{
  "Name": "Freshservice",
  "Category": "RMM",
  "Description": "Freshservice is a SaaS IT Service Management (ITSM) platform from Freshworks Inc. that includes a built-in asset discovery and management capability via two endpoint agents distributed by Freshworks: the **Freshservice Discovery Agent** (FSAgent — installed per-endpoint, gathers hardware/software inventory and reports back to a tenant Freshservice URL) and the **Freshservice Discovery Probe** (a Windows scanning station that performs network-wide discovery via WMI/SSH/SNMP using bundled nmap, plink, Renci.SshNet and SNMP libraries). Both are MSI installers signed by \"Freshworks Inc\" (DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1) and downloaded from `fstools.freshservice.com/agent/` (Discovery Agent) or from the tenant Discovery Hub (Probe).\nThe Discovery Agent registers a SYSTEM Windows service (`FSAgentService`), drops `FSAgentAutoUpdate.exe` (a Freshworks auto-updater that pulls new agent versions from `fstools.freshservice.com`), and persists tenant configuration (account URI + registration key + optional proxy credentials) under `HKLM\\SOFTWARE\\Freshdesk\\FSAgent` (or `HKLM\\SOFTWARE\\WOW6432Node\\Freshdesk\\FSAgent` on x64). The Probe registers a SYSTEM Windows service (`FreshServiceScan`, image `Freshservice.DiscoveryProbe.ScanService.exe`), bundles a substantial network-scanning toolkit (nmap, plink/PuTTY, Renci.SshNet, SnmpSharpNet, Vim25Service, .NET TaskScheduler, SQLite), and stores its tenant config under `HKLM\\SOFTWARE\\Freshworks\\FreshServiceProbe` including a JWT-style `RegistrationKey` value pointing at the tenant `*.freshservice.com` portal.\nOperationally relevant for defenders: the Discovery Agent provides a SYSTEM autostart service with auto-update from a vendor-controlled Freshworks domain on every Windows endpoint where it is deployed; the Probe ships and registers `plink.exe`, `nmap` and `nmap-service-probes`, full Vim25/VMware vSphere SDK bindings and a Renci SSH library — and is intended to perform credentialed sweeps of the entire network including SCCM (`Freshservice.Integrations.SCCM.dll`) and Active Directory (`ListADComputers.vbs`). Both components have been observed in incidents where a threat actor signs up for a Freshservice trial tenant and pushes the legitimately-signed Freshworks installer to victim hosts to gain a SYSTEM-level remote inventory/management foothold without tripping signature-based EDR. The cloud SaaS portion (`<tenant>.freshservice.com`, `myfreshworks.com`, `freshworksapi.com`, `freshconnect.io`) and the Freshworks \"Switchboard\"/Freddy AI features are pure browser-side and do not drop endpoint artifacts; only the Discovery Agent and Discovery Probe install local services.\n",
  "Author": "@MHaggis",
  "Created": "2026-05-04",
  "LastModified": "2026-05-04",
  "Details": {
    "Website": "https://www.freshworks.com/freshservice/",
    "PEMetadata": [
      {
        "Filename": "FSAgentService.exe",
        "OriginalFileName": "FSAgentService.exe",
        "Description": "Freshservice Discovery Agent SYSTEM service (.NET, signed by \"Freshworks Inc\"; registers as Windows service `FSAgentService` and runs as LocalSystem)"
      },
      {
        "Filename": "FSAgentAutoUpdate.exe",
        "OriginalFileName": "FSAgentAutoUpdate.exe",
        "Description": "Freshservice Discovery Agent auto-updater (.NET, signed by \"Freshworks Inc\"; pulls new agent MSIs from fstools.freshservice.com)"
      },
      {
        "Filename": "FSAgentCrashStatusUpdater.exe",
        "OriginalFileName": "FSAgentCrashStatusUpdater.exe",
        "Description": "Freshservice Discovery Agent crash reporter (.NET, signed by \"Freshworks Inc\")"
      },
      {
        "Filename": "FSWmiScanner.exe",
        "OriginalFileName": "FSWmiScanner.exe",
        "Description": "Freshservice WMI inventory helper invoked by the Discovery Agent / Probe (.NET, signed by \"Freshworks Inc\")"
      },
      {
        "Filename": "AgentInstaller.dll",
        "OriginalFileName": "AgentInstaller.dll",
        "Description": "Freshservice Discovery Agent custom-action DLL (.NET, runs the FSAgentService install/uninstall via msiexec)"
      },
      {
        "Filename": "Freshservice.DiscoveryProbe.Window.exe",
        "OriginalFileName": "Freshservice.DiscoveryProbe.Window.exe",
        "Description": "Freshservice Discovery Probe tray application (.NET, ConfuserEx-packed, signed by \"Freshworks Inc\"; references fstools.freshservice.com and the legacy fstools.freshasset.com)"
      },
      {
        "Filename": "Freshservice.DiscoveryProbe.ScanService.exe",
        "OriginalFileName": "Freshservice.DiscoveryProbe.ScanService.exe",
        "Description": "Freshservice Discovery Probe SYSTEM scan service binary (registered as Windows service `FreshServiceScan`, LocalSystem, Automatic startup)"
      },
      {
        "Filename": "Freshservice.DiscoveryProbe.AutoFlush.exe",
        "OriginalFileName": "Freshservice.DiscoveryProbe.AutoFlush.exe",
        "Description": "Freshservice Discovery Probe scheduled flush helper"
      },
      {
        "Filename": "Freshservice.DiscoveryProbe.OIDLibraryPuller.exe",
        "OriginalFileName": "Freshservice.DiscoveryProbe.OIDLibraryPuller.exe",
        "Description": "Freshservice Discovery Probe SNMP OID library updater"
      },
      {
        "Filename": "Freshservice.DiscoveryProbe.ProgressBar.exe",
        "OriginalFileName": "Freshservice.DiscoveryProbe.ProgressBar.exe",
        "Description": "Freshservice Discovery Probe scan progress UI helper"
      },
      {
        "Filename": "AutoUpdate.exe",
        "OriginalFileName": "AutoUpdate.exe",
        "Description": "Freshservice Discovery Probe auto-updater (.NET, signed by \"Freshworks Inc\"; pulls new probe MSIs from fstools.freshservice.com)"
      },
      {
        "Filename": "FSProbeReporter.exe",
        "OriginalFileName": "FSProbeReporter.exe",
        "Description": "Freshservice Discovery Probe telemetry reporter"
      },
      {
        "Filename": "FSProbeCrashStatusUpdater.exe",
        "OriginalFileName": "FSProbeCrashStatusUpdater.exe",
        "Description": "Freshservice Discovery Probe crash reporter"
      },
      {
        "Filename": "FSScheduler.exe",
        "OriginalFileName": "FSScheduler.exe",
        "Description": "Freshservice Discovery Probe scheduler helper (uses Microsoft.Win32.TaskScheduler.dll to register Windows scheduled tasks)"
      },
      {
        "Filename": "IPRangeCalculator.exe",
        "OriginalFileName": "IPRangeCalculator.exe",
        "Description": "Freshservice Discovery Probe IP-range subnet calculator"
      },
      {
        "Filename": "UninstallStatusUpdater.exe",
        "OriginalFileName": "UninstallStatusUpdater.exe",
        "Description": "Freshservice Discovery Probe uninstall reporter"
      },
      {
        "Filename": "plink.exe",
        "OriginalFileName": "plink.exe",
        "Description": "PuTTY plink.exe (PuTTY 0.62) bundled inside the Freshservice Discovery Probe MSI for SSH-based scanning of Linux/Unix hosts (legitimate redistributable, but executes from the Freshservice install dir)"
      }
    ],
    "Privileges": "SYSTEM",
    "Free": "14-day trial; paid SaaS subscription",
    "Verification": "Tenant signup with email; corporate email accepted but not strictly enforced. Discovery Agent / Probe installers are tenant-bound via REGISTRATIONTOKEN (Agent) or a JWT-style RegistrationKey embedded in the Probe MSI (e.g. payload `{\"portal_url\":\"https://<tenant>.freshservice.com\"}`).",
    "SupportedOS": [
      "Windows",
      "MacOS",
      "Linux"
    ],
    "Capabilities": [
      "IT Service Management (ITSM) ticketing and helpdesk",
      "SYSTEM-level endpoint inventory via Discovery Agent (per-host MSI; Windows / macOS / Linux)",
      "Network-wide credentialed asset discovery via Discovery Probe (WMI for Windows, SSH for Linux/Mac, SNMP for network gear, VMware vSphere via Vim25Service.dll)",
      "Active Directory enumeration (bundled `ListADComputers.vbs`, `ListDomains.vbs`)",
      "Microsoft SCCM integration (`Freshservice.Integrations.SCCM.dll`)",
      "Bundled offensive-adjacent toolset shipped inside the Probe MSI (nmap service probe DB, plink.exe / PuTTY, Renci.SshNet, SnmpSharpNet)",
      "Auto-update of agent + probe binaries from fstools.freshservice.com without admin interaction",
      "Tenant-side remote workflow / orchestration (Freshservice Workflow Automator) and Freddy AI",
      "Asset CMDB with per-endpoint hardware/software inventory and software metering"
    ],
    "Vulnerabilities": [],
    "InstallationPaths": [
      "C:\\Program Files (x86)\\Freshdesk\\Freshservice Discovery Agent\\*",
      "C:\\Program Files (x86)\\Freshdesk\\Freshservice Discovery Agent\\bin\\*",
      "C:\\Program Files (x86)\\Freshdesk\\Freshservice Discovery Agent\\conf\\*",
      "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\*",
      "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\*",
      "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\conf\\*",
      "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\db\\*",
      "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\nmap\\*",
      "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\tools\\ssh\\*",
      "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\Freshservice.DiscoveryProbe.ScanService.exe",
      "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\Freshservice.DiscoveryProbe.Window.exe",
      "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\plink.exe",
      "C:\\Program Files (x86)\\Freshdesk\\Freshservice Discovery Agent\\FSAgentService.exe",
      "C:\\Program Files (x86)\\Freshdesk\\Freshservice Discovery Agent\\FSAgentAutoUpdate.exe",
      "*\\FSAgentService.exe",
      "*\\FSAgentAutoUpdate.exe",
      "*\\FSWmiScanner.exe",
      "*\\Freshservice.DiscoveryProbe.Window.exe",
      "*\\Freshservice.DiscoveryProbe.ScanService.exe",
      "fs-windows-agent-*.msi",
      "win-installer-*.msi",
      "fs-probe-*.msi",
      "FSAgent.msi"
    ]
  },
  "Artifacts": {
    "Disk": [
      {
        "File": "C:\\Program Files (x86)\\Freshdesk\\Freshservice Discovery Agent\\FSAgentService.exe",
        "Description": "Freshservice Discovery Agent SYSTEM service binary (registered as Windows service `FSAgentService`). Confirmed via `fs-windows-agent-3.10.0.msi` File table and CAPE Sandbox of SHA256 773f976170f87167d63d55bf83c5f3853d3f10f01dd627ab3dfe0f02b6f25d48.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshdesk\\Freshservice Discovery Agent\\FSAgentAutoUpdate.exe",
        "Description": "Freshservice Discovery Agent auto-updater binary; pulls new MSIs from fstools.freshservice.com.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshdesk\\Freshservice Discovery Agent\\FSAgentCrashStatusUpdater.exe",
        "Description": "Freshservice Discovery Agent crash reporter binary.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshdesk\\Freshservice Discovery Agent\\FSWmiScanner.exe",
        "Description": "Freshservice WMI scanner helper invoked by FSAgentService.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshdesk\\Freshservice Discovery Agent\\AgentInstaller.dll",
        "Description": "Freshservice Discovery Agent custom-action DLL responsible for installing/uninstalling the `FSAgentService` Windows service via msiexec.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshdesk\\Freshservice Discovery Agent\\FSUtil.dll",
        "Description": "Freshservice Discovery Agent shared utility library.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshdesk\\Freshservice Discovery Agent\\Newtonsoft.Json.dll",
        "Description": "Bundled JSON.NET library shipped inside the Discovery Agent MSI.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshdesk\\Freshservice Discovery Agent\\log4net.dll",
        "Description": "Bundled log4net library shipped inside the Discovery Agent MSI.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshdesk\\Freshservice Discovery Agent\\Microsoft.Win32.TaskScheduler.dll",
        "Description": "Microsoft.Win32.TaskScheduler library shipped inside the Discovery Agent MSI; used to register scheduled tasks for inventory cycles.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshdesk\\Freshservice Discovery Agent\\settings.conf",
        "Description": "Freshservice Discovery Agent local config file.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshdesk\\Freshservice Discovery Agent\\fslogger.xml",
        "Description": "log4net configuration file for FSAgentService.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshdesk\\Freshservice Discovery Agent\\logs\\*",
        "Description": "Freshservice Discovery Agent log directory (vendor-documented log location for the Windows agent).",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\Freshservice.DiscoveryProbe.ScanService.exe",
        "Description": "Freshservice Discovery Probe SYSTEM scan service binary (registered as Windows service `FreshServiceScan`). Confirmed via `fs-probe-4.13.0.msi` ServiceInstall table.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\Freshservice.DiscoveryProbe.Window.exe",
        "Description": "Freshservice Discovery Probe tray application; embeds references to fstools.freshservice.com and fstools.freshasset.com.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\AutoUpdate.exe",
        "Description": "Freshservice Discovery Probe auto-updater binary.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\Freshservice.DiscoveryProbe.AutoFlush.exe",
        "Description": "Freshservice Discovery Probe scheduled flush helper.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\Freshservice.DiscoveryProbe.OIDLibraryPuller.exe",
        "Description": "Freshservice Discovery Probe SNMP OID library updater.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\Freshservice.DiscoveryProbe.ProgressBar.exe",
        "Description": "Freshservice Discovery Probe scan progress UI helper.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\FSProbeReporter.exe",
        "Description": "Freshservice Discovery Probe telemetry reporter.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\FSProbeCrashStatusUpdater.exe",
        "Description": "Freshservice Discovery Probe crash reporter.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\UninstallStatusUpdater.exe",
        "Description": "Freshservice Discovery Probe uninstall reporter.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\FSScheduler.exe",
        "Description": "Freshservice Discovery Probe scheduler helper (registers scheduled scan tasks).",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\FSWmiScanner.exe",
        "Description": "Freshservice Discovery Probe WMI scanner helper.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\IPRangeCalculator.exe",
        "Description": "Freshservice Discovery Probe IP-range subnet calculator helper.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\plink.exe",
        "Description": "Bundled PuTTY plink 0.62 executable shipped inside the Discovery Probe MSI for SSH-based scanning. Legitimate redistributable, but execution from this path is a Freshservice-specific signal.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\Freshservice.DiscoveryProbe.ScanService.exe.config",
        "Description": ".NET application config file for the FreshServiceScan service.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\Freshservice.DiscoveryProbe.Model.dll",
        "Description": "Freshservice Discovery Probe data-model assembly.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\Freshservice.DiscoveryProbe.PostMan.dll",
        "Description": "Freshservice Discovery Probe HTTP client assembly.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\Freshservice.DiscoveryProbe.GlobalSettings.dll",
        "Description": "Freshservice Discovery Probe settings assembly.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\Freshservice.DiscoveryProbe.Linux.dll",
        "Description": "Freshservice Discovery Probe Linux scanner assembly.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\Freshservice.DiscoveryProbe.Scanner.dll",
        "Description": "Freshservice Discovery Probe primary scanner assembly.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\Freshservice.DiscoveryProbe.UtilitiesWrapper.dll",
        "Description": "Freshservice Discovery Probe utilities wrapper.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\Freshservice.Discovery.SNMP.dll",
        "Description": "Freshservice Discovery Probe SNMP scanner assembly.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\Freshservice.Discovery.Utilities.dll",
        "Description": "Freshservice Discovery shared utilities assembly.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\Freshservice.Integrations.SCCM.dll",
        "Description": "Freshservice Discovery Probe Microsoft SCCM integration assembly (issues SCCM SQL queries on the customer SCCM server).",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\Vim25Service.dll",
        "Description": "VMware vSphere SDK assembly (12.6 MB) shipped inside the Discovery Probe MSI for VMware ESXi/vCenter inventory.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\Renci.SshNet.dll",
        "Description": "Bundled Renci.SshNet 2016.1.0.0 SSH client library used by the Probe for Linux/Unix scans.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\SnmpSharpNet.dll",
        "Description": "Bundled SnmpSharpNet 0.9.5 SNMP client library used by the Probe.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\System.Data.SQLite.dll",
        "Description": "Bundled System.Data.SQLite library used by the Probe for its local discovery DB.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\SQLite.Interop.dll",
        "Description": "Bundled SQLite native interop DLL used by the Probe.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\Microsoft.Win32.TaskScheduler.dll",
        "Description": "Microsoft.Win32.TaskScheduler library used by FSScheduler.exe to register Windows scheduled scan tasks.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\db\\freshservice_discovery.db",
        "Description": "Freshservice Discovery Probe local SQLite database holding scan results and tenant config.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\conf\\Configurations.json",
        "Description": "Freshservice Discovery Probe primary JSON configuration file.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\conf\\fslogger.xml",
        "Description": "log4net config file for the FreshServiceScan service.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\conf\\fsautoupdatelogger.xml",
        "Description": "log4net config file for the AutoUpdate.exe Probe updater.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\nmap\\nmap-service-probes",
        "Description": "Bundled nmap service-probes database (~2.3 MB) shipped inside the Discovery Probe MSI; used by the Probe for service-version detection on customer networks.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\scan\\windows_scripts\\ListADComputers.vbs",
        "Description": "Bundled VBS that enumerates computers from Active Directory; invoked by the Discovery Probe for AD discovery.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\scan\\windows_scripts\\ListDomains.vbs",
        "Description": "Bundled VBS that enumerates domains from Active Directory.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\scan\\windows_scripts\\GetComputerInfo.vbs",
        "Description": "Bundled VBS that gathers per-host computer info (OS, hardware, users) — invoked by the Probe over WMI.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\scan\\unix_scripts\\unix_ssh_scan.sh",
        "Description": "Bundled Bash script that the Probe pushes over SSH to Linux/Unix targets to gather inventory.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\Uninstall.bat",
        "Description": "Freshservice Discovery Probe uninstall helper batch file (shipped inside the Probe MSI).",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\MsiUpdater.vbs",
        "Description": "Freshservice Discovery Probe VBS helper used by AutoUpdate.exe to chain new MSIs via msiexec.",
        "OS": "Windows"
      },
      {
        "File": "FSProbeUninstall.vbs",
        "Description": "VBS uninstall helper observed in VirusTotal as a referrer file for fstools.freshservice.com (community-distributed Probe uninstall script).",
        "OS": "Windows"
      },
      {
        "File": "%PROGRAMFILES(X86)%\\Freshdesk\\Freshservice Discovery Agent\\*",
        "Description": "Catch-all wildcard for the Discovery Agent install directory (32-bit MSI; on x64 Windows it lands under Program Files (x86)).",
        "OS": "Windows"
      },
      {
        "File": "%PROGRAMFILES(X86)%\\Freshworks\\FreshServiceProbe\\*",
        "Description": "Catch-all wildcard for the Discovery Probe install directory.",
        "OS": "Windows"
      },
      {
        "File": "/Applications/Freshservice Discovery Agent.app",
        "Description": "macOS Discovery Agent install location (vendor docs — supported on macOS Catalina through Sequoia/Tahoe; binary names not directly observed).",
        "OS": "macOS"
      },
      {
        "File": "/opt/freshservice/discovery_agent/*",
        "Description": "Inferred Linux Discovery Agent install root based on the vendor's documented Linux install script and .NET 5+ runtime requirement; not directly verified against a Linux build.",
        "OS": "Linux"
      }
    ],
    "EventLog": [
      {
        "EventID": 7045,
        "ProviderName": "Service Control Manager",
        "LogFile": "System.evtx",
        "ServiceName": "FSAgentService",
        "ImagePath": "\"C:\\\\Program Files (x86)\\\\Freshdesk\\\\Freshservice Discovery Agent\\\\FSAgentService.exe\"",
        "Description": "Service installation event raised when the Freshservice Discovery Agent registers its SYSTEM service via AgentInstaller.dll custom action."
      },
      {
        "EventID": 7045,
        "ProviderName": "Service Control Manager",
        "LogFile": "System.evtx",
        "ServiceName": "FreshServiceScan",
        "ImagePath": "\"C:\\\\Program Files (x86)\\\\Freshworks\\\\FreshServiceProbe\\\\bin\\\\Freshservice.DiscoveryProbe.ScanService.exe\"",
        "Description": "Service installation event raised when the Freshservice Discovery Probe registers its SYSTEM scan service. Service name `FreshServiceScan` and binary path confirmed via the ServiceInstall table inside `fs-probe-4.13.0.msi`."
      },
      {
        "EventID": 4697,
        "ProviderName": "Microsoft-Windows-Security-Auditing",
        "LogFile": "Security.evtx",
        "ServiceName": "FSAgentService",
        "ImagePath": "\"C:\\\\Program Files (x86)\\\\Freshdesk\\\\Freshservice Discovery Agent\\\\FSAgentService.exe\"",
        "Description": "Security-log mirror of the FSAgentService service install (4697 fires when service-install auditing is enabled)."
      },
      {
        "EventID": 4697,
        "ProviderName": "Microsoft-Windows-Security-Auditing",
        "LogFile": "Security.evtx",
        "ServiceName": "FreshServiceScan",
        "ImagePath": "\"C:\\\\Program Files (x86)\\\\Freshworks\\\\FreshServiceProbe\\\\bin\\\\Freshservice.DiscoveryProbe.ScanService.exe\"",
        "Description": "Security-log mirror of the FreshServiceScan service install."
      },
      {
        "EventID": 11707,
        "ProviderName": "MsiInstaller",
        "LogFile": "Application.evtx",
        "Data": "Product: Freshservice Discovery Agent -- Installation completed successfully.",
        "Description": "MsiInstaller success event for the Freshservice Discovery Agent MSI (`fs-windows-agent-*.msi`). ProductName = \"Freshservice Discovery Agent\" confirmed in the MSI Property table."
      },
      {
        "EventID": 11707,
        "ProviderName": "MsiInstaller",
        "LogFile": "Application.evtx",
        "Data": "Product: FreshService Probe -- Installation completed successfully.",
        "Description": "MsiInstaller success event for the Freshservice Discovery Probe MSI (`fs-probe-*.msi`). ProductName = \"FreshService Probe\" confirmed in the MSI Property table."
      },
      {
        "EventID": 4688,
        "ProviderName": "Microsoft-Windows-Security-Auditing",
        "LogFile": "Security.evtx",
        "CommandLine": "msiexec /i \\\\<share>\\\\FSAgent.msi REGISTRATIONTOKEN=\"<tenant-token>\"",
        "Description": "Vendor-documented msiexec command used to install the Discovery Agent silently; the REGISTRATIONTOKEN parameter binds the install to a specific Freshservice tenant. PROXYSERVER/PROXYPORT/PROXYUSERNAME/PROXYPASSWORD parameters may also appear on the command line in clear text."
      },
      {
        "EventID": 4688,
        "ProviderName": "Microsoft-Windows-Security-Auditing",
        "LogFile": "Security.evtx",
        "CommandLine": "C:\\\\Program Files (x86)\\\\Freshdesk\\\\Freshservice Discovery Agent\\\\FSAgentAutoUpdate.exe",
        "Description": "Process-creation event for the Discovery Agent auto-updater reaching out to fstools.freshservice.com to pull a new MSI."
      },
      {
        "EventID": 4688,
        "ProviderName": "Microsoft-Windows-Security-Auditing",
        "LogFile": "Security.evtx",
        "CommandLine": "C:\\\\Program Files (x86)\\\\Freshworks\\\\FreshServiceProbe\\\\bin\\\\plink.exe -ssh <target> -batch ...",
        "Description": "Process-creation event for the bundled PuTTY plink.exe being launched by the Discovery Probe to scan a Linux/Unix host over SSH. Execution of plink.exe from this path is a Freshservice-specific signal (legitimate Probe behaviour, but worth tagging)."
      }
    ],
    "Registry": [
      {
        "Path": "HKLM\\SYSTEM\\CurrentControlSet\\Services\\FSAgentService",
        "Description": "Freshservice Discovery Agent SYSTEM service registration."
      },
      {
        "Path": "HKLM\\SYSTEM\\CurrentControlSet\\Services\\FreshServiceScan",
        "Description": "Freshservice Discovery Probe SYSTEM service registration (image `Freshservice.DiscoveryProbe.ScanService.exe`, LocalSystem, Automatic)."
      },
      {
        "Path": "HKLM\\SOFTWARE\\Freshdesk\\FSAgent",
        "Description": "Freshservice Discovery Agent tenant configuration root. Registry values include `InstallDir`, `ProductCode`, `Version`, `AccountURI`, `RegistrationKey`, `ProxyServer`, `ProxyPort`, `ProxyUserName`, `ProxyPassword`. Confirmed via the Registry table inside `fs-windows-agent-3.10.0.msi`."
      },
      {
        "Path": "HKLM\\SOFTWARE\\WOW6432Node\\Freshdesk\\FSAgent",
        "Description": "Freshservice Discovery Agent tenant configuration root on x64 Windows (the Agent MSI is x86, so HKLM\\SOFTWARE\\Freshdesk\\FSAgent is reflected here). Same value names as above."
      },
      {
        "Path": "HKLM\\SOFTWARE\\Freshworks\\FreshServiceProbe",
        "Description": "Freshservice Discovery Probe tenant configuration root. Registry values include `INSTALLDIR`, `ProductCode`, `Version`, and `RegistrationKey` — the latter is a JWT (e.g. `eyJ...` decoding to `{\"portal_url\":\"https://<tenant>.freshservice.com\"}`). Confirmed via the Registry table inside `fs-probe-4.13.0.msi`."
      },
      {
        "Path": "HKLM\\SOFTWARE\\WOW6432Node\\Freshworks\\FreshServiceProbe",
        "Description": "Freshservice Discovery Probe tenant configuration root on x64 Windows."
      },
      {
        "Path": "HKLM\\SOFTWARE\\Microsoft\\FreshService Probe",
        "Description": "Freshservice Discovery Probe Start-Menu shortcut bookkeeping key (`installed=1`). Created by the ApplicationShortcut component of the Probe MSI."
      },
      {
        "Path": "HKLM\\SOFTWARE\\FreshService Probe",
        "Description": "Freshservice Discovery Probe Desktop-shortcut bookkeeping key (`installed=1`). Created by the ApplicationDesktopShortcut component of the Probe MSI."
      },
      {
        "Path": "HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{8BE075F9-36C7-4145-8BC0-35D420223576}",
        "Description": "Discovery Agent ARP/Uninstall entry. ProductCode UUID confirmed via msiinfo against `fs-windows-agent-3.10.0.msi` (UpgradeCode {6B686B63-A11D-42DE-9678-01FE705125C7}); per-version ProductCodes will differ across releases."
      },
      {
        "Path": "HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\{892D2C60-AFC1-48C0-8C5D-A2DC856A3605}",
        "Description": "Discovery Probe ARP/Uninstall entry. ProductCode UUID confirmed via msiinfo against `fs-probe-4.13.0.msi` (UpgradeCode {82E36A19-1271-4411-ACEC-7BBE4B6BD17A}); per-version ProductCodes will differ across releases."
      }
    ],
    "Network": [
      {
        "Description": "Freshservice Discovery Agent + Discovery Probe MSI distribution and auto-update host (fs-windows-agent-*.msi, win-installer-*.msi, fs-probe-*.msi, AutoUpdate.exe, FSAgentAutoUpdate.exe); served over CloudFront. URL pattern confirmed via VirusTotal in-the-wild URLs for SHA256 773f976170f87167d63d55bf83c5f3853d3f10f01dd627ab3dfe0f02b6f25d48 (https://fstools.freshservice.com/agent/win-installer-3.10.0.msi).",
        "Domains": [
          "fstools.freshservice.com"
        ],
        "Ports": [
          443
        ]
      },
      {
        "Description": "Per-tenant Freshservice ITSM portal that the Discovery Agent and Discovery Probe report inventory back to (the Probe RegistrationKey JWT decodes to a portal_url payload pointing at https://<tenant>.freshservice.com).",
        "Domains": [
          "*.freshservice.com"
        ],
        "Ports": [
          443
        ]
      },
      {
        "Description": "Freshservice corporate / marketing site referenced in the Discovery Agent and Probe MSIs.",
        "Domains": [
          "freshservice.com",
          "www.freshservice.com"
        ],
        "Ports": [
          443
        ]
      },
      {
        "Description": "Legacy Freshservice Discovery infrastructure embedded in the Probe binary (`Freshservice.DiscoveryProbe.Window.exe` references `fstools.freshasset.com`); freshasset.com is a Freshworks-owned Amazon-Registrar-registered domain still used as a fallback distribution / discovery host.",
        "Domains": [
          "fstools.freshasset.com",
          "freshasset.com"
        ],
        "Ports": [
          443
        ]
      },
      {
        "Description": "Freshworks platform identity/SSO and unified Freshworks API; the Freshservice tenant authentication flow and embedded Marketplace iframes load from these domains (browser-side; not invoked by the Discovery Agent service itself).",
        "Domains": [
          "*.myfreshworks.com",
          "*.freshworksapi.com",
          "*.freshworks.com"
        ],
        "Ports": [
          443
        ]
      },
      {
        "Description": "Freshconnect collaboration (Freshworks-owned), used by the Freshservice agent web UI for in-ticket chat. Browser-side only.",
        "Domains": [
          "*.freshconnect.io",
          "api.fdcollab.com",
          "*.fdcollab.com"
        ],
        "Ports": [
          443
        ]
      },
      {
        "Description": "Freshchat / push notification infrastructure used by the Freshservice agent web UI. Browser-side only.",
        "Domains": [
          "*.freshchat.com",
          "*.webpush.freshchat.com",
          "apicdn-wchat.freshchat.com",
          "*.rtschannel.com"
        ],
        "Ports": [
          443
        ]
      },
      {
        "Description": "Freshworks Marketplace integration host serving Freshservice tenant customizations and Freddy AI assets. Browser-side only.",
        "Domains": [
          "*.freshdev.io",
          "static.freshdev.io",
          "*.freshcloud.io",
          "*.in-freshbots.ai"
        ],
        "Ports": [
          443
        ]
      },
      {
        "Description": "Discovery Probe network sweep — the Probe initiates outbound TCP scans against customer-internal IPs on the documented discovery ports for fingerprinting (135/RPC, 445/SMB, 22/SSH, 161/SNMP). Source: vendor doc \"Software requirements for Discovery Probe\".",
        "Domains": [
          "<internal-customer-ranges>"
        ],
        "Ports": [
          22,
          135,
          161,
          445
        ]
      },
      {
        "Description": "Discovery Probe SNMP polling (UDP/161 outbound to managed network devices for OID walks via SnmpSharpNet.dll).",
        "Domains": [
          "<internal-customer-ranges>"
        ],
        "Ports": [
          161
        ]
      }
    ],
    "Other": [
      {
        "Type": "URL",
        "Value": "https://fstools.freshservice.com/agent/win-installer-3.10.0.msi"
      },
      {
        "Type": "URL",
        "Value": "https://fstools.freshservice.com/agent/win-installer-3.7.0.msi"
      },
      {
        "Type": "URL",
        "Value": "https://fstools.freshservice.com/fs-windows-agent-3.10.0.msi"
      },
      {
        "Type": "URL",
        "Value": "https://fstools.freshservice.com/fs-windows-agent-3.5.0.msi"
      },
      {
        "Type": "URL",
        "Value": "https://fstools.freshservice.com/fs-probe-4.13.0.msi"
      },
      {
        "Type": "URL",
        "Value": "https://fstools.freshservice.com/fs-probe-4.4.0-betfairhelpdesk.msi"
      },
      {
        "Type": "SHA256",
        "Value": "773f976170f87167d63d55bf83c5f3853d3f10f01dd627ab3dfe0f02b6f25d48"
      },
      {
        "Type": "SHA256",
        "Value": "20ca682b3485bc5e9b407749fbc42c7b4148c3d6f00c17eab52e9a85bcc1e299"
      },
      {
        "Type": "SHA256",
        "Value": "ae7da71392831894071da4464588713db5fb3babdf5f1d0d88ae7927d3c19179"
      },
      {
        "Type": "SHA256",
        "Value": "16bdb59cb9772a6b8d430d7bc4811c89548aa68aeb833b41f49ce58efcaad48a"
      },
      {
        "Type": "CodeSigningSubject",
        "Value": "CN=Freshworks Inc"
      },
      {
        "Type": "CodeSigningIssuer",
        "Value": "DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1"
      },
      {
        "Type": "ProductCode",
        "Value": "{8BE075F9-36C7-4145-8BC0-35D420223576} (Freshservice Discovery Agent 3.10.0; UpgradeCode {6B686B63-A11D-42DE-9678-01FE705125C7}; per-version ProductCode — do not pin)"
      },
      {
        "Type": "ProductCode",
        "Value": "{892D2C60-AFC1-48C0-8C5D-A2DC856A3605} (FreshService Probe 4.13.0; UpgradeCode {82E36A19-1271-4411-ACEC-7BBE4B6BD17A}; per-version ProductCode — do not pin)"
      }
    ]
  },
  "Detections": [
    {
      "Sigma": "https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/freshservice_files_sigma.yml",
      "Description": "Detects potential files activity of Freshservice RMM tool"
    },
    {
      "Sigma": "https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/freshservice_network_sigma.yml",
      "Description": "Detects potential network activity of Freshservice RMM tool"
    },
    {
      "Sigma": "https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/freshservice_processes_sigma.yml",
      "Description": "Detects potential processes activity of Freshservice RMM tool"
    },
    {
      "Sigma": "https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/freshservice_registry_sigma.yml",
      "Description": "Detects potential registry activity of Freshservice RMM tool"
    }
  ],
  "References": [
    "https://www.freshworks.com/freshservice/",
    "https://support.freshservice.com/support/solutions/articles/200393-freshservice-discovery-agent",
    "https://support.freshservice.com/support/solutions/articles/223635-installing-discovery-agent-windows-",
    "https://support.freshservice.com/support/solutions/articles/199849-installing-discovery-agent-win-in-a-domain-using-gpo-",
    "https://support.freshservice.com/support/solutions/articles/199805-installing-discovery-agent-win-in-a-workgroup-using-psexec-",
    "https://support.freshservice.com/support/solutions/articles/158679-freshservice-discovery-probe",
    "https://support.freshservice.com/support/solutions/articles/158680-downloading-and-installing-the-discovery-probe",
    "https://support.freshservice.com/support/solutions/articles/158681-configuring-the-discovery-probe",
    "https://support.freshservice.com/support/solutions/articles/50000004929-software-requirements-for-discovery-probe",
    "https://support.freshservice.com/support/solutions/articles/50000004074-about-discovery-probe-security",
    "https://support.freshservice.com/support/solutions/articles/234412-freshdesk-domains-to-whitelist-in-your-firewall",
    "https://www.virustotal.com/gui/file/773f976170f87167d63d55bf83c5f3853d3f10f01dd627ab3dfe0f02b6f25d48",
    "https://www.virustotal.com/gui/file/20ca682b3485bc5e9b407749fbc42c7b4148c3d6f00c17eab52e9a85bcc1e299",
    "https://www.virustotal.com/gui/file/ae7da71392831894071da4464588713db5fb3babdf5f1d0d88ae7927d3c19179",
    "https://www.virustotal.com/gui/file/16bdb59cb9772a6b8d430d7bc4811c89548aa68aeb833b41f49ce58efcaad48a",
    "https://www.virustotal.com/gui/domain/fstools.freshservice.com",
    "https://www.virustotal.com/gui/domain/freshservice.com"
  ],
  "Acknowledgement": [
    {
      "Person": "Michael Haag",
      "Handle": "@M_haggis"
    }
  ]
}