What to tell your EDR
Security software sometimes blocks the probe, because it is PowerShell run by a scheduled task as SYSTEM. This page is what to put in an exclusion or an allow rule.
Linux machines are further down, under On Linux.
What it is
| Thing | Where |
|---|---|
| Program files | C:\Program Files\BOBcloud\Monitor - Collect-MonitorChecks.ps1, Send-MonitorPost.ps1 |
| Its own files (log, queue, diagnostics, update work) | C:\ProgramData\BOBcloud\Monitor |
| Scheduled task | \BOBcloud\Monitor Probe, hourly, runs as SYSTEM |
| What the task runs | powershell.exe -NoProfile -NonInteractive -WindowStyle Hidden -ExecutionPolicy Bypass -File "C:\Program Files\BOBcloud\Monitor\Send-MonitorPost.ps1" -Once |
| Settings | Registry key HKLM\SOFTWARE\BOBcloud\Monitor, readable only by SYSTEM and administrators |
| Network | Outbound HTTPS to collector-uk-1.bobcloud.net only. See Firewall requirements. |
What it does
It reads how the machine is set up - Windows Update status, antivirus, firewall, encryption, account and screen-lock settings, installed software, disks - using Windows' own management interfaces and the registry, and sends the results. It writes to its own folder in C:\ProgramData\BOBcloud\Monitor and its own registry key.
If automatic updates are switched on for the machine (Enable automatic updates), the probe can also update itself. When the portal offers a newer version, the same scheduled task downloads it from the collector, checks its signature against our certificate on the machine, and only then replaces its own two files in C:\Program Files\BOBcloud\Monitor. It then starts one more PowerShell, powershell.exe ... -File "C:\Program Files\BOBcloud\Monitor\Send-MonitorPost.ps1" -SelfTest, to check the new version works, and puts the old files back if it does not. Security software that watches for a script replacing scripts will see exactly that.
What it does not do
- It changes nothing on the machine.
- It opens no listening port and accepts no connection.
- It never runs anything it has not checked. It installs a new version only when automatic updates are switched on, and only a release whose signature checks against our certificate, on the machine, before any file is replaced.
- It does not read documents, browsing history or user content, and sends no user names.
What to allow
- The folder
C:\Program Files\BOBcloud\Monitor, and the scheduled task\BOBcloud\Monitor Probe. - Writes by that task to
C:\ProgramData\BOBcloud\Monitor. - If you use automatic updates: writes by that task to
C:\Program Files\BOBcloud\Monitor, and the PowerShell it starts to runSend-MonitorPost.ps1 -SelfTest. - Outbound HTTPS to
collector-uk-1.bobcloud.net.
On Linux
| Thing | Where |
|---|---|
| The probe | /var/lib/bobcloud-monitor/probe/ - one folder per version, and current pointing at the one that runs |
| What the timer runs | /usr/local/sbin/bobcloud-monitor-agent --once, a fixed launcher that runs current |
| Its own files (log) | /var/lib/bobcloud-monitor and /var/log/bobcloud-monitor |
| Credentials | /etc/bobcloud-monitor, readable only by root |
| systemd | bobcloud-monitor-agent.timer, hourly, starting bobcloud-monitor-agent.service as root, with ProtectSystem=strict: it can write only its own two folders |
| Network | Outbound HTTPS to collector-uk-1.bobcloud.net only, as on Windows. |
It runs as root because some of what it reads is root's alone. It changes nothing on the machine, opens no port, and reads no user content.
With automatic updates switched on, the timer's own run downloads a newer version from the collector, checks its signature against our certificate on the machine, puts it in a new folder beside the old one, runs its self-test, and only then points current at it - and back at the old one if the new one fails. Security software that watches for a script writing scripts will see exactly that, inside /var/lib/bobcloud-monitor/probe/.
What to allow: the timer and its service, writes by that service to its two folders, and outbound HTTPS to collector-uk-1.bobcloud.net.
If the probe is still blocked, collect diagnostics - see Collect diagnostics - and send the file along with your EDR's record of what it blocked.