RMM

Freshservice

Freshservice is a SaaS IT Service Management (ITSM) platform from Freshworks Inc. that includes a built-in asset discovery and management capability via two endpoint agents distributed by Freshworks: the **Freshservice Discovery Agent** (FSAgent — installed per-endpoint, gathers hardware/software inventory and reports back to a tenant Freshservice URL) and the **Freshservice Discovery Probe** (a Windows scanning station that performs network-wide discovery via WMI/SSH/SNMP using bundled nmap, plink, Renci.SshNet and SNMP libraries). Both are MSI installers signed by "Freshworks Inc" (DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1) and downloaded from `fstools.freshservice.com/agent/` (Discovery Agent) or from the tenant Discovery Hub (Probe). The Discovery Agent registers a SYSTEM Windows service (`FSAgentService`), drops `FSAgentAutoUpdate.exe` (a Freshworks auto-updater that pulls new agent versions from `fstools.freshservice.com`), and persists tenant configuration (account URI + registration key + optional proxy credentials) under `HKLM\SOFTWARE\Freshdesk\FSAgent` (or `HKLM\SOFTWARE\WOW6432Node\Freshdesk\FSAgent` on x64). The Probe registers a SYSTEM Windows service (`FreshServiceScan`, image `Freshservice.DiscoveryProbe.ScanService.exe`), bundles a substantial network-scanning toolkit (nmap, plink/PuTTY, Renci.SshNet, SnmpSharpNet, Vim25Service, .NET TaskScheduler, SQLite), and stores its tenant config under `HKLM\SOFTWARE\Freshworks\FreshServiceProbe` including a JWT-style `RegistrationKey` value pointing at the tenant `*.freshservice.com` portal. Operationally relevant for defenders: the Discovery Agent provides a SYSTEM autostart service with auto-update from a vendor-controlled Freshworks domain on every Windows endpoint where it is deployed; the Probe ships and registers `plink.exe`, `nmap` and `nmap-service-probes`, full Vim25/VMware vSphere SDK bindings and a Renci SSH library — and is intended to perform credentialed sweeps of the entire network including SCCM (`Freshservice.Integrations.SCCM.dll`) and Active Directory (`ListADComputers.vbs`). Both components have been observed in incidents where a threat actor signs up for a Freshservice trial tenant and pushes the legitimately-signed Freshworks installer to victim hosts to gain a SYSTEM-level remote inventory/management foothold without tripping signature-based EDR. The cloud SaaS portion (`<tenant>.freshservice.com`, `myfreshworks.com`, `freshworksapi.com`, `freshconnect.io`) and the Freshworks "Switchboard"/Freddy AI features are pure browser-side and do not drop endpoint artifacts; only the Discovery Agent and Discovery Probe install local services.

Tool overview

Category
RMM
Research authors
@MHaggis
Created
2026-05-04
Last modified
2026-05-04
Privileges
SYSTEM
Free / availability
14-day trial; paid SaaS subscription
Verification required
Tenant signup with email; corporate email accepted but not strictly enforced. Discovery Agent / Probe installers are tenant-bound via REGISTRATIONTOKEN (Agent) or a JWT-style RegistrationKey embedded in the Probe MSI (e.g. payload `{"portal_url":"https://<tenant>.freshservice.com"}`).
Supported platforms
LinuxWindowsmacOS

Capabilities

IT Service Management (ITSM) ticketing and helpdeskSYSTEM-level endpoint inventory via Discovery Agent (per-host MSI; Windows / macOS / Linux)Network-wide credentialed asset discovery via Discovery Probe (WMI for Windows, SSH for Linux/Mac, SNMP for network gear, VMware vSphere via Vim25Service.dll)Active Directory enumeration (bundled `ListADComputers.vbs`, `ListDomains.vbs`)Microsoft SCCM integration (`Freshservice.Integrations.SCCM.dll`)Bundled offensive-adjacent toolset shipped inside the Probe MSI (nmap service probe DB, plink.exe / PuTTY, Renci.SshNet, SnmpSharpNet)Auto-update of agent + probe binaries from fstools.freshservice.com without admin interactionTenant-side remote workflow / orchestration (Freshservice Workflow Automator) and Freddy AIAsset CMDB with per-endpoint hardware/software inventory and software metering

Executables & installation paths

Filename
FSAgentService.exe
OriginalFileName
FSAgentService.exe
Description
Freshservice Discovery Agent SYSTEM service (.NET, signed by "Freshworks Inc"; registers as Windows service `FSAgentService` and runs as LocalSystem)
Filename
FSAgentAutoUpdate.exe
OriginalFileName
FSAgentAutoUpdate.exe
Description
Freshservice Discovery Agent auto-updater (.NET, signed by "Freshworks Inc"; pulls new agent MSIs from fstools.freshservice.com)
Filename
FSAgentCrashStatusUpdater.exe
OriginalFileName
FSAgentCrashStatusUpdater.exe
Description
Freshservice Discovery Agent crash reporter (.NET, signed by "Freshworks Inc")
Filename
FSWmiScanner.exe
OriginalFileName
FSWmiScanner.exe
Description
Freshservice WMI inventory helper invoked by the Discovery Agent / Probe (.NET, signed by "Freshworks Inc")
Filename
AgentInstaller.dll
OriginalFileName
AgentInstaller.dll
Description
Freshservice Discovery Agent custom-action DLL (.NET, runs the FSAgentService install/uninstall via msiexec)
Filename
Freshservice.DiscoveryProbe.Window.exe
OriginalFileName
Freshservice.DiscoveryProbe.Window.exe
Description
Freshservice Discovery Probe tray application (.NET, ConfuserEx-packed, signed by "Freshworks Inc"; references fstools.freshservice.com and the legacy fstools.freshasset.com)
Filename
Freshservice.DiscoveryProbe.ScanService.exe
OriginalFileName
Freshservice.DiscoveryProbe.ScanService.exe
Description
Freshservice Discovery Probe SYSTEM scan service binary (registered as Windows service `FreshServiceScan`, LocalSystem, Automatic startup)
Filename
Freshservice.DiscoveryProbe.AutoFlush.exe
OriginalFileName
Freshservice.DiscoveryProbe.AutoFlush.exe
Description
Freshservice Discovery Probe scheduled flush helper
Filename
Freshservice.DiscoveryProbe.OIDLibraryPuller.exe
OriginalFileName
Freshservice.DiscoveryProbe.OIDLibraryPuller.exe
Description
Freshservice Discovery Probe SNMP OID library updater
Filename
Freshservice.DiscoveryProbe.ProgressBar.exe
OriginalFileName
Freshservice.DiscoveryProbe.ProgressBar.exe
Description
Freshservice Discovery Probe scan progress UI helper
Filename
AutoUpdate.exe
OriginalFileName
AutoUpdate.exe
Description
Freshservice Discovery Probe auto-updater (.NET, signed by "Freshworks Inc"; pulls new probe MSIs from fstools.freshservice.com)
Filename
FSProbeReporter.exe
OriginalFileName
FSProbeReporter.exe
Description
Freshservice Discovery Probe telemetry reporter
Filename
FSProbeCrashStatusUpdater.exe
OriginalFileName
FSProbeCrashStatusUpdater.exe
Description
Freshservice Discovery Probe crash reporter
Filename
FSScheduler.exe
OriginalFileName
FSScheduler.exe
Description
Freshservice Discovery Probe scheduler helper (uses Microsoft.Win32.TaskScheduler.dll to register Windows scheduled tasks)
Filename
IPRangeCalculator.exe
OriginalFileName
IPRangeCalculator.exe
Description
Freshservice Discovery Probe IP-range subnet calculator
Filename
UninstallStatusUpdater.exe
OriginalFileName
UninstallStatusUpdater.exe
Description
Freshservice Discovery Probe uninstall reporter
Filename
plink.exe
OriginalFileName
plink.exe
Description
PuTTY plink.exe (PuTTY 0.62) bundled inside the Freshservice Discovery Probe MSI for SSH-based scanning of Linux/Unix hosts (legitimate redistributable, but executes from the Freshservice install dir)

Installation paths

C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\*
C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\bin\*
C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\conf\*
C:\Program Files (x86)\Freshworks\FreshServiceProbe\*
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\*
C:\Program Files (x86)\Freshworks\FreshServiceProbe\conf\*
C:\Program Files (x86)\Freshworks\FreshServiceProbe\db\*
C:\Program Files (x86)\Freshworks\FreshServiceProbe\nmap\*
C:\Program Files (x86)\Freshworks\FreshServiceProbe\tools\ssh\*
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.DiscoveryProbe.ScanService.exe
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.DiscoveryProbe.Window.exe
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\plink.exe
C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\FSAgentService.exe
C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\FSAgentAutoUpdate.exe
*\FSAgentService.exe
*\FSAgentAutoUpdate.exe
*\FSWmiScanner.exe
*\Freshservice.DiscoveryProbe.Window.exe
*\Freshservice.DiscoveryProbe.ScanService.exe
fs-windows-agent-*.msi
win-installer-*.msi
fs-probe-*.msi
FSAgent.msi

FORENSIC EVIDENCE

Disk artifacts

File
C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\FSAgentService.exe
Description
Freshservice Discovery Agent SYSTEM service binary (registered as Windows service `FSAgentService`). Confirmed via `fs-windows-agent-3.10.0.msi` File table and CAPE Sandbox of SHA256 773f976170f87167d63d55bf83c5f3853d3f10f01dd627ab3dfe0f02b6f25d48.
OS
Windows
File
C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\FSAgentAutoUpdate.exe
Description
Freshservice Discovery Agent auto-updater binary; pulls new MSIs from fstools.freshservice.com.
OS
Windows
File
C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\FSAgentCrashStatusUpdater.exe
Description
Freshservice Discovery Agent crash reporter binary.
OS
Windows
File
C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\FSWmiScanner.exe
Description
Freshservice WMI scanner helper invoked by FSAgentService.
OS
Windows
File
C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\AgentInstaller.dll
Description
Freshservice Discovery Agent custom-action DLL responsible for installing/uninstalling the `FSAgentService` Windows service via msiexec.
OS
Windows
File
C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\FSUtil.dll
Description
Freshservice Discovery Agent shared utility library.
OS
Windows
File
C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\Newtonsoft.Json.dll
Description
Bundled JSON.NET library shipped inside the Discovery Agent MSI.
OS
Windows
File
C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\log4net.dll
Description
Bundled log4net library shipped inside the Discovery Agent MSI.
OS
Windows
File
C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\Microsoft.Win32.TaskScheduler.dll
Description
Microsoft.Win32.TaskScheduler library shipped inside the Discovery Agent MSI; used to register scheduled tasks for inventory cycles.
OS
Windows
File
C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\settings.conf
Description
Freshservice Discovery Agent local config file.
OS
Windows
File
C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\fslogger.xml
Description
log4net configuration file for FSAgentService.
OS
Windows
File
C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\logs\*
Description
Freshservice Discovery Agent log directory (vendor-documented log location for the Windows agent).
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.DiscoveryProbe.ScanService.exe
Description
Freshservice Discovery Probe SYSTEM scan service binary (registered as Windows service `FreshServiceScan`). Confirmed via `fs-probe-4.13.0.msi` ServiceInstall table.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.DiscoveryProbe.Window.exe
Description
Freshservice Discovery Probe tray application; embeds references to fstools.freshservice.com and fstools.freshasset.com.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\AutoUpdate.exe
Description
Freshservice Discovery Probe auto-updater binary.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.DiscoveryProbe.AutoFlush.exe
Description
Freshservice Discovery Probe scheduled flush helper.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.DiscoveryProbe.OIDLibraryPuller.exe
Description
Freshservice Discovery Probe SNMP OID library updater.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.DiscoveryProbe.ProgressBar.exe
Description
Freshservice Discovery Probe scan progress UI helper.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\FSProbeReporter.exe
Description
Freshservice Discovery Probe telemetry reporter.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\FSProbeCrashStatusUpdater.exe
Description
Freshservice Discovery Probe crash reporter.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\UninstallStatusUpdater.exe
Description
Freshservice Discovery Probe uninstall reporter.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\FSScheduler.exe
Description
Freshservice Discovery Probe scheduler helper (registers scheduled scan tasks).
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\FSWmiScanner.exe
Description
Freshservice Discovery Probe WMI scanner helper.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\IPRangeCalculator.exe
Description
Freshservice Discovery Probe IP-range subnet calculator helper.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\plink.exe
Description
Bundled PuTTY plink 0.62 executable shipped inside the Discovery Probe MSI for SSH-based scanning. Legitimate redistributable, but execution from this path is a Freshservice-specific signal.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.DiscoveryProbe.ScanService.exe.config
Description
.NET application config file for the FreshServiceScan service.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.DiscoveryProbe.Model.dll
Description
Freshservice Discovery Probe data-model assembly.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.DiscoveryProbe.PostMan.dll
Description
Freshservice Discovery Probe HTTP client assembly.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.DiscoveryProbe.GlobalSettings.dll
Description
Freshservice Discovery Probe settings assembly.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.DiscoveryProbe.Linux.dll
Description
Freshservice Discovery Probe Linux scanner assembly.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.DiscoveryProbe.Scanner.dll
Description
Freshservice Discovery Probe primary scanner assembly.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.DiscoveryProbe.UtilitiesWrapper.dll
Description
Freshservice Discovery Probe utilities wrapper.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.Discovery.SNMP.dll
Description
Freshservice Discovery Probe SNMP scanner assembly.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.Discovery.Utilities.dll
Description
Freshservice Discovery shared utilities assembly.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.Integrations.SCCM.dll
Description
Freshservice Discovery Probe Microsoft SCCM integration assembly (issues SCCM SQL queries on the customer SCCM server).
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Vim25Service.dll
Description
VMware vSphere SDK assembly (12.6 MB) shipped inside the Discovery Probe MSI for VMware ESXi/vCenter inventory.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Renci.SshNet.dll
Description
Bundled Renci.SshNet 2016.1.0.0 SSH client library used by the Probe for Linux/Unix scans.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\SnmpSharpNet.dll
Description
Bundled SnmpSharpNet 0.9.5 SNMP client library used by the Probe.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\System.Data.SQLite.dll
Description
Bundled System.Data.SQLite library used by the Probe for its local discovery DB.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\SQLite.Interop.dll
Description
Bundled SQLite native interop DLL used by the Probe.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Microsoft.Win32.TaskScheduler.dll
Description
Microsoft.Win32.TaskScheduler library used by FSScheduler.exe to register Windows scheduled scan tasks.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\db\freshservice_discovery.db
Description
Freshservice Discovery Probe local SQLite database holding scan results and tenant config.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\conf\Configurations.json
Description
Freshservice Discovery Probe primary JSON configuration file.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\conf\fslogger.xml
Description
log4net config file for the FreshServiceScan service.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\conf\fsautoupdatelogger.xml
Description
log4net config file for the AutoUpdate.exe Probe updater.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\nmap\nmap-service-probes
Description
Bundled nmap service-probes database (~2.3 MB) shipped inside the Discovery Probe MSI; used by the Probe for service-version detection on customer networks.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\scan\windows_scripts\ListADComputers.vbs
Description
Bundled VBS that enumerates computers from Active Directory; invoked by the Discovery Probe for AD discovery.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\scan\windows_scripts\ListDomains.vbs
Description
Bundled VBS that enumerates domains from Active Directory.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\scan\windows_scripts\GetComputerInfo.vbs
Description
Bundled VBS that gathers per-host computer info (OS, hardware, users) — invoked by the Probe over WMI.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\scan\unix_scripts\unix_ssh_scan.sh
Description
Bundled Bash script that the Probe pushes over SSH to Linux/Unix targets to gather inventory.
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\Uninstall.bat
Description
Freshservice Discovery Probe uninstall helper batch file (shipped inside the Probe MSI).
OS
Windows
File
C:\Program Files (x86)\Freshworks\FreshServiceProbe\MsiUpdater.vbs
Description
Freshservice Discovery Probe VBS helper used by AutoUpdate.exe to chain new MSIs via msiexec.
OS
Windows
File
FSProbeUninstall.vbs
Description
VBS uninstall helper observed in VirusTotal as a referrer file for fstools.freshservice.com (community-distributed Probe uninstall script).
OS
Windows
File
%PROGRAMFILES(X86)%\Freshdesk\Freshservice Discovery Agent\*
Description
Catch-all wildcard for the Discovery Agent install directory (32-bit MSI; on x64 Windows it lands under Program Files (x86)).
OS
Windows
File
%PROGRAMFILES(X86)%\Freshworks\FreshServiceProbe\*
Description
Catch-all wildcard for the Discovery Probe install directory.
OS
Windows
File
/Applications/Freshservice Discovery Agent.app
Description
macOS Discovery Agent install location (vendor docs — supported on macOS Catalina through Sequoia/Tahoe; binary names not directly observed).
OS
macOS
File
/opt/freshservice/discovery_agent/*
Description
Inferred Linux Discovery Agent install root based on the vendor's documented Linux install script and .NET 5+ runtime requirement; not directly verified against a Linux build.
OS
Linux

FORENSIC EVIDENCE

Event log artifacts

EventID
7045
ProviderName
Service Control Manager
LogFile
System.evtx
ServiceName
FSAgentService
ImagePath
"C:\\Program Files (x86)\\Freshdesk\\Freshservice Discovery Agent\\FSAgentService.exe"
Description
Service installation event raised when the Freshservice Discovery Agent registers its SYSTEM service via AgentInstaller.dll custom action.
EventID
7045
ProviderName
Service Control Manager
LogFile
System.evtx
ServiceName
FreshServiceScan
ImagePath
"C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\Freshservice.DiscoveryProbe.ScanService.exe"
Description
Service installation event raised when the Freshservice Discovery Probe registers its SYSTEM scan service. Service name `FreshServiceScan` and binary path confirmed via the ServiceInstall table inside `fs-probe-4.13.0.msi`.
EventID
4697
ProviderName
Microsoft-Windows-Security-Auditing
LogFile
Security.evtx
ServiceName
FSAgentService
ImagePath
"C:\\Program Files (x86)\\Freshdesk\\Freshservice Discovery Agent\\FSAgentService.exe"
Description
Security-log mirror of the FSAgentService service install (4697 fires when service-install auditing is enabled).
EventID
4697
ProviderName
Microsoft-Windows-Security-Auditing
LogFile
Security.evtx
ServiceName
FreshServiceScan
ImagePath
"C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\Freshservice.DiscoveryProbe.ScanService.exe"
Description
Security-log mirror of the FreshServiceScan service install.
EventID
11707
ProviderName
MsiInstaller
LogFile
Application.evtx
Data
Product: Freshservice Discovery Agent -- Installation completed successfully.
Description
MsiInstaller success event for the Freshservice Discovery Agent MSI (`fs-windows-agent-*.msi`). ProductName = "Freshservice Discovery Agent" confirmed in the MSI Property table.
EventID
11707
ProviderName
MsiInstaller
LogFile
Application.evtx
Data
Product: FreshService Probe -- Installation completed successfully.
Description
MsiInstaller success event for the Freshservice Discovery Probe MSI (`fs-probe-*.msi`). ProductName = "FreshService Probe" confirmed in the MSI Property table.
EventID
4688
ProviderName
Microsoft-Windows-Security-Auditing
LogFile
Security.evtx
CommandLine
msiexec /i \\<share>\\FSAgent.msi REGISTRATIONTOKEN="<tenant-token>"
Description
Vendor-documented msiexec command used to install the Discovery Agent silently; the REGISTRATIONTOKEN parameter binds the install to a specific Freshservice tenant. PROXYSERVER/PROXYPORT/PROXYUSERNAME/PROXYPASSWORD parameters may also appear on the command line in clear text.
EventID
4688
ProviderName
Microsoft-Windows-Security-Auditing
LogFile
Security.evtx
CommandLine
C:\\Program Files (x86)\\Freshdesk\\Freshservice Discovery Agent\\FSAgentAutoUpdate.exe
Description
Process-creation event for the Discovery Agent auto-updater reaching out to fstools.freshservice.com to pull a new MSI.
EventID
4688
ProviderName
Microsoft-Windows-Security-Auditing
LogFile
Security.evtx
CommandLine
C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\plink.exe -ssh <target> -batch ...
Description
Process-creation event for the bundled PuTTY plink.exe being launched by the Discovery Probe to scan a Linux/Unix host over SSH. Execution of plink.exe from this path is a Freshservice-specific signal (legitimate Probe behaviour, but worth tagging).

FORENSIC EVIDENCE

Registry artifacts

Path
HKLM\SYSTEM\CurrentControlSet\Services\FSAgentService
Description
Freshservice Discovery Agent SYSTEM service registration.
Path
HKLM\SYSTEM\CurrentControlSet\Services\FreshServiceScan
Description
Freshservice Discovery Probe SYSTEM service registration (image `Freshservice.DiscoveryProbe.ScanService.exe`, LocalSystem, Automatic).
Path
HKLM\SOFTWARE\Freshdesk\FSAgent
Description
Freshservice Discovery Agent tenant configuration root. Registry values include `InstallDir`, `ProductCode`, `Version`, `AccountURI`, `RegistrationKey`, `ProxyServer`, `ProxyPort`, `ProxyUserName`, `ProxyPassword`. Confirmed via the Registry table inside `fs-windows-agent-3.10.0.msi`.
Path
HKLM\SOFTWARE\WOW6432Node\Freshdesk\FSAgent
Description
Freshservice Discovery Agent tenant configuration root on x64 Windows (the Agent MSI is x86, so HKLM\SOFTWARE\Freshdesk\FSAgent is reflected here). Same value names as above.
Path
HKLM\SOFTWARE\Freshworks\FreshServiceProbe
Description
Freshservice Discovery Probe tenant configuration root. Registry values include `INSTALLDIR`, `ProductCode`, `Version`, and `RegistrationKey` — the latter is a JWT (e.g. `eyJ...` decoding to `{"portal_url":"https://<tenant>.freshservice.com"}`). Confirmed via the Registry table inside `fs-probe-4.13.0.msi`.
Path
HKLM\SOFTWARE\WOW6432Node\Freshworks\FreshServiceProbe
Description
Freshservice Discovery Probe tenant configuration root on x64 Windows.
Path
HKLM\SOFTWARE\Microsoft\FreshService Probe
Description
Freshservice Discovery Probe Start-Menu shortcut bookkeeping key (`installed=1`). Created by the ApplicationShortcut component of the Probe MSI.
Path
HKLM\SOFTWARE\FreshService Probe
Description
Freshservice Discovery Probe Desktop-shortcut bookkeeping key (`installed=1`). Created by the ApplicationDesktopShortcut component of the Probe MSI.
Path
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8BE075F9-36C7-4145-8BC0-35D420223576}
Description
Discovery Agent ARP/Uninstall entry. ProductCode UUID confirmed via msiinfo against `fs-windows-agent-3.10.0.msi` (UpgradeCode {6B686B63-A11D-42DE-9678-01FE705125C7}); per-version ProductCodes will differ across releases.
Path
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{892D2C60-AFC1-48C0-8C5D-A2DC856A3605}
Description
Discovery Probe ARP/Uninstall entry. ProductCode UUID confirmed via msiinfo against `fs-probe-4.13.0.msi` (UpgradeCode {82E36A19-1271-4411-ACEC-7BBE4B6BD17A}); per-version ProductCodes will differ across releases.

FORENSIC EVIDENCE

Network artifacts

Description
Freshservice Discovery Agent + Discovery Probe MSI distribution and auto-update host (fs-windows-agent-*.msi, win-installer-*.msi, fs-probe-*.msi, AutoUpdate.exe, FSAgentAutoUpdate.exe); served over CloudFront. URL pattern confirmed via VirusTotal in-the-wild URLs for SHA256 773f976170f87167d63d55bf83c5f3853d3f10f01dd627ab3dfe0f02b6f25d48 (https://fstools.freshservice.com/agent/win-installer-3.10.0.msi).
Domains
  • fstools.freshservice.com
Ports
  • 443
Description
Per-tenant Freshservice ITSM portal that the Discovery Agent and Discovery Probe report inventory back to (the Probe RegistrationKey JWT decodes to a portal_url payload pointing at https://<tenant>.freshservice.com).
Domains
  • *.freshservice.com
Ports
  • 443
Description
Freshservice corporate / marketing site referenced in the Discovery Agent and Probe MSIs.
Domains
  • freshservice.com
  • www.freshservice.com
Ports
  • 443
Description
Legacy Freshservice Discovery infrastructure embedded in the Probe binary (`Freshservice.DiscoveryProbe.Window.exe` references `fstools.freshasset.com`); freshasset.com is a Freshworks-owned Amazon-Registrar-registered domain still used as a fallback distribution / discovery host.
Domains
  • fstools.freshasset.com
  • freshasset.com
Ports
  • 443
Description
Freshworks platform identity/SSO and unified Freshworks API; the Freshservice tenant authentication flow and embedded Marketplace iframes load from these domains (browser-side; not invoked by the Discovery Agent service itself).
Domains
  • *.myfreshworks.com
  • *.freshworksapi.com
  • *.freshworks.com
Ports
  • 443
Description
Freshconnect collaboration (Freshworks-owned), used by the Freshservice agent web UI for in-ticket chat. Browser-side only.
Domains
  • *.freshconnect.io
  • api.fdcollab.com
  • *.fdcollab.com
Ports
  • 443
Description
Freshchat / push notification infrastructure used by the Freshservice agent web UI. Browser-side only.
Domains
  • *.freshchat.com
  • *.webpush.freshchat.com
  • apicdn-wchat.freshchat.com
  • *.rtschannel.com
Ports
  • 443
Description
Freshworks Marketplace integration host serving Freshservice tenant customizations and Freddy AI assets. Browser-side only.
Domains
  • *.freshdev.io
  • static.freshdev.io
  • *.freshcloud.io
  • *.in-freshbots.ai
Ports
  • 443
Description
Discovery Probe network sweep — the Probe initiates outbound TCP scans against customer-internal IPs on the documented discovery ports for fingerprinting (135/RPC, 445/SMB, 22/SSH, 161/SNMP). Source: vendor doc "Software requirements for Discovery Probe".
Domains
  • <internal-customer-ranges>
Ports
  • 22
  • 135
  • 161
  • 445
Description
Discovery Probe SNMP polling (UDP/161 outbound to managed network devices for OID walks via SnmpSharpNet.dll).
Domains
  • <internal-customer-ranges>
Ports
  • 161

FORENSIC EVIDENCE

Other artifacts

Type
SHA256
Value
773f976170f87167d63d55bf83c5f3853d3f10f01dd627ab3dfe0f02b6f25d48
Type
SHA256
Value
20ca682b3485bc5e9b407749fbc42c7b4148c3d6f00c17eab52e9a85bcc1e299
Type
SHA256
Value
ae7da71392831894071da4464588713db5fb3babdf5f1d0d88ae7927d3c19179
Type
SHA256
Value
16bdb59cb9772a6b8d430d7bc4811c89548aa68aeb833b41f49ce58efcaad48a
Type
CodeSigningSubject
Value
CN=Freshworks Inc
Type
CodeSigningIssuer
Value
DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
Type
ProductCode
Value
{8BE075F9-36C7-4145-8BC0-35D420223576} (Freshservice Discovery Agent 3.10.0; UpgradeCode {6B686B63-A11D-42DE-9678-01FE705125C7}; per-version ProductCode — do not pin)
Type
ProductCode
Value
{892D2C60-AFC1-48C0-8C5D-A2DC856A3605} (FreshService Probe 4.13.0; UpgradeCode {82E36A19-1271-4411-ACEC-7BBE4B6BD17A}; per-version ProductCode — do not pin)

Detections

Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/freshservice_files_sigma.yml
Description
Detects potential files activity of Freshservice RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/freshservice_network_sigma.yml
Description
Detects potential network activity of Freshservice RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/freshservice_processes_sigma.yml
Description
Detects potential processes activity of Freshservice RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/freshservice_registry_sigma.yml
Description
Detects potential registry activity of Freshservice RMM tool

References

Acknowledgements

Person
Michael Haag
Handle
@M_haggis