TEAM: Huntress Managed Endpoint Detection and Response (EDR)
PRODUCT: Huntress ESPM (Endpoint Security Posture Management)
ENVIRONMENT: Windows Only
SUMMARY: How to enable ESPM RMM Guard.
RMM Guard is a capability within Huntress Managed ESPM that automatically discovers remote monitoring and management (RMM) and other remote access tools across your Windows endpoints, and shows you where they are running and when they were last seen. This article walks through enabling and using RMM Guard for discovery.
Step 1: Join ESPM
- If you have not previously done so, click the ESPM icon in the left navigation of the Huntress Dashboard and click “Start Trial”
- Enable ESPM for the Account or Organizations you want to scan:
- Click the ESPM icon in the left navigation of the Huntress Dashboard.
- Select Settings.
- Set Account Settings to Enabled for account-wide coverage, or use Add Organization Override to enable specific organizations, then Save.
- For more detail, see Huntress Managed ESPM (Early Access) Readiness, Requirements, and FAQ.
Step 2: Let RMM Guard discover RMM tools
Once ESPM is enabled and endpoints are reporting, RMM Guard automatically discovers remote access tools that are running in your environment and lists them in the RMM Tools Inventory.
- After first enabling ESPM for an account or organization, allow up to 24 hours for RMM Guard to build a complete inventory.
- You can speed up discovery by restarting endpoints where appropriate.
- To view discovered RMMs, click the ESPM Icon in the left-hand navigation, then select RMM Guard.
Step 3: Filter for specific RMM
- In the RMM Tools Inventory, use the search to look for the RMM.
- Selecting an entry opens a details panel showing the organizations and endpoints where this tool has been seen.
- You can also export the list as a CSV if you need.
We’d love to get your feedback
If you run into unexpected results, or have suggestions that would make RMM Guard more useful, submit feedback at https://feedback.huntress.com/espm.