3 ms·
I do not know Drata, but an endpoint agent on a company machine is not that odd. Generally, they come from the big EDR companies, such as Carbon Black, CrowdStr
by fdye 5y ago
I do not know Drata, but an endpoint agent on a company machine is not that odd. Generally, they come from the big EDR companies, such as Carbon Black, CrowdStrike, etc. They would mostly run in the background and scan for malware, push out Group Policy changes, and yes, provide a backdoor to run scripts on your machine. Drata sounds a bit more like spyware though. Technically, EDR agents can do session captures (recording the screen, showing what was run on the computer over history, processes, network traffic). Generally, though its only utilized for incident response and not tracking a contractors time, making sure they are working, etc. Although I must admit, theoretically there is nothing preventing that, although its at a more technical level then most management would know how to decipher.
I second the recommendations above. Only agree to install it on a company machine, same for any agent or company AV, etc. If they wont provide it then its a no go on any personal hardware of yours.