Skip to content

User Agent

L’User Agent Γ¨ un servizio Windows leggero che raccoglie informazioni sulle sessioni utente e le applicazioni in esecuzione.

v1.0.0 - 19 Dicembre 2025

  • βœ… Monitoraggio sessioni utente attive
  • βœ… Raccolta applicazioni in esecuzione (path, nome, icona)
  • βœ… Tracking connessioni TCP stabilite
  • βœ… Cache locale intelligente (invia solo dati nuovi)
  • βœ… Versioning e telemetria OS
  • βœ… Servizio Windows con auto-restart
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Macchina Utente β”‚
β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚
β”‚ β”‚ Corellix User Agent v1.0.0 β”‚ β”‚
β”‚ β”‚ β”‚ β”‚
β”‚ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β”‚
β”‚ β”‚ β”‚ App Collector β”‚ β”‚ Connection Collector β”‚ β”‚ β”‚
β”‚ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”‚
β”‚ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”‚
β”‚ β”‚ β–Ό β”‚ β”‚
β”‚ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β”‚
β”‚ β”‚ β”‚ Cache Locale β”‚ β”‚ β”‚
β”‚ β”‚ β”‚ (solo dati nuovi) β”‚ β”‚ β”‚
β”‚ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”‚
β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚ HTTP POST
β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Corellix Collector (:5050) β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
  1. Scarica CorellixUserAgent-1.0.0.zip
  2. Estrai ed esegui Setup.bat come amministratore
  3. Configura nel wizard:
    • Hostname/IP del Collector
    • Porta (default: 5050)
    • API Key (opzionale)
{
"AgentSettings": {
"ProxyServiceUrl": "http://localhost:5050",
"ApiKey": "",
"PollingIntervalSeconds": 30,
"MaxBatchSize": 500
}
}
ParametroDescrizioneDefault
ProxyServiceUrlURL completo del Collectorhttp://localhost:5050
ApiKeyChiave API per autenticazione(vuoto)
PollingIntervalSecondsIntervallo di raccolta dati30
MaxBatchSizeNumero massimo elementi per batch500
Terminal window
# Avviare il servizio
Start-Service CorellixUserAgent
# oppure
net start CorellixUserAgent
# Fermare il servizio
Stop-Service CorellixUserAgent
# Stato del servizio
Get-Service CorellixUserAgent
# Riavviare il servizio
Restart-Service CorellixUserAgent

Ogni richiesta al Collector include:

{
"agentHostName": "WORKSTATION-01",
"agentVersion": "1.0.0",
"osVersion": "Microsoft Windows NT 10.0.22631.0",
"osArchitecture": "X64",
"timestamp": "2025-12-19T10:30:00Z",
"appUsages": [
{
"sessionId": 2,
"userName": "DOMAIN\\user",
"applicationName": "Microsoft Word",
"processPath": "C:\\Program Files\\Microsoft Office\\...",
"timestamp": "2025-12-19T10:30:00Z"
}
],
"newApps": [
{
"processPath": "C:\\Program Files\\...",
"productName": "Microsoft Word",
"icon": "base64..."
}
]
}

Directory: C:\Program Files\Corellix\UserAgent\logs\

File: corellix-user-agent-YYYYMMDD.log

Terminal window
# Visualizza log in tempo reale
Get-Content "C:\Program Files\Corellix\UserAgent\logs\corellix-user-agent-*.log" -Tail 50 -Wait
Terminal window
# Via PowerShell
powershell -ExecutionPolicy Bypass -File Setup-CorellixUserAgent.ps1 -Uninstall
# Via sc.exe
net stop CorellixUserAgent
sc.exe delete CorellixUserAgent
RequisitoValore
OSWindows 7+ / Server 2012 R2+
.NET8.0 Runtime
RAM~50 MB
Disco~20 MB
ReteConnettivitΓ  verso Collector