
Someone needs a tool the company never licensed, so they download a cracked copy. It works, which is the problem. Pirated software means unknown code from an untrusted source, updating from servers nobody vetted, on a machine inside the client network. The user saved a license fee. The network gained a supply chain it never agreed to.
enhanced.io is a channel-only Open XDR SOCaaS built exclusively for MSPs, with 400+ integrations across endpoint, network, cloud, identity and IoT/OT.
The situation
This pattern shows up more than most MSPs expect, and not only at small clients. An employee installs a cracked productivity suite from a piracy site. The installer bundles more than the product: a loader that phones home, quietly, on a schedule. The machine runs normally. Nothing crashes. The user has no idea the tool came with a passenger.
What we detect
The endpoint agent reports an unsigned binary from an untrusted source establishing persistence, which raises the first alert. The network sensor adds the second layer: outbound connections from the machine to a low-reputation host, on a regular schedule, unrelated to any legitimate update infrastructure. Process telemetry plus traffic pattern correlates into one case on the machine, scored High for the persistence and the callback together.
What gets automated
The callback destination is blocked at the firewall, cutting the loader off from its host. Depending on the response posture for the machine, containment fires automatically or routes to review. The persistence mechanism is flagged in the case for removal rather than auto-deleted, because cleanup on a user's working machine is a decision the MSP makes with context.
Where humans step in
An analyst identifies the software, the loader, and whether the same binary exists anywhere else in the tenant, because cracked installs travel by recommendation between colleagues. Escalation to the MSP covers the cleanup and the finding beneath it: this client has unlicensed software in the estate, which means the security tooling is now compensating for a licensing decision. The Fractional Security Director puts the structural point in the monthly review, with a documented recommendation the client either acts on or formally accepts the risk of.
The outcome
The loader is dead, the machine is clean, and the estate has been swept for repeats. The harder outcome is the honest one: detection contains the consequence, and the risk remains until the licensing gap closes. The client now holds a written recommendation and owns the decision, which is exactly where responsibility for it belongs.
Check your own stack
Would an unsigned binary with persistence raise an alert at every client, or only some?
Does anything watch outbound traffic for callbacks, or only inbound threats?
When tooling finds a licensing problem, who documents the risk and who accepts it?
