AI intelligence layer for MSPs
Stop onboarding surprises. Start proactive MSP intelligence.
Wegweiser reads your client's logs like a senior engineer, surfacing hidden risks before they become tickets - the AI layer that deepens any RMM stack. When it finds something, act on the spot: a live terminal and Windows remote control are built in.
RMM-agnostic agent
Our lightweight agent deploys through ANY RMM platform - Windows workstations, servers, Linux, macOS and networked devices - for comprehensive insight across the estate.
Hierarchical health scoring
Every device gets an AI-calculated health score with prioritised recommendations. Scores cascade up through groups and organisations for complete visibility.
Beyond traditional RMM
Surface critical patterns over the last 30 days that automation misses. Deep log analysis and pattern recognition that supplement your team's expertise.
Why we built this
Solving critical MSP bottlenecks
Two bottlenecks sit in every MSP's lifecycle: Client Onboarding Hell - where larger customers hide critical issues beneath the surface - and the Knowledge Gap - where nobody can know everything about every hardware type or event log. We use AI to supplement your team's expertise.
"I built the AI layer I always wished existed - one that reads logs the way an experienced engineer would, not just counts them."
25+ analyzers, across the stack
Capabilities
What Wegweiser does
Onboarding Assessment
The day-one report that fuses the estate's analysers into the hidden issues a new client never mentioned - compounding device risk, fleet-wide analyser failures, exposed-and-unhealthy machines - with a rolling weekly diff and compliance posture. Deterministic scoring, no LLM on the hot path.
Unrecognised-binary detection
Executables from every install location and user profile on Windows, and the standard binary paths on Linux and macOS, hashed and checked against the NIST National Software Reference Library. The custom, in-house and novel binaries that match nothing known lead each weekly scan - the ones in user-writable paths first. A throttled agent scan; read-only intelligence, never a verdict.
Discuss-and-Override
Findings you can argue with. When a finding is benign - your own admin tool, a dev box's open ports - accept it in two clicks, one scanner detection at a time or the whole analysis, or just tell the AI in chat. The score recomputes honestly, every override is audited, a whole-analysis accept is one click to undo, and new findings still alert.
Root-cause investigation
A finding tells you what is wrong; an investigation works out why. A tool-using AI agent walks event timelines, baselines and live osquery, then reports probable cause, evidence and the next action - one click, or automatically on fresh critical findings up to a daily cap per client.
Patch posture, every OS
Windows, Linux and macOS - pending and security updates, end-of-life operating systems, and whether the update machinery itself works. A box that can't patch is the finding, not a footnote. Read-only intel; your RMM still does the patching.
Windows remote control
Full desktop control from the browser - no VPN, no inbound firewall rules at the client, no second product. Change-driven capture stays light on the endpoint, switching between monitors is one click, and every session lands in the audit log under an always-on-top banner the user cannot close.
Live terminal, every OS
A real PowerShell or bash session in the browser, running as SYSTEM or root on any online device running the agent - operators only. Credentials are scoped to a single session and expire on their own after 30 minutes, and every session open is audited. Investigate a finding and fix it in the same minute.
Live AI chat & monitoring
Ask about any device, group or organisation and get streaming AI answers over that level's full analysis history. In a device chat it can also accept findings as expected risk and recompute the health score on request. Open the live monitor and CPU, memory, disk and network stream from the agent about every two seconds; the rest of the time a lighter baseline rides the heartbeat.
Event forecast
Predict which Windows events fire in the next 24 hours and 7 days - pure statistical analysis of 30-day archives, zero AI cost, with confidence from scheduled to sporadic.
Autonomous AI threat detection
Every 24 hours the AI turns CISA KEV, NVD and GitHub advisories into YARA rules, validates them by compiling with YARA-X, and files them in your threat-intel pack - promote one and the next pack build carries it into the fleet sweep. Rules that fire too often are auto-demoted, so noise cannot drown the real findings.
Shadow AI discovery
Find the AI tools nobody approved. Claude Code, Gemini CLI, GitHub Copilot CLI and Ollama on Windows, Linux and macOS; Claude Desktop, ChatGPT Desktop and LM Studio on Windows; Antigravity on Linux. Matched on what the tool is rather than where it sits, so it's caught wherever the scan reaches - including from a stray config file. Every hit tags the device and evidences your CIS and ISO 27001 unauthorised-software controls.
Community & government feeds
Your scan packs aren't only ours. YARA-Forge - which aggregates 45+ vetted public rule repositories - is pulled weekly and built straight into your packs, while CISA's Known Exploited Vulnerabilities list, NVD and GitHub advisories drive rule generation. Coverage follows what attackers are using, not what merely scored high.
Retrohunt
Detection that reaches backwards. When a sample is newly published as malicious, its hash is matched against the binary inventory already collected across your fleet - so a file that was unknown the day it landed is still found the day it becomes known. Hits land in the threat-hunting view like any other detection.
Explain it, then dismiss it once
Ask the AI why a rule fired and get the matched file, the rule's provenance and a plain-English read. If it's a false positive, mute it once and it applies to every device that matched in the window you're viewing - and once enough endpoints reject the rule, it's dropped from the packs entirely.
Client uptime monitoring
Watch the services a client actually notices - web, mail, VPN endpoints - with per-organisation monitors and keyword checks. Outages are re-probed independently before anyone is paged, then alert down the same Slack, Teams and webhook channels as everything else, with a recovery notice when it clears.
Passkey sign-in
Phishing-resistant login with WebAuthn passkeys - Touch ID, Windows Hello or a hardware key - alongside TOTP two-factor and single-use backup codes.
Report Centre
Generate a device, organisation or tenant PDF on demand, and have the organisation or tenant report e-mail itself weekly or monthly. Plus a plain-English client QBR, a device-inventory CSV per organisation, and a searchable archive of every PDF you produce.
Intelligence hub
A dedicated AI command centre: health KPIs, AI-generated strategic recommendations, health trends at tenant, organisation, group and device level, and chat across the whole tenant.
Slack / Teams / webhook alerts
Critical findings land in your workflow - Teams, Slack, e-mail, or a ticket-shaped webhook your PSA ingests. Sign generic-webhook deliveries with an HMAC secret, and test any channel in one click.
Share-with-client links
Hand a client a tokenised read-only health view - no login, no chat, no internal IDs - revocable any time.
CIS / ISO 27001 / Cyber Essentials
Findings carry the controls they materially evidence - CIS v8, ISO/IEC 27001:2022, NCSC Cyber Essentials, and NIST 800-53 on logging and patching. A hand-maintained, deliberately conservative mapping, not AI guesswork. Walk in speaking the client's language.
Bring your own LLM
Point the analysis pipeline and chat at your own Ollama instance - no client data goes to OpenAI, Anthropic or Azure, and chat retrieval runs on local CPU embeddings. Built for public sector, healthcare and legal. Same UI, your models.
In motion
See it in action
Fit
Who should try Wegweiser?
MSPs struggling with onboarding
The larger the customer, the harder it is to find the machines with critical issues lurking beneath the surface.
Teams wanting AI-assisted insight
Nobody can know everything about every hardware type or event log. Let AI supplement your team's expertise.
Forward-thinking MSPs
Anyone curious about the future of intelligent RMM supplements and centrally managed AI intelligence.
Ready to transform your MSP operations?
Start uncovering what's really happening inside your clients' systems - in minutes, not days. Register and receive 1,000 Wegcoins - enough to run deep AI analyses across many devices. No card required.
Start free - no card requiredTalk to us
Contact
Questions, demos or partnership chats - we typically reply within one business day.
Address
Old Forge, Newmarket Road, United Kingdom, CB8 7PP
Phone
+44 1223 297 870
info@wegweiser.tech













