is there a way to query where mRemoteNG version < 1.76 is installed in IDR?
Hi Hayden,
this sounds more like a use case for our Insight VM Product
could one create an IDR query at least to make a dashboard for most usage by users?
Hey Hayden - if we know the filepath for mRemoteNG we should be able to find use of this tool in Endpoint AgentâProcess Start/Stop logs. Typically in those logs there is a FileVersion field as well where could work to narrow down which version returns in your query result. Note - these results would show the use of this tool vs. just having the tool installed.
Within InsightVM you could try this search:
SELECT
da.sites AS âSite_Nameâ,
da.ip_address AS âIP_Addressâ,
da.mac_address AS âMAC_Addressâ,
da.host_name AS âDNS_Hostnameâ,
ds.vendor AS âVendorâ,
ds.name AS âSoftware_Nameâ,
ds.family AS âSoftware_Familyâ,
ds.version AS âSoftware_Versionâ,
ds.software_class AS âSoftware_Classâ
FROM dim_asset_software das
JOIN dim_software ds USING(software_id)
JOIN dim_asset da ON da.asset_id = das.asset_id
WHERE ds.software_class likeâ%â AND ds.name like â%mRemoteNG%â
ORDER BY ds.name ASC
Id like to do the same for Remote Desktop Connection Manager too.
Within InsightIDR - something along these lines should help:
where(metadata.ProductName=/mRemoteNG/i)groupby(metadata.ProductName)calculate(count)
bingo! thanks!
found one
where(metadata.ProductName=/Remote Desktop Connection Manager/i)groupby(user)