Linux, helping you identify systems with excessive or insufficient uptime for optimal performance and maintenance scheduling.

System Time Monitoring

Monitor and alert on system time discrepancies across Windows, macOS, and Linux. Ensure time synchronization to prevent authentication failures, compliance issues, and operational disruptions.

Sentinel One (S1) Monitoring Policy

Monitor SentinelOne service health across Windows and macOS. Automatically restarts stopped services, triggers alerts, and closes resolved issues—ensuring endpoints remain secure and operational with minimal manual intervention.

Security Monitoring Policy

Ensure airtight security across Windows, macOS, and Linux systems with this plug-and-play monitoring policy. Detect and remediate DNS, firewall, admin user, sudo user, and SSH key anomalies in real-time—no coding required.

Nginx Service Monitoring

Proactively monitor and manage the Nginx service on Linux devices. Automatically restart stopped services, and receive real-time alerts to ensure uninterrupted web server operations.

Global Monitoring Policy

Comprehensive cross-platform monitoring for Windows, macOS, and Linux endpoints. Tracks CPU, memory, disk usage, and uptime, generating actionable alerts for proactive IT management.

Failed Login Monitor

This monitor policy includes two pre-configured monitors: one that alerts on failed admin logins and another that alerts on any failed login attempt. Choose whether to monitor all users or just admins and delete the other.

Endpoint Standards Monitoring

A cross-platform monitoring policy that ensures devices meet your organization’s CPU, RAM, and disk storage standards, helping you track compliance and identify when replacements are needed.

DNS Monitoring Policy

Monitors DNS resolution health across Windows, macOS, and Linux. Alerts when devices fail to resolve configured hostnames and auto-resolves when connectivity is restored.

Admin Monitoring Policy

Get instant alerts when unauthorized admin users appear on any Windows, macOS, or Linux device. Maintain security, enforce compliance, and simplify monitoring—no coding required. Pair with remediation automations to automatically disable unauthorized

Admin Login Monitor

This monitor policy includes two pre-configured monitors: one that alerts on all admin logins and another that alerts only on unauthorized admin logins. Customize based on your security needs. Windows only for now—macOS and Linux support coming

Ready when you are.

No credit card. No sales call. Just sign up and start managing.