Freshservice
Freshservice is a SaaS IT Service Management (ITSM) platform from Freshworks Inc. that includes a built-in asset discovery and management capability via two endpoint agents distributed by Freshworks: the **Freshservice Discovery Agent** (FSAgent — installed per-endpoint, gathers hardware/software inventory and reports back to a tenant Freshservice URL) and the **Freshservice Discovery Probe** (a Windows scanning station that performs network-wide discovery via WMI/SSH/SNMP using bundled nmap, plink, Renci.SshNet and SNMP libraries). Both are MSI installers signed by "Freshworks Inc" (DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1) and downloaded from `fstools.freshservice.com/agent/` (Discovery Agent) or from the tenant Discovery Hub (Probe). The Discovery Agent registers a SYSTEM Windows service (`FSAgentService`), drops `FSAgentAutoUpdate.exe` (a Freshworks auto-updater that pulls new agent versions from `fstools.freshservice.com`), and persists tenant configuration (account URI + registration key + optional proxy credentials) under `HKLM\SOFTWARE\Freshdesk\FSAgent` (or `HKLM\SOFTWARE\WOW6432Node\Freshdesk\FSAgent` on x64). The Probe registers a SYSTEM Windows service (`FreshServiceScan`, image `Freshservice.DiscoveryProbe.ScanService.exe`), bundles a substantial network-scanning toolkit (nmap, plink/PuTTY, Renci.SshNet, SnmpSharpNet, Vim25Service, .NET TaskScheduler, SQLite), and stores its tenant config under `HKLM\SOFTWARE\Freshworks\FreshServiceProbe` including a JWT-style `RegistrationKey` value pointing at the tenant `*.freshservice.com` portal. Operationally relevant for defenders: the Discovery Agent provides a SYSTEM autostart service with auto-update from a vendor-controlled Freshworks domain on every Windows endpoint where it is deployed; the Probe ships and registers `plink.exe`, `nmap` and `nmap-service-probes`, full Vim25/VMware vSphere SDK bindings and a Renci SSH library — and is intended to perform credentialed sweeps of the entire network including SCCM (`Freshservice.Integrations.SCCM.dll`) and Active Directory (`ListADComputers.vbs`). Both components have been observed in incidents where a threat actor signs up for a Freshservice trial tenant and pushes the legitimately-signed Freshworks installer to victim hosts to gain a SYSTEM-level remote inventory/management foothold without tripping signature-based EDR. The cloud SaaS portion (`<tenant>.freshservice.com`, `myfreshworks.com`, `freshworksapi.com`, `freshconnect.io`) and the Freshworks "Switchboard"/Freddy AI features are pure browser-side and do not drop endpoint artifacts; only the Discovery Agent and Discovery Probe install local services.
Tool overview
- Category
- RMM
- Research authors
- @MHaggis
- Created
- 2026-05-04
- Last modified
- 2026-05-04
- Privileges
- SYSTEM
- Free / availability
- 14-day trial; paid SaaS subscription
- Verification required
- Tenant signup with email; corporate email accepted but not strictly enforced. Discovery Agent / Probe installers are tenant-bound via REGISTRATIONTOKEN (Agent) or a JWT-style RegistrationKey embedded in the Probe MSI (e.g. payload `{"portal_url":"https://<tenant>.freshservice.com"}`).
- Supported platforms
Linux
Windows
macOS
Capabilities
Executables & installation paths
- Filename
- FSAgentService.exe
- OriginalFileName
- FSAgentService.exe
- Description
- Freshservice Discovery Agent SYSTEM service (.NET, signed by "Freshworks Inc"; registers as Windows service `FSAgentService` and runs as LocalSystem)
- Filename
- FSAgentAutoUpdate.exe
- OriginalFileName
- FSAgentAutoUpdate.exe
- Description
- Freshservice Discovery Agent auto-updater (.NET, signed by "Freshworks Inc"; pulls new agent MSIs from fstools.freshservice.com)
- Filename
- FSAgentCrashStatusUpdater.exe
- OriginalFileName
- FSAgentCrashStatusUpdater.exe
- Description
- Freshservice Discovery Agent crash reporter (.NET, signed by "Freshworks Inc")
- Filename
- FSWmiScanner.exe
- OriginalFileName
- FSWmiScanner.exe
- Description
- Freshservice WMI inventory helper invoked by the Discovery Agent / Probe (.NET, signed by "Freshworks Inc")
- Filename
- AgentInstaller.dll
- OriginalFileName
- AgentInstaller.dll
- Description
- Freshservice Discovery Agent custom-action DLL (.NET, runs the FSAgentService install/uninstall via msiexec)
- Filename
- Freshservice.DiscoveryProbe.Window.exe
- OriginalFileName
- Freshservice.DiscoveryProbe.Window.exe
- Description
- Freshservice Discovery Probe tray application (.NET, ConfuserEx-packed, signed by "Freshworks Inc"; references fstools.freshservice.com and the legacy fstools.freshasset.com)
- Filename
- Freshservice.DiscoveryProbe.ScanService.exe
- OriginalFileName
- Freshservice.DiscoveryProbe.ScanService.exe
- Description
- Freshservice Discovery Probe SYSTEM scan service binary (registered as Windows service `FreshServiceScan`, LocalSystem, Automatic startup)
- Filename
- Freshservice.DiscoveryProbe.AutoFlush.exe
- OriginalFileName
- Freshservice.DiscoveryProbe.AutoFlush.exe
- Description
- Freshservice Discovery Probe scheduled flush helper
- Filename
- Freshservice.DiscoveryProbe.OIDLibraryPuller.exe
- OriginalFileName
- Freshservice.DiscoveryProbe.OIDLibraryPuller.exe
- Description
- Freshservice Discovery Probe SNMP OID library updater
- Filename
- Freshservice.DiscoveryProbe.ProgressBar.exe
- OriginalFileName
- Freshservice.DiscoveryProbe.ProgressBar.exe
- Description
- Freshservice Discovery Probe scan progress UI helper
- Filename
- AutoUpdate.exe
- OriginalFileName
- AutoUpdate.exe
- Description
- Freshservice Discovery Probe auto-updater (.NET, signed by "Freshworks Inc"; pulls new probe MSIs from fstools.freshservice.com)
- Filename
- FSProbeReporter.exe
- OriginalFileName
- FSProbeReporter.exe
- Description
- Freshservice Discovery Probe telemetry reporter
- Filename
- FSProbeCrashStatusUpdater.exe
- OriginalFileName
- FSProbeCrashStatusUpdater.exe
- Description
- Freshservice Discovery Probe crash reporter
- Filename
- FSScheduler.exe
- OriginalFileName
- FSScheduler.exe
- Description
- Freshservice Discovery Probe scheduler helper (uses Microsoft.Win32.TaskScheduler.dll to register Windows scheduled tasks)
- Filename
- IPRangeCalculator.exe
- OriginalFileName
- IPRangeCalculator.exe
- Description
- Freshservice Discovery Probe IP-range subnet calculator
- Filename
- UninstallStatusUpdater.exe
- OriginalFileName
- UninstallStatusUpdater.exe
- Description
- Freshservice Discovery Probe uninstall reporter
- Filename
- plink.exe
- OriginalFileName
- plink.exe
- Description
- PuTTY plink.exe (PuTTY 0.62) bundled inside the Freshservice Discovery Probe MSI for SSH-based scanning of Linux/Unix hosts (legitimate redistributable, but executes from the Freshservice install dir)
Installation paths
FORENSIC EVIDENCE
Disk artifacts
- File
- C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\FSAgentService.exe
- Description
- Freshservice Discovery Agent SYSTEM service binary (registered as Windows service `FSAgentService`). Confirmed via `fs-windows-agent-3.10.0.msi` File table and CAPE Sandbox of SHA256 773f976170f87167d63d55bf83c5f3853d3f10f01dd627ab3dfe0f02b6f25d48.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\FSAgentAutoUpdate.exe
- Description
- Freshservice Discovery Agent auto-updater binary; pulls new MSIs from fstools.freshservice.com.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\FSAgentCrashStatusUpdater.exe
- Description
- Freshservice Discovery Agent crash reporter binary.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\FSWmiScanner.exe
- Description
- Freshservice WMI scanner helper invoked by FSAgentService.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\AgentInstaller.dll
- Description
- Freshservice Discovery Agent custom-action DLL responsible for installing/uninstalling the `FSAgentService` Windows service via msiexec.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\FSUtil.dll
- Description
- Freshservice Discovery Agent shared utility library.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\Newtonsoft.Json.dll
- Description
- Bundled JSON.NET library shipped inside the Discovery Agent MSI.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\log4net.dll
- Description
- Bundled log4net library shipped inside the Discovery Agent MSI.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\Microsoft.Win32.TaskScheduler.dll
- Description
- Microsoft.Win32.TaskScheduler library shipped inside the Discovery Agent MSI; used to register scheduled tasks for inventory cycles.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\settings.conf
- Description
- Freshservice Discovery Agent local config file.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\fslogger.xml
- Description
- log4net configuration file for FSAgentService.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshdesk\Freshservice Discovery Agent\logs\*
- Description
- Freshservice Discovery Agent log directory (vendor-documented log location for the Windows agent).
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.DiscoveryProbe.ScanService.exe
- Description
- Freshservice Discovery Probe SYSTEM scan service binary (registered as Windows service `FreshServiceScan`). Confirmed via `fs-probe-4.13.0.msi` ServiceInstall table.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.DiscoveryProbe.Window.exe
- Description
- Freshservice Discovery Probe tray application; embeds references to fstools.freshservice.com and fstools.freshasset.com.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\AutoUpdate.exe
- Description
- Freshservice Discovery Probe auto-updater binary.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.DiscoveryProbe.AutoFlush.exe
- Description
- Freshservice Discovery Probe scheduled flush helper.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.DiscoveryProbe.OIDLibraryPuller.exe
- Description
- Freshservice Discovery Probe SNMP OID library updater.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.DiscoveryProbe.ProgressBar.exe
- Description
- Freshservice Discovery Probe scan progress UI helper.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\FSProbeReporter.exe
- Description
- Freshservice Discovery Probe telemetry reporter.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\FSProbeCrashStatusUpdater.exe
- Description
- Freshservice Discovery Probe crash reporter.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\UninstallStatusUpdater.exe
- Description
- Freshservice Discovery Probe uninstall reporter.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\FSScheduler.exe
- Description
- Freshservice Discovery Probe scheduler helper (registers scheduled scan tasks).
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\FSWmiScanner.exe
- Description
- Freshservice Discovery Probe WMI scanner helper.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\IPRangeCalculator.exe
- Description
- Freshservice Discovery Probe IP-range subnet calculator helper.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\plink.exe
- Description
- Bundled PuTTY plink 0.62 executable shipped inside the Discovery Probe MSI for SSH-based scanning. Legitimate redistributable, but execution from this path is a Freshservice-specific signal.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.DiscoveryProbe.ScanService.exe.config
- Description
- .NET application config file for the FreshServiceScan service.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.DiscoveryProbe.Model.dll
- Description
- Freshservice Discovery Probe data-model assembly.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.DiscoveryProbe.PostMan.dll
- Description
- Freshservice Discovery Probe HTTP client assembly.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.DiscoveryProbe.GlobalSettings.dll
- Description
- Freshservice Discovery Probe settings assembly.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.DiscoveryProbe.Linux.dll
- Description
- Freshservice Discovery Probe Linux scanner assembly.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.DiscoveryProbe.Scanner.dll
- Description
- Freshservice Discovery Probe primary scanner assembly.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.DiscoveryProbe.UtilitiesWrapper.dll
- Description
- Freshservice Discovery Probe utilities wrapper.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.Discovery.SNMP.dll
- Description
- Freshservice Discovery Probe SNMP scanner assembly.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.Discovery.Utilities.dll
- Description
- Freshservice Discovery shared utilities assembly.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Freshservice.Integrations.SCCM.dll
- Description
- Freshservice Discovery Probe Microsoft SCCM integration assembly (issues SCCM SQL queries on the customer SCCM server).
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Vim25Service.dll
- Description
- VMware vSphere SDK assembly (12.6 MB) shipped inside the Discovery Probe MSI for VMware ESXi/vCenter inventory.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Renci.SshNet.dll
- Description
- Bundled Renci.SshNet 2016.1.0.0 SSH client library used by the Probe for Linux/Unix scans.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\SnmpSharpNet.dll
- Description
- Bundled SnmpSharpNet 0.9.5 SNMP client library used by the Probe.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\System.Data.SQLite.dll
- Description
- Bundled System.Data.SQLite library used by the Probe for its local discovery DB.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\SQLite.Interop.dll
- Description
- Bundled SQLite native interop DLL used by the Probe.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\bin\Microsoft.Win32.TaskScheduler.dll
- Description
- Microsoft.Win32.TaskScheduler library used by FSScheduler.exe to register Windows scheduled scan tasks.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\db\freshservice_discovery.db
- Description
- Freshservice Discovery Probe local SQLite database holding scan results and tenant config.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\conf\Configurations.json
- Description
- Freshservice Discovery Probe primary JSON configuration file.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\conf\fslogger.xml
- Description
- log4net config file for the FreshServiceScan service.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\conf\fsautoupdatelogger.xml
- Description
- log4net config file for the AutoUpdate.exe Probe updater.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\nmap\nmap-service-probes
- Description
- Bundled nmap service-probes database (~2.3 MB) shipped inside the Discovery Probe MSI; used by the Probe for service-version detection on customer networks.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\scan\windows_scripts\ListADComputers.vbs
- Description
- Bundled VBS that enumerates computers from Active Directory; invoked by the Discovery Probe for AD discovery.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\scan\windows_scripts\ListDomains.vbs
- Description
- Bundled VBS that enumerates domains from Active Directory.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\scan\windows_scripts\GetComputerInfo.vbs
- Description
- Bundled VBS that gathers per-host computer info (OS, hardware, users) — invoked by the Probe over WMI.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\scan\unix_scripts\unix_ssh_scan.sh
- Description
- Bundled Bash script that the Probe pushes over SSH to Linux/Unix targets to gather inventory.
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\Uninstall.bat
- Description
- Freshservice Discovery Probe uninstall helper batch file (shipped inside the Probe MSI).
- OS
- Windows
- File
- C:\Program Files (x86)\Freshworks\FreshServiceProbe\MsiUpdater.vbs
- Description
- Freshservice Discovery Probe VBS helper used by AutoUpdate.exe to chain new MSIs via msiexec.
- OS
- Windows
- File
- FSProbeUninstall.vbs
- Description
- VBS uninstall helper observed in VirusTotal as a referrer file for fstools.freshservice.com (community-distributed Probe uninstall script).
- OS
- Windows
- File
- %PROGRAMFILES(X86)%\Freshdesk\Freshservice Discovery Agent\*
- Description
- Catch-all wildcard for the Discovery Agent install directory (32-bit MSI; on x64 Windows it lands under Program Files (x86)).
- OS
- Windows
- File
- %PROGRAMFILES(X86)%\Freshworks\FreshServiceProbe\*
- Description
- Catch-all wildcard for the Discovery Probe install directory.
- OS
- Windows
- File
- /Applications/Freshservice Discovery Agent.app
- Description
- macOS Discovery Agent install location (vendor docs — supported on macOS Catalina through Sequoia/Tahoe; binary names not directly observed).
- OS
- macOS
- File
- /opt/freshservice/discovery_agent/*
- Description
- Inferred Linux Discovery Agent install root based on the vendor's documented Linux install script and .NET 5+ runtime requirement; not directly verified against a Linux build.
- OS
- Linux
FORENSIC EVIDENCE
Event log artifacts
- EventID
- 7045
- ProviderName
- Service Control Manager
- LogFile
- System.evtx
- ServiceName
- FSAgentService
- ImagePath
- "C:\\Program Files (x86)\\Freshdesk\\Freshservice Discovery Agent\\FSAgentService.exe"
- Description
- Service installation event raised when the Freshservice Discovery Agent registers its SYSTEM service via AgentInstaller.dll custom action.
- EventID
- 7045
- ProviderName
- Service Control Manager
- LogFile
- System.evtx
- ServiceName
- FreshServiceScan
- ImagePath
- "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\Freshservice.DiscoveryProbe.ScanService.exe"
- Description
- Service installation event raised when the Freshservice Discovery Probe registers its SYSTEM scan service. Service name `FreshServiceScan` and binary path confirmed via the ServiceInstall table inside `fs-probe-4.13.0.msi`.
- EventID
- 4697
- ProviderName
- Microsoft-Windows-Security-Auditing
- LogFile
- Security.evtx
- ServiceName
- FSAgentService
- ImagePath
- "C:\\Program Files (x86)\\Freshdesk\\Freshservice Discovery Agent\\FSAgentService.exe"
- Description
- Security-log mirror of the FSAgentService service install (4697 fires when service-install auditing is enabled).
- EventID
- 4697
- ProviderName
- Microsoft-Windows-Security-Auditing
- LogFile
- Security.evtx
- ServiceName
- FreshServiceScan
- ImagePath
- "C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\Freshservice.DiscoveryProbe.ScanService.exe"
- Description
- Security-log mirror of the FreshServiceScan service install.
- EventID
- 11707
- ProviderName
- MsiInstaller
- LogFile
- Application.evtx
- Data
- Product: Freshservice Discovery Agent -- Installation completed successfully.
- Description
- MsiInstaller success event for the Freshservice Discovery Agent MSI (`fs-windows-agent-*.msi`). ProductName = "Freshservice Discovery Agent" confirmed in the MSI Property table.
- EventID
- 11707
- ProviderName
- MsiInstaller
- LogFile
- Application.evtx
- Data
- Product: FreshService Probe -- Installation completed successfully.
- Description
- MsiInstaller success event for the Freshservice Discovery Probe MSI (`fs-probe-*.msi`). ProductName = "FreshService Probe" confirmed in the MSI Property table.
- EventID
- 4688
- ProviderName
- Microsoft-Windows-Security-Auditing
- LogFile
- Security.evtx
- CommandLine
- msiexec /i \\<share>\\FSAgent.msi REGISTRATIONTOKEN="<tenant-token>"
- Description
- Vendor-documented msiexec command used to install the Discovery Agent silently; the REGISTRATIONTOKEN parameter binds the install to a specific Freshservice tenant. PROXYSERVER/PROXYPORT/PROXYUSERNAME/PROXYPASSWORD parameters may also appear on the command line in clear text.
- EventID
- 4688
- ProviderName
- Microsoft-Windows-Security-Auditing
- LogFile
- Security.evtx
- CommandLine
- C:\\Program Files (x86)\\Freshdesk\\Freshservice Discovery Agent\\FSAgentAutoUpdate.exe
- Description
- Process-creation event for the Discovery Agent auto-updater reaching out to fstools.freshservice.com to pull a new MSI.
- EventID
- 4688
- ProviderName
- Microsoft-Windows-Security-Auditing
- LogFile
- Security.evtx
- CommandLine
- C:\\Program Files (x86)\\Freshworks\\FreshServiceProbe\\bin\\plink.exe -ssh <target> -batch ...
- Description
- Process-creation event for the bundled PuTTY plink.exe being launched by the Discovery Probe to scan a Linux/Unix host over SSH. Execution of plink.exe from this path is a Freshservice-specific signal (legitimate Probe behaviour, but worth tagging).
FORENSIC EVIDENCE
Registry artifacts
- Path
- HKLM\SYSTEM\CurrentControlSet\Services\FSAgentService
- Description
- Freshservice Discovery Agent SYSTEM service registration.
- Path
- HKLM\SYSTEM\CurrentControlSet\Services\FreshServiceScan
- Description
- Freshservice Discovery Probe SYSTEM service registration (image `Freshservice.DiscoveryProbe.ScanService.exe`, LocalSystem, Automatic).
- Path
- HKLM\SOFTWARE\Freshdesk\FSAgent
- Description
- Freshservice Discovery Agent tenant configuration root. Registry values include `InstallDir`, `ProductCode`, `Version`, `AccountURI`, `RegistrationKey`, `ProxyServer`, `ProxyPort`, `ProxyUserName`, `ProxyPassword`. Confirmed via the Registry table inside `fs-windows-agent-3.10.0.msi`.
- Path
- HKLM\SOFTWARE\WOW6432Node\Freshdesk\FSAgent
- Description
- Freshservice Discovery Agent tenant configuration root on x64 Windows (the Agent MSI is x86, so HKLM\SOFTWARE\Freshdesk\FSAgent is reflected here). Same value names as above.
- Path
- HKLM\SOFTWARE\Freshworks\FreshServiceProbe
- Description
- Freshservice Discovery Probe tenant configuration root. Registry values include `INSTALLDIR`, `ProductCode`, `Version`, and `RegistrationKey` — the latter is a JWT (e.g. `eyJ...` decoding to `{"portal_url":"https://<tenant>.freshservice.com"}`). Confirmed via the Registry table inside `fs-probe-4.13.0.msi`.
- Path
- HKLM\SOFTWARE\WOW6432Node\Freshworks\FreshServiceProbe
- Description
- Freshservice Discovery Probe tenant configuration root on x64 Windows.
- Path
- HKLM\SOFTWARE\Microsoft\FreshService Probe
- Description
- Freshservice Discovery Probe Start-Menu shortcut bookkeeping key (`installed=1`). Created by the ApplicationShortcut component of the Probe MSI.
- Path
- HKLM\SOFTWARE\FreshService Probe
- Description
- Freshservice Discovery Probe Desktop-shortcut bookkeeping key (`installed=1`). Created by the ApplicationDesktopShortcut component of the Probe MSI.
- Path
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8BE075F9-36C7-4145-8BC0-35D420223576}
- Description
- Discovery Agent ARP/Uninstall entry. ProductCode UUID confirmed via msiinfo against `fs-windows-agent-3.10.0.msi` (UpgradeCode {6B686B63-A11D-42DE-9678-01FE705125C7}); per-version ProductCodes will differ across releases.
- Path
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{892D2C60-AFC1-48C0-8C5D-A2DC856A3605}
- Description
- Discovery Probe ARP/Uninstall entry. ProductCode UUID confirmed via msiinfo against `fs-probe-4.13.0.msi` (UpgradeCode {82E36A19-1271-4411-ACEC-7BBE4B6BD17A}); per-version ProductCodes will differ across releases.
FORENSIC EVIDENCE
Network artifacts
- Description
- Freshservice Discovery Agent + Discovery Probe MSI distribution and auto-update host (fs-windows-agent-*.msi, win-installer-*.msi, fs-probe-*.msi, AutoUpdate.exe, FSAgentAutoUpdate.exe); served over CloudFront. URL pattern confirmed via VirusTotal in-the-wild URLs for SHA256 773f976170f87167d63d55bf83c5f3853d3f10f01dd627ab3dfe0f02b6f25d48 (https://fstools.freshservice.com/agent/win-installer-3.10.0.msi).
- Domains
- fstools.freshservice.com
- Ports
- 443
- Description
- Per-tenant Freshservice ITSM portal that the Discovery Agent and Discovery Probe report inventory back to (the Probe RegistrationKey JWT decodes to a portal_url payload pointing at https://<tenant>.freshservice.com).
- Domains
- *.freshservice.com
- Ports
- 443
- Description
- Freshservice corporate / marketing site referenced in the Discovery Agent and Probe MSIs.
- Domains
- freshservice.com
- www.freshservice.com
- Ports
- 443
- Description
- Legacy Freshservice Discovery infrastructure embedded in the Probe binary (`Freshservice.DiscoveryProbe.Window.exe` references `fstools.freshasset.com`); freshasset.com is a Freshworks-owned Amazon-Registrar-registered domain still used as a fallback distribution / discovery host.
- Domains
- fstools.freshasset.com
- freshasset.com
- Ports
- 443
- Description
- Freshworks platform identity/SSO and unified Freshworks API; the Freshservice tenant authentication flow and embedded Marketplace iframes load from these domains (browser-side; not invoked by the Discovery Agent service itself).
- Domains
- *.myfreshworks.com
- *.freshworksapi.com
- *.freshworks.com
- Ports
- 443
- Description
- Freshconnect collaboration (Freshworks-owned), used by the Freshservice agent web UI for in-ticket chat. Browser-side only.
- Domains
- *.freshconnect.io
- api.fdcollab.com
- *.fdcollab.com
- Ports
- 443
- Description
- Freshchat / push notification infrastructure used by the Freshservice agent web UI. Browser-side only.
- Domains
- *.freshchat.com
- *.webpush.freshchat.com
- apicdn-wchat.freshchat.com
- *.rtschannel.com
- Ports
- 443
- Description
- Freshworks Marketplace integration host serving Freshservice tenant customizations and Freddy AI assets. Browser-side only.
- Domains
- *.freshdev.io
- static.freshdev.io
- *.freshcloud.io
- *.in-freshbots.ai
- Ports
- 443
- Description
- Discovery Probe network sweep — the Probe initiates outbound TCP scans against customer-internal IPs on the documented discovery ports for fingerprinting (135/RPC, 445/SMB, 22/SSH, 161/SNMP). Source: vendor doc "Software requirements for Discovery Probe".
- Domains
- <internal-customer-ranges>
- Ports
- 22
- 135
- 161
- 445
- Description
- Discovery Probe SNMP polling (UDP/161 outbound to managed network devices for OID walks via SnmpSharpNet.dll).
- Domains
- <internal-customer-ranges>
- Ports
- 161
FORENSIC EVIDENCE
Other artifacts
- Type
- SHA256
- Value
- 773f976170f87167d63d55bf83c5f3853d3f10f01dd627ab3dfe0f02b6f25d48
- Type
- SHA256
- Value
- 20ca682b3485bc5e9b407749fbc42c7b4148c3d6f00c17eab52e9a85bcc1e299
- Type
- SHA256
- Value
- ae7da71392831894071da4464588713db5fb3babdf5f1d0d88ae7927d3c19179
- Type
- SHA256
- Value
- 16bdb59cb9772a6b8d430d7bc4811c89548aa68aeb833b41f49ce58efcaad48a
- Type
- CodeSigningSubject
- Value
- CN=Freshworks Inc
- Type
- CodeSigningIssuer
- Value
- DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
- Type
- ProductCode
- Value
- {8BE075F9-36C7-4145-8BC0-35D420223576} (Freshservice Discovery Agent 3.10.0; UpgradeCode {6B686B63-A11D-42DE-9678-01FE705125C7}; per-version ProductCode — do not pin)
- Type
- ProductCode
- Value
- {892D2C60-AFC1-48C0-8C5D-A2DC856A3605} (FreshService Probe 4.13.0; UpgradeCode {82E36A19-1271-4411-ACEC-7BBE4B6BD17A}; per-version ProductCode — do not pin)
Detections
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/freshservice_files_sigma.yml
- Description
- Detects potential files activity of Freshservice RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/freshservice_network_sigma.yml
- Description
- Detects potential network activity of Freshservice RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/freshservice_processes_sigma.yml
- Description
- Detects potential processes activity of Freshservice RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/freshservice_registry_sigma.yml
- Description
- Detects potential registry activity of Freshservice RMM tool
References
- https://www.freshworks.com/freshservice/
- https://support.freshservice.com/support/solutions/articles/200393-freshservice-discovery-agent
- https://support.freshservice.com/support/solutions/articles/223635-installing-discovery-agent-windows-
- https://support.freshservice.com/support/solutions/articles/199849-installing-discovery-agent-win-in-a-domain-using-gpo-
- https://support.freshservice.com/support/solutions/articles/199805-installing-discovery-agent-win-in-a-workgroup-using-psexec-
- https://support.freshservice.com/support/solutions/articles/158679-freshservice-discovery-probe
- https://support.freshservice.com/support/solutions/articles/158680-downloading-and-installing-the-discovery-probe
- https://support.freshservice.com/support/solutions/articles/158681-configuring-the-discovery-probe
- https://support.freshservice.com/support/solutions/articles/50000004929-software-requirements-for-discovery-probe
- https://support.freshservice.com/support/solutions/articles/50000004074-about-discovery-probe-security
- https://support.freshservice.com/support/solutions/articles/234412-freshdesk-domains-to-whitelist-in-your-firewall
- https://www.virustotal.com/gui/file/773f976170f87167d63d55bf83c5f3853d3f10f01dd627ab3dfe0f02b6f25d48
- https://www.virustotal.com/gui/file/20ca682b3485bc5e9b407749fbc42c7b4148c3d6f00c17eab52e9a85bcc1e299
- https://www.virustotal.com/gui/file/ae7da71392831894071da4464588713db5fb3babdf5f1d0d88ae7927d3c19179
- https://www.virustotal.com/gui/file/16bdb59cb9772a6b8d430d7bc4811c89548aa68aeb833b41f49ce58efcaad48a
- https://www.virustotal.com/gui/domain/fstools.freshservice.com
- https://www.virustotal.com/gui/domain/freshservice.com
Acknowledgements
- Person
- Michael Haag
- Handle
- @M_haggis