Moorfox

Moorfox documentation

Guides for the people who use Moorfox day to day: enrolling machines, getting onto them, and keeping a fleet organised once it is bigger than you can hold in your head. Every screenshot is from a live dashboard.

Where to start

If you have just been given an account, read Add a device and then Connect and manage. That is the whole loop: get a machine in, get onto it, fix the thing.

Groups and tags becomes worth reading at around the second dozen machines, and it is what alert routing is built on, so read those two in order. The security score is how you decide which machines to work on first, patching is how the most common finding on that list fixes itself every week, and automation is how you stop doing the same fix by hand. The activity log answers who did what, and the device page reference is there for when a pill appears that you have not seen before.

Add a device

To add a device to Moorfox, open Add device in the dashboard, choose Windows or Linux, then choose Easy to download an installer to run on the machine, or Advanced to copy a one-line command.

Connect and manage

To connect to a device in Moorfox, open it from the device list and press Connect for a remote desktop session, or use the Manage tab for a terminal, file explorer, process list and service control without taking over the screen.

Groups and tags

In Moorfox a device belongs to exactly one group, which is how you split a fleet by customer or site, and carries any number of tags, which cut across groups.

Alerts and settings

Moorfox alert thresholds are set per type under Settings: CPU and memory each take a percentage and a sustained window, disk takes a percentage, offline takes a number of minutes, and Windows crashes are a switch.

Security score

The Moorfox security score grades each machine out of 100 across thirteen factors, including disk encryption, antivirus, firewall, patch compliance and OS support.

Patching

Moorfox agents scan Windows and Linux machines for pending updates, and a patch policy installs them inside a weekly window evaluated in each device's own timezone, optionally holding back anything that has been pending for fewer than a set number of days.

Automation

Moorfox automation has two layers: a command library of saved scripts, offered in the terminal and on the remote-desktop toolbar, and flows that chain those commands into a sequence run against a device as one unit, either manually or when a device is reported stolen.

Activity log

The Moorfox activity log is an append-only audit trail of everything that changed and who changed it.

Device page reference

The pills across the top of a Moorfox device page are, in order: online or offline, archived, the OS and architecture, the product type, whether UAC is available on Windows, the device's group, and one chip per tag.

Looking for definitions rather than instructions? The glossary covers the terms. The automation library has scripts you can paste into a Moorfox terminal.