RMM Check for Software Installations in the User Context
Hi, Octoja Team,
I have a feature request for your monitoring/RMM system to make software security even smarter.
The problem:
A lot of adware and annoying PUPs (potentially unwanted programs) deliberately bypass Windows admin rights during installation. They don’t nest themselves globally (HKLM), but directly in the user context (HKCU / the user’s AppData), as we unfortunately see time and again on client computers.
What we need:
A check that scans the installed software and specifically targets anything installed only in the user context.
The check should be able to do the following:
Issue a warning: As soon as a program appears in the user context, an alert is displayed in the dashboard.
Exception filter (whitelist): Since there are also legitimate tools that do this (such as FreeCAD for individual users, Teams, or OneDrive), we need a filter to exclude known programs from the alert (preferably globally and per device).
This would make it possible to detect shadow IT and user-level malware much more quickly, before they cause any damage.
Log in to comment and vote
No comments yet
Be the first to share your thoughts.