{"id":1335,"date":"2026-09-02T12:02:34","date_gmt":"2026-09-02T06:32:34","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1335"},"modified":"2026-09-03T11:13:14","modified_gmt":"2026-09-03T05:43:14","slug":"faronics-deploy-abuse-screenconnect","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/faronics-deploy-abuse-screenconnect\/","title":{"rendered":"Faronics Deploy Abuse Turns Endpoint Management into an Attack Path"},"content":{"rendered":"<p>Faronics Deploy abuse is a phishing campaign in which attackers trick victims into installing legitimate, signed Faronics Deploy software. The installation enrolls Windows endpoints into attacker-controlled deployments. Attackers can then remotely execute scripts and install ConnectWise ScreenConnect.<\/p>\n<p>Huntress observed Faronics-related lures reaching more than 457 endpoints between July 21 and August 20, 2026. The campaign is notable because attackers do not need a malicious imitation of the management software. Instead, they abuse legitimate administrative capabilities after convincing victims to install the Faronics agent.<\/p>\n<h2>Faronics Deploy Abuse at a Glance<\/h2>\n<table style=\"font-weight: 400; width: 100.381%;\" data-tablestyle=\"MsoNormalTable\" data-tablelook=\"1696\" aria-rowcount=\"11\" aria-colcount=\"2\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td style=\"width: 24.7126%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Detail<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 83.1034%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Information<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td style=\"width: 24.7126%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Campaign<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 83.1034%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Faronics Deploy abuse<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td style=\"width: 24.7126%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Initial access<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 83.1034%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Phishing and social engineering<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td style=\"width: 24.7126%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Abused software<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 83.1034%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Faronics Deploy<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"5\">\n<td style=\"width: 24.7126%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Affected endpoints<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 83.1034%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Windows computers<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"6\">\n<td style=\"width: 24.7126%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Remote execution<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 83.1034%;\" data-celllook=\"0\"><span data-contrast=\"auto\">PowerShell through Faronics deployment functionality<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"7\">\n<td style=\"width: 24.7126%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Secondary remote access<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 83.1034%;\" data-celllook=\"0\"><span data-contrast=\"auto\">ConnectWise ScreenConnect<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"8\">\n<td style=\"width: 24.7126%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Observed period<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 83.1034%;\" data-celllook=\"0\"><span data-contrast=\"auto\">July 21 to August 20, 2026<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"9\">\n<td style=\"width: 24.7126%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Researcher<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 83.1034%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Huntress<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"10\">\n<td style=\"width: 24.7126%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Observed reach<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 83.1034%;\" data-celllook=\"0\"><span data-contrast=\"auto\">More than 457 endpoints\u00a0encountered\u00a0related lures<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"11\">\n<td style=\"width: 24.7126%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Vendor response<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 83.1034%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Faronics implemented\u00a0additional\u00a0anti-abuse measures after\u00a0Huntress\u00a0reported the activity<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>How Phishing Leads to an Attacker-Controlled Faronics Deployment<\/h2>\n<p>The attack begins with phishing emails disguised as familiar business communications. Huntress observed lures involving invoices, tax documents, financial records and other routine files.<\/p>\n<p>When recipients follow the phishing link, the delivery infrastructure profiles the visitor. Huntress found JavaScript collecting information such as the browser User-Agent, platform, screen resolution, time zone, language and touch capabilities.<\/p>\n<p>The infrastructure can use this information to decide what content to display. Potential analysis environments may receive decoy content instead of the campaign workflow.<\/p>\n<p>Selected victims encounter pages imitating familiar services or software. Huntress observed fake Adobe document pages, plugin-update messages and Zoom meeting invitations.<\/p>\n<p>The page then prompts the victim to execute a Faronics-signed installer. Observed filenames included:<\/p>\n<ul>\n<li><code>Adobe.exe<\/code><\/li>\n<li><code>AdobeReader.exe<\/code><\/li>\n<li><code>Invoice_89940.exe<\/code><\/li>\n<\/ul>\n<p>Once executed with administrative privileges, the installer enrolls the Windows endpoint into an attacker-controlled Faronics deployment.<\/p>\n<p>That enrollment is the critical transition in the campaign.<\/p>\n<p>The attacker can now use legitimate Faronics deployment functionality to remotely execute scripts. As a result, subsequent commands do not require the victim to manually execute each payload.<\/p>\n<h2>How Faronics Deploy Chains PowerShell to ScreenConnect<\/h2>\n<p>After enrollment, Huntress repeatedly observed attackers using Faronics Deploy to execute PowerShell on affected endpoints.<\/p>\n<p>The attackers used Faronics deployment functionality to retrieve scripts and additional content from external infrastructure. This included content hosted on GitHub and attacker-controlled servers.<\/p>\n<p>Observed execution and delivery methods included:<\/p>\n<ul>\n<li>PowerShell for executing remotely delivered scripts<\/li>\n<li><code>curl<\/code> for retrieving additional content<\/li>\n<li><code>mshta<\/code> for loading additional content<\/li>\n<li><code>msiexec<\/code> for installing software from remote infrastructure<\/li>\n<li>GitHub as an external staging location<\/li>\n<\/ul>\n<p>The scripts subsequently installed ConnectWise ScreenConnect, a legitimate remote-support application.<\/p>\n<p>ScreenConnect provided another remote-access mechanism independent of Faronics. Therefore, removing an unauthorized Faronics installation alone may not eliminate every remote-access path established during the incident.<\/p>\n<p>ScreenConnect itself is not malware. The security issue is its unauthorized installation and malicious use as a remote-access tool.<\/p>\n<p>This distinction matters for defenders. Legitimate software may not trigger the same assumptions as an unfamiliar malicious executable. Consequently, organizations need to distinguish approved remote-management tools from unexpected installations.<\/p>\n<h2>How to Investigate Faronics Deploy Abuse on Affected Endpoints<\/h2>\n<p>An unexpected Faronics installation should prompt investigation, but its presence alone does not prove compromise.<\/p>\n<p>Huntress recommends examining:<\/p>\n<p><code>C:\\ProgramData\\Faronics\\Logs\\ScriptRunner.log<\/code><\/p>\n<p>The log can contain information about scripts remotely executed through Faronics. It can also preserve associated source URLs, providing useful evidence during incident investigation.<\/p>\n<p>Where the relevant Windows logging policies were enabled before the activity occurred, defenders can supplement <code>ScriptRunner.log<\/code> with native Windows telemetry. PowerShell Script Block Logging generates Event ID <code>4104<\/code>, which can preserve the content of processed PowerShell script blocks.<\/p>\n<p>Windows Security Event ID <code>4688<\/code> records process creation, while command-line arguments are available when Audit Process Creation and the Include command line in process creation events setting are enabled. These records can provide additional context when investigating PowerShell and related processes executed during the campaign.<\/p>\n<p>Administrators should investigate for:<\/p>\n<ul>\n<li>unexpected PowerShell or other remotely executed scripts<\/li>\n<li>GitHub or external payload URLs<\/li>\n<li>unauthorized ScreenConnect installations<\/li>\n<li>other unexpected remote-management tools<\/li>\n<li>scripts executed before or after RMM installation<\/li>\n<li>configuration requests containing the Faronics <code>ck<\/code> identifier<\/li>\n<\/ul>\n<p>The <code>ck<\/code> parameter can also provide an investigative pivot. Faronics told Huntress that the identifier maps activity to a customer or deployment.<\/p>\n<p>Therefore, defenders investigating multiple endpoints can use the identifier alongside other evidence. This can help determine whether systems may be associated with the same suspicious deployment.<\/p>\n<p>The strongest signal is not simply the presence of Faronics Deploy. Instead, defenders should look for an unexpected Faronics installation combined with suspicious remote execution or unauthorized remote-management software.<br \/>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Windows_thumbnail.webp?format=webp\" class=\"resource-box__image\" alt=\"Windows Platform Capability Statement\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Windows_thumbnail.webp?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Windows_thumbnail-300x225.webp?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Windows_thumbnail-768x576.webp?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Windows_thumbnail-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"Windows_thumbnail\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Windows Platform Capability Statement\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Explore how centralized Windows device management helps IT teams manage applications, security controls and endpoint configurations across enterprise devices.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/infographics\/windows-device-management\/'>\n                            Download the infographic\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section><\/p>\n<h2>How Hexnode Helps Address Unauthorized Remote Management Software<\/h2>\n<p>The Faronics Deploy campaign shows why enterprises need both governance over administrative software and visibility into suspicious endpoint activity. Hexnode UEM and Hexnode XDR address different parts of this requirement, from controlling applications on managed endpoints to investigating and containing suspicious activity.<\/p>\n<h3>Govern Remote Management Software with Hexnode UEM<\/h3>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> provides application-management capabilities for supported Windows endpoints. Administrators can use application policies and software visibility to control which applications belong on managed devices.<\/p>\n<p>For example, IT teams can define policies around approved applications and restrict unwanted software where supported. This helps organizations maintain clearer baselines for administrative and remote-management tools.<\/p>\n<p>Application governance is especially relevant when software such as Faronics Deploy or ScreenConnect is not approved for a particular endpoint.<\/p>\n<p>Where supported and appropriately configured, <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-application-allowlisting\/\">application allowlisting<\/a> or blocklisting can further restrict unauthorized software on managed endpoints. For this campaign, organizations could apply these controls as part of a broader policy for restricting unapproved administrative and remote-management applications. However, enforcement depends on the Windows configuration and policy applied, so these controls should not be described as automatically blocking every Faronics installer before enrollment.<\/p>\n<p>Hexnode UEM should not be positioned as detecting the Faronics campaign itself. Organizations still need to investigate Faronics-specific artifacts and determine what occurred after an unauthorized enrollment.<\/p>\n<h3>Investigate and Contain Suspicious Endpoint Activity with Hexnode XDR<\/h3>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> provides endpoint telemetry and investigation capabilities. These include historical endpoint events, process-tree visibility and query-based investigation.<\/p>\n<p>Such visibility can help analysts examine suspicious execution involving processes such as PowerShell, mshta or msiexec. Analysts can also inspect surrounding process and endpoint activity instead of evaluating individual commands in isolation.<\/p>\n<p>When an investigation confirms malicious activity, documented response capabilities can support containment. Depending on the identified artifact or process, administrators can use relevant actions such as:<\/p>\n<ul>\n<li>isolating an affected endpoint<\/li>\n<li>terminating a malicious process<\/li>\n<li>terminating its process tree<\/li>\n<li>quarantining a malicious file<\/li>\n<li>deleting an executable associated with malicious activity<\/li>\n<\/ul>\n<p>These capabilities support endpoint investigation and response. However, they do not mean Hexnode XDR specifically detects Faronics Deploy abuse, ScreenConnect abuse or this campaign automatically.<\/p>\n<p>Likewise, XDR investigation does not replace campaign-specific remediation. Administrators should still preserve and examine relevant Faronics logs and remove unauthorized management deployments.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/What-to-Look-for-When-Doing-EDR-Software-Comparison-1024x535-1.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>What to Look for When Doing EDR Software Comparison?<\/h4><p>Learn which detection, investigation, response and operational capabilities enterprises should evaluate.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/what-to-look-for-when-doing-edr-software-comparison\/\" aria-label=\"What to Look for When Doing EDR Software Comparison?\"><\/a><\/div><\/div><\/div>\n<h2>What Enterprises Should Do After Suspected Faronics Deploy Abuse<\/h2>\n<p>Organizations should treat an unexpected Faronics deployment as an incident requiring investigation rather than simply uninstalling the application.<\/p>\n<p>Recommended actions include:<\/p>\n<ul>\n<li><strong>Isolate affected endpoints when compromise is suspected<\/strong>. This can restrict further remote attacker activity while investigation continues.<\/li>\n<li><strong>Identify the Faronics deployment<\/strong>. Review the associated <code>ck<\/code> identifier and related artifacts.<\/li>\n<li><strong>Preserve <code>ScriptRunner.log<\/code><\/strong>. Collect relevant evidence before removing Faronics from the endpoint.<\/li>\n<li><strong>Review remote script activity<\/strong>. Investigate PowerShell commands, external URLs and other scripts executed through the deployment.<\/li>\n<li><strong>Hunt for ScreenConnect<\/strong>. Check affected systems for unexpected ScreenConnect installations.<\/li>\n<li><strong>Look for additional RMM software<\/strong>. Determine whether attackers introduced other remote-access mechanisms.<\/li>\n<li><strong>Remove unauthorized management software<\/strong>. Do this after preserving the forensic information required for investigation.<\/li>\n<li><strong>Investigate follow-on activity<\/strong>. Review processes, files and network activity associated with suspicious scripts.<\/li>\n<li><strong>Assess credential exposure<\/strong>. Rotate credentials where investigation indicates potential exposure or unauthorized interactive access.<\/li>\n<li><strong>Report suspected abuse to Faronics<\/strong>. Vendor involvement can help investigate unauthorized deployments.<\/li>\n<\/ul>\n<p>Organizations should also maintain an inventory of approved remote-management tools.<\/p>\n<p>An unfamiliar RMM agent should receive additional scrutiny. Legitimate administrative software can provide extensive endpoint control when deployed without authorization.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Does finding Faronics Deploy on an endpoint mean it is compromised?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>No. Faronics Deploy is legitimate administrative software, so its presence alone does not indicate compromise. Administrators should determine whether the installation was authorized and correlate it with unexpected remote scripts, ScreenConnect installations or suspicious deployment identifiers.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">How did attackers abuse Faronics Deploy in the reported campaign?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>The reported campaign involved social engineering and abuse of legitimate Faronics Deploy functionality after victims were tricked into installing signed software that enrolled their endpoints into attacker-controlled deployments.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Is uninstalling Faronics Deploy enough to remediate an affected endpoint?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Not necessarily. Huntress observed attackers installing ScreenConnect as an additional remote-access mechanism. Defenders should investigate follow-on activity and identify other unauthorized remote-management software before completing remediation.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Why did attackers use both Faronics Deploy and ScreenConnect?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Faronics Deploy provided a way to remotely execute scripts after an endpoint joined the attacker-controlled deployment. ScreenConnect then provided an additional remote-access mechanism independent of the unauthorized Faronics enrollment.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n<h3>Faronics Deploy Abuse Shows the Risk of Unauthorized Management Agents<\/h3>\n<p>The Faronics Deploy abuse campaign shows how legitimate administrative software can become part of an attack path when deployed without authorization.<\/p>\n<p>The <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hackers-abuse-faronics-deploy-admin-tool-to-install-screenconnect\/?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=faronics_deploy_abuse\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">campaign<\/a> starts with social engineering, with victims tricked into installing legitimate, signed Faronics Deploy software that attackers then abuse for remote script execution. Victims run legitimate, signed software that connects their endpoints to infrastructure controlled by attackers. Faronics deployment capabilities then enable remote script execution, while ScreenConnect provides another remote-access mechanism.<\/p>\n<p>For enterprises, the lesson extends beyond blocking a specific executable. IT and security teams need visibility into which management agents are authorized and where they are installed.<\/p>\n<p>UEM can support application governance and endpoint baselines. XDR can support investigation and containment when suspicious endpoint activity appears.<\/p>\n<p>However, neither replaces incident-specific investigation. When Faronics Deploy abuse is suspected, defenders should preserve Faronics artifacts, investigate remote execution and identify unauthorized remote-access mechanisms before completing remediation.<br \/>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen control over your enterprise endpoints<\/h5><p>Manage applications, enforce endpoint policies and build stronger visibility across your managed device environment with Hexnode.<\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Try Hexnode Now<\/a><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Faronics Deploy abuse is a phishing campaign in which attackers trick victims into installing legitimate,&#8230;<\/p>\n","protected":false},"author":4,"featured_media":1366,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[10,16],"class_list":["post-1335","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-phishing","category-windows","product_category-extended-detection-and-response","tab_group-identity-and-phishing"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Faronics Deploy Abuse Installs ScreenConnect via Phishing<\/title>\n<meta name=\"description\" content=\"Faronics Deploy abuse uses phishing to enroll Windows endpoints, execute PowerShell and install ScreenConnect.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/faronics-deploy-abuse-screenconnect\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Faronics Deploy Abuse Installs ScreenConnect via Phishing\" \/>\n<meta property=\"og:description\" content=\"Faronics Deploy abuse uses phishing to enroll Windows endpoints, execute PowerShell and install ScreenConnect.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/faronics-deploy-abuse-screenconnect\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-02T06:32:34+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-03T05:43:14+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Faronics-Deploy-Abuse-Turns-Endpoint-Management-into-an-Attack-Path.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"754\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nora Blake\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nora Blake\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/faronics-deploy-abuse-screenconnect\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/faronics-deploy-abuse-screenconnect\\\/\"},\"author\":{\"name\":\"Nora Blake\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\"},\"headline\":\"Faronics Deploy Abuse Turns Endpoint Management into an Attack Path\",\"datePublished\":\"2026-09-02T06:32:34+00:00\",\"dateModified\":\"2026-09-03T05:43:14+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/faronics-deploy-abuse-screenconnect\\\/\"},\"wordCount\":1672,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/faronics-deploy-abuse-screenconnect\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Faronics-Deploy-Abuse-Turns-Endpoint-Management-into-an-Attack-Path.jpeg?format=webp\",\"articleSection\":[\"Phishing\",\"Windows\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/faronics-deploy-abuse-screenconnect\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/faronics-deploy-abuse-screenconnect\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/faronics-deploy-abuse-screenconnect\\\/\",\"name\":\"Faronics Deploy Abuse Installs ScreenConnect via Phishing\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/faronics-deploy-abuse-screenconnect\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/faronics-deploy-abuse-screenconnect\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Faronics-Deploy-Abuse-Turns-Endpoint-Management-into-an-Attack-Path.jpeg?format=webp\",\"datePublished\":\"2026-09-02T06:32:34+00:00\",\"dateModified\":\"2026-09-03T05:43:14+00:00\",\"description\":\"Faronics Deploy abuse uses phishing to enroll Windows endpoints, execute PowerShell and install ScreenConnect.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/faronics-deploy-abuse-screenconnect\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/faronics-deploy-abuse-screenconnect\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/faronics-deploy-abuse-screenconnect\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Faronics-Deploy-Abuse-Turns-Endpoint-Management-into-an-Attack-Path.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Faronics-Deploy-Abuse-Turns-Endpoint-Management-into-an-Attack-Path.jpeg?format=webp\",\"width\":1340,\"height\":754,\"caption\":\"Faronics Deploy Abuse Turns Endpoint Management into an Attack Path\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/faronics-deploy-abuse-screenconnect\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Faronics Deploy Abuse Turns Endpoint Management into an Attack Path\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\",\"name\":\"Nora Blake\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"caption\":\"Nora Blake\"},\"description\":\"I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/nora-blake\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Faronics Deploy Abuse Installs ScreenConnect via Phishing","description":"Faronics Deploy abuse uses phishing to enroll Windows endpoints, execute PowerShell and install ScreenConnect.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/faronics-deploy-abuse-screenconnect\/","og_locale":"en_US","og_type":"article","og_title":"Faronics Deploy Abuse Installs ScreenConnect via Phishing","og_description":"Faronics Deploy abuse uses phishing to enroll Windows endpoints, execute PowerShell and install ScreenConnect.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/faronics-deploy-abuse-screenconnect\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-02T06:32:34+00:00","article_modified_time":"2026-09-03T05:43:14+00:00","og_image":[{"width":1340,"height":754,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Faronics-Deploy-Abuse-Turns-Endpoint-Management-into-an-Attack-Path.jpeg?format=webp","type":"image\/jpeg"}],"author":"Nora Blake","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Nora Blake","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/faronics-deploy-abuse-screenconnect\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/faronics-deploy-abuse-screenconnect\/"},"author":{"name":"Nora Blake","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d"},"headline":"Faronics Deploy Abuse Turns Endpoint Management into an Attack Path","datePublished":"2026-09-02T06:32:34+00:00","dateModified":"2026-09-03T05:43:14+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/faronics-deploy-abuse-screenconnect\/"},"wordCount":1672,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/faronics-deploy-abuse-screenconnect\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Faronics-Deploy-Abuse-Turns-Endpoint-Management-into-an-Attack-Path.jpeg?format=webp","articleSection":["Phishing","Windows"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/faronics-deploy-abuse-screenconnect\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/faronics-deploy-abuse-screenconnect\/","url":"https:\/\/www.hexnode.com\/threat-watch\/faronics-deploy-abuse-screenconnect\/","name":"Faronics Deploy Abuse Installs ScreenConnect via Phishing","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/faronics-deploy-abuse-screenconnect\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/faronics-deploy-abuse-screenconnect\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Faronics-Deploy-Abuse-Turns-Endpoint-Management-into-an-Attack-Path.jpeg?format=webp","datePublished":"2026-09-02T06:32:34+00:00","dateModified":"2026-09-03T05:43:14+00:00","description":"Faronics Deploy abuse uses phishing to enroll Windows endpoints, execute PowerShell and install ScreenConnect.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/faronics-deploy-abuse-screenconnect\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/faronics-deploy-abuse-screenconnect\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/faronics-deploy-abuse-screenconnect\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Faronics-Deploy-Abuse-Turns-Endpoint-Management-into-an-Attack-Path.jpeg?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Faronics-Deploy-Abuse-Turns-Endpoint-Management-into-an-Attack-Path.jpeg?format=webp","width":1340,"height":754,"caption":"Faronics Deploy Abuse Turns Endpoint Management into an Attack Path"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/faronics-deploy-abuse-screenconnect\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Faronics Deploy Abuse Turns Endpoint Management into an Attack Path"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d","name":"Nora Blake","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","caption":"Nora Blake"},"description":"I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/nora-blake\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1335","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1335"}],"version-history":[{"count":3,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1335\/revisions"}],"predecessor-version":[{"id":1357,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1335\/revisions\/1357"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1366"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1335"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1335"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}