Search:
Advanced search
|
Scout: how does it work?Article ID: 213
Last updated: 28 May, 2015
Installation requirements
Available modules
InstallationWhen a computer is infected, the Scout executable file is copied (after about 15 seconds) to the Windows autostart folder. The silent installer that infected the PC stays in RAM until the next system reboot/logoff and synchronizes with the server, sending the collected data. When is loaded into memory, the Scout checks if:
If the PC is running an Elite instance and the Scout executable file was run from the Windows Startup folder, the Scout executable file is deleted from the PC; in all other cases the process ends without further actions. The Scout agent deals with:
!!! ⇒ The system data are sent only once for each Scout execution, whereas the screenshots are sent periodically.
Synchronisation with the serverWhen the Scout process is run, after the initial control procedures it waits for 5 minutes without performing any task. After 5 minutes, the process starts again at the first user activity detected (input from keyboard or mouse). Subsequently it creates the synchronization thread that deals with exchanging data with the server; if the server sent to Elite or Soldier an upgrade command, the Scout instance is updated. Synchronization occurs every 20 minutes if the previous synchronization was successful; otherwise every 5 minutes a new connection attempt is done. !!! ⇒ The synchronization timers cannot be edited by console. Synchronization timers overview
How to test the agentConsider this recap as the starting point for all your tests. We're always referring to the first stage of the agent (Scout), using a silent installer. Remember that silent installer should never be sent to the target as is, but one of your field operators must run it directly on the target computer:
At this point you can leave the session open, log off or even restart the machine; the agent will run and will restart at every user login. In order to troubleshoot if the process is running, consider that:
Every time the agent is started (directly or automatically), the first synchronization happens if:
After that, other synchronizations occur every 20 minutes. A recap to some common concerns:
|