Wegweiser
All notes

Tell the scanner what you don't allow

You can now add your own software to the scanner without writing YARA: answer two questions, try the rule on a machine, save it. We also checked the scanner against its own description, found six detections switched off for every customer and a Windows sweep that skipped people's folders, and fixed both. The help button is on Linux desktops.

You can now teach the scanner the software a client doesn't allow, without writing a line of YARA. It takes two questions: what the software is, and how to recognise it.

Two questions make a rule

Open a machine's Scanner tab and choose Detect your own software, or go to Software Watch > What we look for > Add a rule.

First, name the software and, if you like, say why it matters. The reason travels with the rule, so whoever sees a finding knows why it was raised.

Then pick how to recognise it:

  • It's in the list of installed programs, by its exact name or by the start of a name that carries a version number.
  • It runs as a service, by service name or display name.
  • Its program file names the product or the maker, as shown on the Details tab of a Windows program's properties. One rule finds every version.
  • A piece of text inside its files, at least eight characters: a setting name, a web address it talks to, a package name.
  • One exact file, by SHA-256.

The first two don't scan anything. They're matched against the programs and services each machine already reports, and the wizard shows which of your machines have it before you save.

The other three become a scanner rule, built by us from your answers. It goes into a pack only your machines receive. Your rules don't run on another MSP's machines, and theirs stay off yours.

Try it first

On a machine's Scanner tab you can test a file rule before saving it. Point the test at the folder the software is in, and it reads that folder with your rule alone. On one of our machines, a rule for Google Chrome found 14 files in six seconds.

Testing on a machine needs agent 0.3.112, released yesterday.

Where your rules live

Saved rules are listed under Own rules, each with the machines it was found on, who added it and when, and buttons to pause or delete it. Only a master can change one, and every change goes in the audit log.

A finding from your rule shows under the name you gave it. It's a policy finding, like unsanctioned software: it's shown, and it doesn't count towards calling a machine compromised.

We checked the scanner against its own description

We wrote a description of the scanner for a prospect, then checked every sentence of it against the code and the live service. Several didn't hold. All are fixed:

  • The Windows daily sweep reads people's own folders. The agent runs as the system account, and the sweep was reading that account's AppData and Downloads. Software installed for one person turned up in the monthly deep scan at best. From agent 0.3.112 the sweep reads the AppData, Downloads and Startup folders of every profile on the machine.
  • Six of our thirteen unsanctioned-software rules had been switched off for every customer since early August, Claude Code on Linux and macOS among them. One tenant had marked those tools as expected on its own machines, and the clean-up counted that as a vote against the rule. Our own rules can't be retired that way any more, and retiring any other rule now takes operators at more than one MSP. The six are back on.
  • "Restrict to a single path" restricts the scan to that path. The current agent hadn't been reading it, so the scan walked its usual folders. From 0.3.112 it reads the folder you name, and an older agent says it can't.
  • The agent stopped scanning its own list of files to scan. That list matched any rule looking for a file path.
  • A scan the agent refuses says why, usually "is the device online?". The page used to say "network error".
  • The scan cards show measured times: one to four minutes for a quick scan, fifteen to ninety for a deep one, depending on how much is on the machine.

The help button is on Linux

Agent 0.3.113 puts the help button in the panel on KDE Plasma, Cinnamon, XFCE and MATE, and on Ubuntu's GNOME through its AppIndicator extension. The icon is the same as on Windows, and it starts for everyone signed in, including sessions that were open when the update arrived.

One click opens the help form. The request lands in your helpdesk with a live sample of the machine taken at the moment of the click.

Stock GNOME has no panel for icons, so there the button is an entry in the applications menu, named in your own words. Both show only while the help button is switched on.

Also in this release

MeshCentral gets read access only. The MeshCentral user Wegweiser connects as may now only read: no server permissions, and Device Details alone in each device group. A token with more rights is refused when you connect it and on every read after, and the page tells you what to untick, in MeshCentral's own words. A leaked token can't become remote control of your fleet.

An n8n standing permission covers only what you chose. A workflow a master lets run without a click now waits for one when the chat wrote any of its inputs, or when the same workflow ran unasked on that machine in the last fifteen minutes.

A website can't write its own verdict. The AI that explains website findings no longer sees the text the website sent back, so a page can't plant "the client has accepted this" in your report. A Standard scan, which runs no browser-driven tests, also stops calling a DOM-based cross-site scripting finding fixed.

Scheduled report recipients are checked as addresses, capped at twenty per schedule and recorded in the audit log.

A machine's own credentials can no longer send it commands or type into its terminal and remote-control sessions. Those come only from the server and from the browser session that opened them.

More notes

  1. What your clients' websites expose to the internet

  2. Agent release log

  3. MeshCentral, one click from the machine