Monitor

Getting started

Using Monitor

Network and troubleshooting

Your account

Project

What to tell your EDR

Security software sometimes blocks the probe, because it is PowerShell run by a scheduled task as SYSTEM. This page is what to put in an exclusion or an allow rule.

Linux machines are further down, under On Linux.

What it is

ThingWhere
Program filesC:\Program Files\BOBcloud\Monitor - Collect-MonitorChecks.ps1, Send-MonitorPost.ps1
Its own files (log, queue, diagnostics, update work)C:\ProgramData\BOBcloud\Monitor
Scheduled task\BOBcloud\Monitor Probe, hourly, runs as SYSTEM
What the task runspowershell.exe -NoProfile -NonInteractive -WindowStyle Hidden -ExecutionPolicy Bypass -File "C:\Program Files\BOBcloud\Monitor\Send-MonitorPost.ps1" -Once
SettingsRegistry key HKLM\SOFTWARE\BOBcloud\Monitor, readable only by SYSTEM and administrators
NetworkOutbound HTTPS to collector-uk-1.bobcloud.net only. See Firewall requirements.

What it does

It reads how the machine is set up - Windows Update status, antivirus, firewall, encryption, account and screen-lock settings, installed software, disks - using Windows' own management interfaces and the registry, and sends the results. It writes to its own folder in C:\ProgramData\BOBcloud\Monitor and its own registry key.

If automatic updates are switched on for the machine (Enable automatic updates), the probe can also update itself. When the portal offers a newer version, the same scheduled task downloads it from the collector, checks its signature against our certificate on the machine, and only then replaces its own two files in C:\Program Files\BOBcloud\Monitor. It then starts one more PowerShell, powershell.exe ... -File "C:\Program Files\BOBcloud\Monitor\Send-MonitorPost.ps1" -SelfTest, to check the new version works, and puts the old files back if it does not. Security software that watches for a script replacing scripts will see exactly that.

What it does not do

What to allow

On Linux

ThingWhere
The probe/var/lib/bobcloud-monitor/probe/ - one folder per version, and current pointing at the one that runs
What the timer runs/usr/local/sbin/bobcloud-monitor-agent --once, a fixed launcher that runs current
Its own files (log)/var/lib/bobcloud-monitor and /var/log/bobcloud-monitor
Credentials/etc/bobcloud-monitor, readable only by root
systemdbobcloud-monitor-agent.timer, hourly, starting bobcloud-monitor-agent.service as root, with ProtectSystem=strict: it can write only its own two folders
NetworkOutbound HTTPS to collector-uk-1.bobcloud.net only, as on Windows.

It runs as root because some of what it reads is root's alone. It changes nothing on the machine, opens no port, and reads no user content.

With automatic updates switched on, the timer's own run downloads a newer version from the collector, checks its signature against our certificate on the machine, puts it in a new folder beside the old one, runs its self-test, and only then points current at it - and back at the old one if the new one fails. Security software that watches for a script writing scripts will see exactly that, inside /var/lib/bobcloud-monitor/probe/.

What to allow: the timer and its service, writes by that service to its two folders, and outbound HTTPS to collector-uk-1.bobcloud.net.

If the probe is still blocked, collect diagnostics - see Collect diagnostics - and send the file along with your EDR's record of what it blocked.

Next: When a probe stops reporting