ESPM RMM Guard - Ninja RMM and Ncplayer
D
David Molohon
Ninja RMM utilizes ncplayer.exe and ncstreamer.exe. Ncplayer is stored in AppData and is per user. Ncstreamer is the intended client access exe, and Ncplayer seems to be used in accessing that.
Since Ncplayer is in the technician's AppData and installed per user, can we have whitelisting in other parts of the detection path? Right now, we're only allowing Ncstreamer via the Program Files path, but I feel like we will run into the issue of not being able to open Ncplayer when attempting to remote in as a technician since it was caught by RMM Guard.
Is there a way to set up detections for both the initiator and client and differentiate between them?