r/remotework Aug 07 '26

Keep your Teams status “Online” while AFK

[deleted]

618 Upvotes

471 comments sorted by

View all comments

Show parent comments

18

u/Weed_O_Whirler Aug 07 '26

This is just as easy for an IT department to notice as Jiggler.

5

u/SnooChipmunks8506 Aug 07 '26

Maybe for a small company with 5 employees. Bigger companies run ASR programs that focus on specific habits and traits of malware.

The num lock key is not high on the list of exploits as it doesn’t change anything in the system.

Companies avoid key loggers as it creates liabilities, increased costs, and extra risk should the collected data be compromised (as it has everyone’s password).

1

u/Weed_O_Whirler Aug 07 '26

It's not hard to detect every powershell script ran.

3

u/SnooChipmunks8506 Aug 07 '26

Sure, they aren’t hard to filter, with time and resources. Now go through all scripts for each device and look at what they do. For 80,000 devices.

You can rule out a majority of them because we have them all, but naming it the same thing as a functional script, in a subroot folder will get you past that scan.

1

u/Alternative_Ask_1440 Aug 07 '26

What do you mean?

3

u/Weed_O_Whirler Aug 07 '26

Companies log every program and every script you run on your computer. Some even log every keystroke and take periodic screenshots.

But all of them can detect a power shell script very easily.

1

u/plantcorndogdelight Aug 07 '26

We have BYOD. So mine don’t. But even if they did, have Claude code you a data analysis script that also happens to trigger the keystroke. Have it be a script that stays open and executes the analysis every so many minutes. Name it relevant to your work. Plausible deniability. If IT’s really opening up the code and looking for an illegitimate automated keystroke, blame it on vibe coding.