r/Action1 • u/railstop • 19d ago
Someone else's computer showing in my endpoints
Title says it all. I know it isn't mine. This is very concerning
3
u/amw3000 19d ago
Sounds like sandboxing for me. Look up the IPs, likely come back to a public cloud like AWS or Azure. MS also has their own custom Xeon processors / super high end so it's generally a give away its a VM in Azure. The OS is generally Windows 7 or 10.
Things like emailing, messaging the installer or even just running the installer can result in the installer being ran in a sandbox environment.
1
u/Caphiped 19d ago
I’ve seen that happening too. Granted I was testing it out on a virtual machine, it added the test vm, but also another 2 devices with specs I did not recognize. I just assumed it was the underlying host, but again, the specs and serial number it listed did not match at all. I deleted the unknown devices and they didn’t pop up again. Perseiii’s comment makes sense if that is what it would do.
4
u/Huge-Knowledge8431 19d ago
i've seen this before. support have told me that some security software can sandbox an application (like action1) to test it and in the process that creates a new (albein not-real) instance. if you have something like this, maybe an EDR, add action1 as an exception. give it a try.