Skip to content

Quest Software

Quest Software is a U.S.-based enterprise software vendor focused on systems management, identity and access management, database management, data protection, migration, and Microsoft platform administration.

Profile source: Mallory opens in a new tab

Quest Software

Family profile

Quest Software is a U.S.-based enterprise software vendor focused on systems management, identity and access management, database management, data protection, migration, and Microsoft platform administration. The company is widely known for products such as NetVault Backup, KACE, PowerGUI, and tools for Active Directory, PKI, and coexistence or migration scenarios involving Microsoft and legacy collaboration platforms. Quest has operated for decades in the enterprise IT market and serves organizations ranging from mid-sized businesses to large enterprises and public-sector environments.

From a cybersecurity perspective, Quest Software is relevant both as a software supplier and as a vendor whose products have been the subject of multiple publicly disclosed vulnerabilities. Quest NetVault Backup has had numerous high-severity issues disclosed in 2026, including SQL injection, command injection, authentication bypass, and cross-site scripting flaws affecting multiple components and creating potential paths to remote code execution. Quest Coexistence Manager for Notes was also reported vulnerable in 2025 to an HTTP request smuggling issue in its Free/Busy Connector. These disclosures make patch management and exposure assessment for Quest products particularly important in enterprise environments.

Quest has also appeared in the threat landscape as a victim organization in reporting on REvil ransomware activity. In addition, some Quest products and tooling have surfaced in intrusion reporting and administrative tradecraft, including PowerGUI in malware delivery chains and Quest administrative tools in enterprise identity operations. Overall, Quest Software is a significant enterprise infrastructure software provider with notable security relevance due to both product exposure and its presence in broader cyber incident reporting.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 15, 2026
Last activity
Aug 15, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • US1

Leading providers

  • Cloudflare, Inc.1

Infrastructure traits

  • Anycast 1
  • Hosting 1

Samples

Recent associated samples

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.