teams
The controls are not there, or not everywhere
Some coverage with holes in it, or almost none. Either way the software on those machines is unidentified, and there is nothing on them positioned to act on it.
one
What this does
In one sentence.
It reads every piece of software on a machine and tells you what each one is, who made it, and how certain that is, so the list you have been meaning to go through arrives already sorted.
Windows, macOS and Linux. One agent, installed once.
two
The number that applies to you
410 items on one ordinary laptop. 168 of them are not in any commercial software catalog.
That is the figure that matters here, and it is not the one a security vendor would lead with.
Editor extensions, bundled runtimes, portable executables, internal tools, small open-source utilities. If you bought a catalog-based inventory product tomorrow, those 168 are the ones it still could not name. Roughly two in five, on one machine.
The reason you have never had a satisfying answer about them is not that you did not look hard enough. It is that the answer was not available from a list of names.
three
Why the things you already tried did not settle it
Software inventory has probably been on the list for a while. Not because it was deprioritised, but because it never once became the most urgent thing in a given week, and there are only so many weeks.
So you have almost certainly done some of these. They are the right instincts and they all stop at the same place.
- An export from your management tool into a spreadsheet.
- Gives you names and versions, and no way to tell which of them matter.
- A script walking the uninstall keys.
- Accurate for machine-wide installs, silent about everything a user installed into their own profile.
- Sorting the export and reading it.
- Works until the list is long enough that reading it stops being a plan.
- Asking people what they installed.
- Produces honest answers and incomplete ones.
Every one of them gives you a list of names. None tells you what any of it is: whether a name you do not recognise is a driver, a build tool, a remote access client, or something a contractor left behind three years ago.
four
What you would actually do with it
Look, then decide, then act. You can stop after any of them.
Look. Every item categorized, with a confidence attached. The unknown column stops being most of the page.
Decide. Approve what belongs, block what does not. Rules can carry the repetitive cases so the queue holds the ones that need you.
Act, when you want to. The agent can quarantine what you blocked, and it ships switched off. In monitor mode it shows you what it would have done and touches nothing, which is the mode to run first when there is nobody to cover for you if a decision is wrong.
five
What changes, honestly
Not the number of people.
Anyone telling you a categorization tool means fewer engineers is describing a confidence level they do not have. Attribution is graded, some of it is a best guess, and someone still has to look at those. That someone is you either way.
What changes is reach. The same one person covers the whole inventory instead of the part that shouted loudest, because the list arrives with categories and vendors already on it.
And when somebody asks what is running on the machines, the answer is a document rather than a shrug. That is usually worth more internally than the time it saves.
More of this
New posts on what a file tells you before you run it: headers, signatures, manifests, overlays, the fields most inventory never reads. Only when there is something worth the write-up.
We intend to offer a tool that does this across every file on an endpoint. You get one message when you can use it.