Skip to main content

RMM Check for Software Installations in the User Context

Hi, Octoja Team,

I have a feature request for your monitoring/RMM system to make software security even smarter.

The problem:
A lot of adware and annoying PUPs (potentially unwanted programs) deliberately bypass Windows admin rights during installation. They don’t nest themselves globally (HKLM), but directly in the user context (HKCU / the user’s AppData), as we unfortunately see time and again on client computers.

What we need:
A check that scans the installed software and specifically targets anything installed only in the user context.

The check should be able to do the following:

  • Issue a warning: As soon as a program appears in the user context, an alert is displayed in the dashboard.

  • Exception filter (whitelist): Since there are also legitimate tools that do this (such as FreeCAD for individual users, Teams, or OneDrive), we need a filter to exclude known programs from the alert (preferably globally and per device).

This would make it possible to detect shadow IT and user-level malware much more quickly, before they cause any damage.

Log in to comment and vote

No comments yet

Be the first to share your thoughts.