Keep completed endpoint scans moving into the validated outbox.
The server understands the completion-state field produced by current agents, validates its bounded values, and still accepts legacy manifests that predate the field.
Completed endpoint artifacts carry their validated completion state into delivery without being rejected as an unknown manifest field. If output is quarantined, both the endpoint and Fleet now call for attention instead of letting a recent local scan time hide the unfinished delivery state.
The server understands the completion-state field produced by current agents, validates its bounded values, and still accepts legacy manifests that predate the field.
A quarantined artifact now overrides a recent local scan timestamp: Fleet and the Windows endpoint report Attention required with a bounded reason.
Portable PE version parsing now applies on Windows, Linux, macOS, ARM, MIPS, PowerPC, and RISC-V. Platform-specific APIs add native context without becoming the only way to recover core evidence.
Roll out the signed Windows endpoint through Intune or install it directly. Choose all local drives or selected folders through managed scan profiles or the standalone configuration tray, without editing configuration files.
Collect evidence from endpoints, servers, storage, firmware images, embedded platforms, and inherited environments—including versions, hashes, publishers, packages, and file context.
Approve a known-good scan as your baseline, then see added, removed, and changed software alongside version, publisher, product, and environment drift.
Begin with a plain-language brief and a ranked view of unusual patterns, then verify each signal against the evidence instead of relying on a black-box score.
Bring vulnerability context, malware hash intelligence, signatures, and forensic indicators together. CVSS v4.0 scores are used when published, and visible feed status helps you judge how current the supporting intelligence is.
Turn searchable inventory and measured drift into a concise explanation of exposure and next steps. Share inventory CSV exports and NIST 800-53 POA&M worksheets with safer handling of collected evidence in spreadsheets.
Important software lives beyond the reach of conventional endpoint inventory: in appliances, firmware, servers, storage, isolated systems, and environments your team did not build. Portable collectors extend that reach across ARM, MIPS, PowerPC, and now RISC-V64, bringing those sources into the same evidence workflow as the managed fleet.
The result is more than a list of installed applications. Your team can establish what good looks like, measure change, connect suspicious or vulnerable software to its source, and use AI-enabled insights to decide where human attention will have the greatest impact.
Install the signed Windows endpoint or take a portable collector to the target. Bring the results into VersionGopher, establish a trusted baseline, and use search, risk context, drift analysis, and AI-enabled insights to turn raw software evidence into a clear next action.
See Windows and portable download options Configure Windows endpoint collection Designate and compare drift baselines Explore AI-enabled insights Check security intelligence and feed status Open Help CenterDeploy the Windows endpoint or run a portable collector where agents cannot go.
Search the evidence, assess risk, and see what changed from a trusted state.
Follow the strongest signals and package the evidence into a defensible brief.
Start with a laptop, server, fleet, firmware image, or inherited environment—and turn the results into an evidence-backed risk brief.