Skip to content

Security

ARROW Control gives you a terminal, a remote desktop, and a file browser on the device, straight from your browser. That is a lot of reach, so it is fenced in carefully. This page covers how. For platform-wide protections, start with Security.

ARROW Control answers only over the private VPN. There is no public address and no other way in. Getting on the VPN comes first, every time, and then you sign in with the device’s own system account. See Accessing ARROW Control for the full connection steps.

Being on the VPN does not let you into every device on it. A consultant can reach a device only when they are assigned to it in the Console, and ARROW keeps that in sync automatically: assign a consultant and their access appears within a few minutes, unassign them and it is revoked just as automatically. You never write a firewall rule by hand. See Network Access Control for the model.

Access is intentionally one-way. You can reach a device over SSH, VNC, and other management protocols, but the device can never open a connection back toward your workstation. This is the exact protection you want in ARROW’s job: if a box you are testing from gets compromised, it cannot turn around and pivot into your own machine or the rest of your infrastructure.

Terminal sessions in ARROW Control can be recorded and reviewed later in Terminal Logs, so there is a record of what was run on a device and when. On an engagement that others may need to audit, that record is the difference between “we think” and “we know.”

Everything ARROW Control touches lives on the device’s encrypted storage. A lost or seized device does not give up its files, its history, or its credentials. See Hardware Security.

  • Protect the system credentials. ARROW Control signs you in with the VM’s own account. Treat those credentials like any other sensitive login and do not share them outside the people assigned to the engagement.
  • Close out when you are done. End sessions you are not using, and sign out on any computer that is not your own.
  • Report anything unexpected. If you see a session, file, or process you did not start, contact support rather than digging into it yourself.