Unexpected computers can appear in the portal inventory for the following reasons:
Cause – security tool sandboxing: Endpoint protection products such as EDR/AV, VPN clients or next‑generation firewalls often download and “explode” (install) the ABR MSI in a virtual sandbox to analyze its behavior. Because the ABR installer embeds its licence, the security software completes the install and registers the sandbox in the portal without requiring manual license entry.
Common: This behavior is widespread among major security vendors; new sandboxes continue to emerge despite our ongoing efforts to detect and mitigate them.
Typical indicators: These phantom entries frequently report old operating systems (e.g., Windows 7/10), generic hostnames and minimal system activity.
Past vs present: In the past, the device’s IP address could be traced back to the security tool vendor, but many modern sandboxes route their traffic through Tor or other anonymizing networks, making the source IP less useful.
Remediation: If you see an unknown device with these traits, it’s usually safe to delete it from your inventory. Removing these entries does not impact your real endpoints.
Refer to Unexpected Inventory Computers for more information.