Windows machines scan themselves on a schedule.
A signed Windows endpoint service runs the collector on a schedule and uploads verified results to your hosted instance, so managed machines stay inventoried without hands-on scans.
Since the forensic discovery cockpit shipped, VersionGopher has grown a managed Windows endpoint you deploy through Microsoft Intune, a fleet view of every enrolled machine, and cross-sectional drift detection that answers the question every fleet operator actually has: my machines were built to be identical, so how far have they drifted from each other? The evidence-gated CVE matcher is now in production, and the collector and supply-chain paths are hardened.
A signed Windows endpoint service runs the collector on a schedule and uploads verified results to your hosted instance, so managed machines stay inventoried without hands-on scans.
Package the endpoint as an .intunewin, assign it to a device group, and enroll each machine with a one-use bootstrap token. A non-Intune admin can enroll from the configuration tray, no PowerShell required.
Fleet cohesion measures how identical your machines really are, on a green-to-red gradient, and names the machines that have diverged, so bad patch management and configuration drift surface early.
See every enrolled endpoint with its state, last scan, and identity; run bulk actions; retire or clean up devices; and keep per-organization scope on every fleet operation.
The skeptical, evidence-gated CVE matcher shipped to production: weak identities require corroboration, and visible vulnerabilities are separated from needs-verification and audit-only decisions.
Front-end dependency installation is locked down with an enforced npm supply-chain policy and check, reducing the blast radius of a poisoned or unexpected package during setup.
Product-banner reads, malformed ELF notes, self-referential PE resources, and version-scoring work are all bounded, with generated malformed-file regressions proving the fixes.
OSV incremental updates read the documented columns, resume from a stored watermark in bounded batches, and retry transient failures without losing catalog state.
New machines get imaged the same, deployed, and then quietly diverge: one misses a patch cycle, another keeps a leftover agent, a third picks up software nobody approved. By the time it shows up in an audit, the fleet is all over the place. VersionGopher now measures that divergence directly and shows it as a single gradient, so drift is something you watch trend, not something you discover after the fact.
The signal is deliberately robust. Rather than comparing version strings, which real Windows systems fragment into thousands of side-by-side components, fleet cohesion compares the overlap of each machine's file-hash sets. A freshly imaged fleet scores near the top; as machines fall to different patch levels or accumulate unique software, the score falls toward red and the outlier machines are named.
Drift detection is scoped honestly. It applies only to managed host-tracking endpoints, because a machine has to be compared with its own fleet, not with unrelated uploads. Snapshots accrue over time, and an alert fires when a fleet slides from its own recent baseline, before it reaches the red band.
Alongside the fleet work, the evidence-gated CVE matcher favors defensible decisions over broad matches, the collector is hardened against hostile files, and front-end dependency installation follows an enforced supply-chain policy.
The collector stays lightweight and the deeper analysis lives in the hosted workflow: the Fleet view, fleet cohesion and drift, ML/AI Insights, CVE evidence lanes, package risk, binary forensic signals, search, and assessment reports.
Deploy managed endpoints with Intune Understand groups, similarity, and drift Read the CVE evidence decision guide Open help and setup notes
Start with one Windows endpoint group, firmware image, storage estate, inherited environment, or embedded platform.