TEAM: Huntress Managed Endpoint Detection and Response (EDR)
PRODUCT: Huntress ESPM (Endpoint Security Posture Management)
ENVIRONMENT: Windows Only
SUMMARY: How to enable ESPM RMM Guard.
RMM Guard is a capability within Huntress Managed ESPM that automatically discovers remote monitoring and management (RMM) and other remote access tools across your Windows endpoints, and shows you where they are running and when they were last seen. This article walks through enabling and using RMM Guard for discovery.
Step 1: Join ESPM
- If you have not previously done so, click the ESPM icon in the left navigation of the Huntress Dashboard and click “Start Trial”
- ESPM's App Control is off by default, so you'll need to enable ESPM for the Account, Organizations, or endpoints you want to scan:
- Click the ESPM icon in the left navigation of the Huntress Dashboard.
- Select Settings.
- Set Account Settings to Enabled for account-wide coverage, use Add Organization Override to enable specific organizations, or use Add Endpoint Override to enable specific machines, then Save. Overrides can be used for granular control over exactly which endpoints or organizations are enrolled in ESPM.
- For example if you want to enable just a single organization, keep Account Setting as "Disabled" but add an Organization Override for that org.
- Conversely, if you wanted to exclude your fail-over servers, you'd set the Account Setting as "Enabled" and then create a Override for the fail-over servers.
- For more detail, see Huntress Managed ESPM (Early Access) Readiness, Requirements, and FAQ.
Step 2: Let RMM Guard discover RMM tools
Once ESPM is enabled and endpoints are reporting, RMM Guard automatically discovers remote access tools that are running in your environment and lists them in the RMM Tools Inventory.
- After first enabling ESPM for an account or organization, allow up to 24 hours for RMM Guard to build a complete inventory.
- You can speed up discovery by restarting endpoints where appropriate.
- To view discovered RMMs, click the ESPM Icon in the left-hand navigation, then select RMM Guard.
Step 3: Filter for specific RMM
- In the RMM Tools Inventory, use the search to look for the RMM.
- Selecting an entry opens a details panel showing the organizations and endpoints where this tool has been seen.
- You can also export the list as a CSV if you need.
We’d love to get your feedback
If you run into unexpected results, or have suggestions that would make RMM Guard more useful, submit feedback at https://feedback.huntress.com/espm.