Stealth Agent Mode: Invisible Endpoint Monitoring

Anexet's stealth agent runs silently on Windows endpoints — no visible icon, no pop-ups, no notification to the monitored user. The Windows service can be renamed to your company name so the tool is not identifiable as a monitoring product. Anexet is deployed on-premise; the vendor has no access to your data.

Schedule a Demo
Anexet Administrator Console showing agent deployment and configuration settings

Covert Monitoring That Preserves the Integrity of Investigations

The moment a suspected employee spots monitoring software, the investigation is compromised. Stealth mode eliminates that risk.

Insider-threat investigations depend on one critical condition: the subject must not know they are being watched. An employee who identifies a monitoring tool in the system tray, task manager, or services list can change behavior, destroy evidence, or attempt to remove the agent — defeating the investigation before it yields actionable findings.

Anexet's stealth agent is engineered to operate without any visible footprint on the monitored workstation. There is no tray icon, no pop-up, no taskbar entry. The Windows service runs under a name you choose — your company name or any neutral label — so it appears as a legitimate internal IT process to anyone who checks the services panel.

Stealth mode is available from the Standard plan. It is a deployment-level feature, not a premium add-on. All captured data is transmitted over an encrypted channel to your on-premise Anexet server, where it is indexed and accessible only to authorized security staff.

Why it matters

  • Behavioral integrity

    You observe what the employee actually does — not a performance staged for the audience of a visible monitoring tool.

  • Evidence integrity

    The employee cannot selectively delete, overwrite, or move files to defeat a specific investigation window they know is open.

  • Agent integrity

    An employee who does not know the agent is running cannot attempt to uninstall, crash, or circumvent it.

How Anexet Stays Invisible

All stealth capabilities are available from the Standard plan. The exact visibility profile for your environment is confirmed during the demo.

No visible presence on the desktop

  • No system-tray icon

    Standard

    The agent does not place an icon in the Windows notification area (near the clock). There is no visible indicator that monitoring is active.

  • No pop-ups or notifications

    Standard

    No window, splash screen, status dialog, or notification ever appears on the monitored desktop. The agent presents no user-facing interface.

  • Silent background operation

    Standard

    Monitoring begins at login and continues without any interaction from or visibility to the monitored user.

Service name masking

  • Rename the Windows service to your company name

    Standard

    The Windows service running the Anexet agent can be renamed to your organization's own name or any neutral label. It appears as an internal IT process — not as a monitoring product — to anyone who inspects the services list.

  • No Anexet branding in the services panel

    Standard

    An investigated employee, IT contractor, or curious user who opens Windows Services sees your chosen service name — nothing identifiable as third-party surveillance software.

Encrypted network channel

  • TLS-encrypted agent-to-server traffic

    Standard

    All communication between the endpoint agent and the Anexet Data Processing Server is TLS-encrypted, preventing interception of monitoring data in transit.

  • Traffic blends with corporate network

    Standard

    The agent's network connection can be configured to resemble normal corporate traffic patterns, making it harder to identify through endpoint network inspection.

Process-level visibility (e.g. in Windows Task Manager) depends on deployment configuration reviewed during rollout. AV exclusions must be configured before deployment — see the antivirus note below.

All Evidence Stays on Your Server — No Vendor Access, No Cloud Upload

The Anexet endpoint agent transmits captured data — intercepted communications, user activity logs, screenshots, and audio/video recordings — over an encrypted internal network connection to your on-premise Anexet Data Processing Server. Nothing is sent to the vendor or any external service. All data is indexed on your infrastructure and accessible only to authorized users in your security console.

Scinero Software Limited, the vendor, has no access to your server, your captured data, or your monitoring configurations. This applies in every monitoring mode — including stealth. On-premise deployment means you retain complete control over evidence during and after an investigation.

Anexet Administrator Console showing agent deployment settings
Anexet Client Console showing user activity intercepted data

How Stealth Agent Mode Is Deployed

Four steps from configuration to silent, evidence-ready monitoring.

Before rollout, your implementation specialist configures the agent profile: stealth settings, service name, communication parameters, and the AV exclusion list for your endpoint protection platform. These settings are finalized during the demo.

1

The agent package is deployed to workstations via your standard software distribution mechanism — Group Policy, SCCM, or equivalent. No installer UI appears on the monitored workstation; installation is silent.

2

AV exclusions are applied in your antivirus or EDR console before agent deployment. This step is required: an unconfigured AV policy can quarantine or terminate the agent. The exact exclusion scope is confirmed with your implementation specialist.

3

The agent starts monitoring immediately after installation. Captured data flows over an encrypted channel to your on-premise server, where it is indexed and available in the Client Console for search, investigation, and reporting — without any indication to the monitored user.

4

Before rollout, your implementation specialist configures the agent profile: stealth settings, service name, communication parameters, and the AV exclusion list for your endpoint protection platform. These settings are finalized during the demo.

1

The agent package is deployed to workstations via your standard software distribution mechanism — Group Policy, SCCM, or equivalent. No installer UI appears on the monitored workstation; installation is silent.

2

AV exclusions are applied in your antivirus or EDR console before agent deployment. This step is required: an unconfigured AV policy can quarantine or terminate the agent. The exact exclusion scope is confirmed with your implementation specialist.

3

The agent starts monitoring immediately after installation. Captured data flows over an encrypted channel to your on-premise server, where it is indexed and available in the Client Console for search, investigation, and reporting — without any indication to the monitored user.

4

Arrow

Stealth Agent Mode by Plan

StandardCore employee activity monitoring.
Network traffic interception
USB control
Printers monitoring
Messengers interception
Browsers interception
and 4 more
Includes:
Anexet Activity
Most popular
AdvancedAdds DLP and deeper visibility.
Standard plan included
DLP features
Network shares monitoring
Keylogger
Webcam pictures
and 4 more
Includes:
Anexet DLP
Anexet Activity
All-in-one
PremiumAll-in-one solution.
Standard + Advanced plans included
Advanced search (digital fingerprints, hash search)
File systems monitoring
User relations analysis
Risk analysis
and 6 more
Includes:
Anexet DLP
Anexet Inventory
Anexet Activity
Anexet Ultimate

Frequently Asked Questions

Common questions about stealth agent mode — what it hides, which plan includes it, antivirus, and legal considerations.

Is the stealth agent completely invisible to the user?

There is no visible icon, pop-up, notification, or user-facing window. The agent runs as a background Windows service under a name you choose. What is visible at the technical level (e.g. in Windows Task Manager) depends on deployment configuration — your implementation specialist reviews this during the demo and confirms the visibility profile for your environment.

Stealth operation is included in all plans — Standard, Advanced, and Premium. Standard is the entry-level plan and includes Anexet Activity, full network interception, and stealth deployment. Advanced adds DLP features, blocking policies, and keylogger. Premium adds Inventory, Risk Analysis, AI Server, and SIEM. All plan pricing is Price on Request; minimum 5 licenses.

Yes. The Windows service running the Anexet agent can be renamed to your organization's own name or any neutral label during the deployment configuration phase. This is done before the agent package is distributed to workstations. Your implementation specialist guides this step as part of the rollout.

Possibly, if AV exclusions are not configured first. Antivirus and endpoint detection and response (EDR) platforms can flag monitoring-class behavior regardless of the service name. AV exclusions are configured as part of the deployment rollout — the Scinero implementation team reviews your AV platform and provides the required exclusion policy. Deploying stealth mode without completing AV exclusion setup is not recommended.

Yes — Anexet is deployed entirely on your own infrastructure. Scinero Software Limited, the vendor, has no access to your server, your captured data, or your monitoring configurations. This applies in stealth mode and all other monitoring modes. Anexet is deployed on-premise; the vendor has no access to your data.

This is jurisdiction-specific and context-specific. Covert monitoring is subject to labor law, data protection law (including GDPR in the EU), and sector-specific regulations. Requirements vary by country — some permit covert monitoring for active investigations with appropriate internal authorization; others impose stricter limits. Anexet helps your organization implement the technical controls for covert monitoring — it does not constitute legal authorization, certification, or compliance with any regulation. Consult your legal team and HR counsel before activating stealth mode, particularly for targeted investigations.

No. Stealth mode is a configuration of how the agent presents itself — no tray icon, masked service name, configured network profile. It does not add a processing layer or change how the agent captures data. Resource footprint is the same as standard deployment.

They work together. Stealth mode controls what the agent shows (or does not show) on the monitored workstation. On-premise deployment controls where captured data goes — your own server, not a vendor cloud. Together they allow covert investigation without exposing evidence data outside your organization. The On-Premise Deployment page covers the full data-sovereignty architecture.

Three professionals collaborating and looking at a tablet in a meeting

See Stealth Agent Mode in Action

Tell us about your insider-threat or investigation requirements. We will walk you through the stealth configuration options — service name masking, AV exclusion setup, deployment scope — and arrange a demo or a free trial of Anexet Ultimate.

I accept that my personal data can be processed in accordance with the Privacy Policy