Rewst.io

Fair enough on Jinja.

The point is they don't need to run an agent or push their scripts through RMM. Instead of generating a script on the fly and pushing it via RMM API call, they could store them in keyvaults and invoke them from RMM. The endpoint doesn't need an additional agent, and you can set up conditional access and other restrictions on the vault plus having deep audit capabilities.

That impromptu solution is way better than their current potential of "let me breach this one provider and push malware to every RMM agent at XXX MSPs without restriction." Why breach each individual MSP RMM when you can breach a fledgling platform and have control of many. It's bad design.

/r/msp Thread Parent