RMM Path Details
complete
N
Nathan
The new RMM Guard reports on installed tools, but doesn't provide any supporting details. For example, during Beta I have multiple RMM's being reporting on endpoints, yet all our normal inventory tools are unable to validate Huntress' findings. The tool should allow admins to drill down into the path or whatever data huntress is using to support their findings.
Chris Bisnett
marked this post as
complete
Chris Bisnett
The details for these detections were lacking. We also ran into the same limitations when trying to do our investigations through the UI. It's good you pointed it out because it helps us make sure we're delivering a good product and it's part of the process for iterating on an early stage product.
Today we shipped some updates to RMM Guard that shows detection paths for each of the hosts in the side drawer. So if you select the RMM we'll show you both the hosts that we have identified with the tool, but also one of the recent paths we detected. This should help us and you investigate the findings and validate whether the detection is a true or false positive.
As others mentioned in this thread, we did have some false positive detections show up. We had mistakenly classified some common libraries and shared components as if they were a part of an RMM tool and that caused some errant detections where we suggested a tool was on a machine where it wasn't. We cleaned this up earlier today and we're putting in some guardrails to avoid mistakes like this in the future. Again, part of the learning process.
Going forward we will add more functionality to the UI to make deeper investigations easier. Look for that in the coming weeks
N
Nathan
Chris Bisnett Appreciate the quick turnaround on a fix for this.
Adrian
Chris Bisnett thank you!
Adrian
Seeing the same behavior, RMM Guard reporting different installed tools but no details other than the machines its detected on. I also see no indication of the tools after researching. I agree with Nathan more data is needed to allow us to investigate. The console does say "learning" so maybe this data will eventually surface?
Julian Jacobsen
I am having this same issue. I have an internal server reporting that it's got RemotePC installed. However, I see no indication of this in Program Files, Add/remove Programs, or the registry.