{
  "Name": "BreezeRMM",
  "Category": "RMM",
  "Description": "BreezeRMM (Breeze) is an open-source remote monitoring and management platform developed by LanternOps, LLC. The vendor advertises remote access, fleet device management, patch management, script execution, software deployment, and monitoring across Windows, macOS, and Linux endpoints, with both self-hosted and managed cloud deployment options. Like other RMM agents, Breeze can be dropped and run by an operator to gain persistent remote access to endpoints. A Breeze agent sample is tracked on abuse.ch MalwareBazaar, and the on-disk artifacts below were reported in LOLRMM GitHub issue #235. A separately inspected unsigned Windows build identifies itself as PixoIT RMM Agent while retaining Breeze RMM Go module paths. Its product-specific filename is included as branded-build coverage; no PixoIT vendor affiliation or abuse of that build was established.\n",
  "Author": "ChrisJr404",
  "Created": "2026-08-26",
  "LastModified": "2026-09-22",
  "Details": {
    "Website": "https://breezermm.com/",
    "PEMetadata": [
      {
        "Filename": "breeze-agent.exe",
        "OriginalFileName": "",
        "Description": "Breeze RMM agent",
        "Product": "Breeze"
      },
      {
        "Filename": "breeze-watchdog.exe",
        "OriginalFileName": "",
        "Description": "Breeze agent watchdog process",
        "Product": "Breeze"
      },
      {
        "Filename": "breeze-user-helper.exe",
        "OriginalFileName": "",
        "Description": "Breeze user-context helper process",
        "Product": "Breeze"
      },
      {
        "Filename": "breeze-backup.exe",
        "OriginalFileName": "",
        "Description": "Breeze agent backup component",
        "Product": "Breeze"
      },
      {
        "Filename": "PixoIT-agent.exe",
        "OriginalFileName": "PixoIT-agent.exe",
        "Description": "PixoIT RMM Agent",
        "Product": "PixoIT RMM Agent"
      }
    ],
    "Privileges": "User and SYSTEM",
    "Free": true,
    "Verification": "The public Breeze website documents an open-source RMM with remote access, patching, script execution, and software deployment. The signer LanternOps, LLC and the on-disk artifacts are sourced from LOLRMM GitHub issue #235 and the linked abuse.ch MalwareBazaar sample. Static inspection of the separate PixoIT-branded version 0.105.5 build recovered github.com/breeze-rmm/agent module paths and coherent enrollment, heartbeat, remote desktop, terminal, file-transfer, inventory, and patch components. That sample's full-file SHA-256 was verified and it is unsigned; the LanternOps signer attribution does not apply to it. No PixoIT corporate relationship, installation path, live session, or abuse was established. Official Breeze v0.115.0 Linux and macOS release artifacts were inspected without execution. The Linux release binary and installer source confirm the systemd layout below. The notarized macOS package payload and its installer scripts confirm the LaunchDaemon, watchdog, desktop-helper LaunchAgents, binaries, Application Support directory, and log paths below. The PixoIT observations remain limited to the separately inspected Windows build; they do not establish PixoIT Linux or macOS support.\n",
    "SupportedOS": [
      "Windows",
      "macOS",
      "Linux"
    ],
    "Capabilities": [
      "Remote access",
      "Remote monitoring",
      "Patch management",
      "Script execution",
      "Software deployment",
      "Monitoring and alerting"
    ],
    "Vulnerabilities": [],
    "InstallationPaths": [
      "C:\\Program Files\\Breeze\\*",
      "C:\\ProgramData\\Breeze\\*",
      "PixoIT-agent.exe",
      "/usr/local/bin/breeze-agent",
      "/usr/local/bin/breeze-watchdog",
      "/usr/local/bin/breeze-backup",
      "/usr/local/bin/breeze-desktop-helper",
      "/etc/breeze/*",
      "/var/lib/breeze/*",
      "/var/log/breeze/*",
      "/etc/systemd/system/breeze-agent.service",
      "/Library/Application Support/Breeze/*",
      "/Library/Logs/Breeze/*",
      "/Library/LaunchDaemons/com.breeze.agent.plist",
      "/Library/LaunchDaemons/com.breeze.watchdog.plist",
      "/Library/LaunchAgents/com.breeze.desktop-helper-user.plist",
      "/Library/LaunchAgents/com.breeze.desktop-helper-loginwindow.plist"
    ]
  },
  "Artifacts": {
    "Disk": [
      {
        "File": "PixoIT-agent.exe",
        "Description": "Original filename of the unsigned PixoIT-branded Breeze RMM build, verified in PE resources; not an asserted standard installation path.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files\\Breeze\\breeze-agent.exe",
        "Description": "Breeze RMM agent executable reported in issue 235.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files\\Breeze\\breeze-watchdog.exe",
        "Description": "Breeze agent watchdog executable reported in issue 235.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files\\Breeze\\breeze-user-helper.exe",
        "Description": "Breeze user-context helper executable reported in issue 235.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files\\Breeze\\breeze-backup.exe",
        "Description": "Breeze agent backup executable reported in issue 235.",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files\\Breeze\\scripts\\install\\install-windows.ps1",
        "Description": "Breeze Windows install script reported in issue 235.",
        "OS": "Windows"
      },
      {
        "File": "C:\\ProgramData\\Breeze\\agent.env",
        "Description": "Breeze agent environment configuration reported in issue 235.",
        "OS": "Windows"
      },
      {
        "File": "C:\\ProgramData\\Breeze\\secrets.yaml",
        "Description": "Breeze agent secrets file reported in issue 235.",
        "OS": "Windows"
      },
      {
        "File": "C:\\ProgramData\\Breeze\\logs\\agent.log",
        "Description": "Breeze agent log file reported in issue 235.",
        "OS": "Windows"
      },
      {
        "File": "/usr/local/bin/breeze-agent",
        "Description": "Breeze agent binary installed by the official Linux installer and present in the official v0.115.0 macOS package payload.",
        "OS": "Linux/macOS"
      },
      {
        "File": "/usr/local/bin/breeze-watchdog",
        "Description": "Breeze watchdog binary installed by the official Linux installer when the matching helper binary is supplied, and present in the official v0.115.0 macOS package payload.",
        "OS": "Linux/macOS"
      },
      {
        "File": "/usr/local/bin/breeze-backup",
        "Description": "Breeze backup helper installed by the official Linux installer when the matching helper binary is supplied, and present in the official v0.115.0 macOS package payload.",
        "OS": "Linux/macOS"
      },
      {
        "File": "/usr/local/bin/breeze-desktop-helper",
        "Description": "Desktop helper present in the official v0.115.0 macOS package payload and referenced by its user-session and LoginWindow LaunchAgents.",
        "OS": "macOS"
      },
      {
        "File": "/etc/breeze/agent.yaml",
        "Description": "Default Breeze agent configuration path checked by the official Linux installer and referenced by the released Linux agent.",
        "OS": "Linux"
      },
      {
        "File": "/var/lib/breeze/*",
        "Description": "Breeze agent data directory created by the official Linux installer.",
        "OS": "Linux"
      },
      {
        "File": "/var/log/breeze/*",
        "Description": "Breeze log directory created by the official Linux installer; the released Linux agent references /var/log/breeze/agent.log.",
        "OS": "Linux"
      },
      {
        "File": "/var/run/breeze/agent.sock",
        "Description": "Breeze agent IPC socket path; the official Linux installer creates /var/run/breeze and the released Linux agent references agent.sock there.",
        "OS": "Linux"
      },
      {
        "File": "/etc/systemd/system/breeze-agent.service",
        "Description": "Official Breeze Linux systemd unit. It runs /usr/local/bin/breeze-agent start with /etc/breeze as its working directory and enables boot persistence.",
        "OS": "Linux"
      },
      {
        "File": "/usr/lib/systemd/user/breeze-agent-user.service",
        "Description": "Official per-user Breeze helper systemd unit installed when supplied with the Linux installer source.",
        "OS": "Linux"
      },
      {
        "File": "/etc/xdg/autostart/breeze-agent-user.desktop",
        "Description": "Official Breeze user-helper XDG autostart fallback installed by the Linux installer.",
        "OS": "Linux"
      },
      {
        "File": "/usr/lib/tmpfiles.d/breeze-agent.conf",
        "Description": "Official tmpfiles rule that creates /run/breeze at boot for Breeze agent IPC.",
        "OS": "Linux"
      },
      {
        "File": "/Library/Application Support/Breeze/*",
        "Description": "Breeze macOS configuration and IPC directory created by the v0.115.0 package postinstall script.",
        "OS": "macOS"
      },
      {
        "File": "/Library/Logs/Breeze/agent.log",
        "Description": "Standard output log path for the Breeze agent LaunchDaemon in the official v0.115.0 macOS package.",
        "OS": "macOS"
      },
      {
        "File": "/Library/Logs/Breeze/agent.err",
        "Description": "Standard error log path for the Breeze agent LaunchDaemon in the official v0.115.0 macOS package.",
        "OS": "macOS"
      },
      {
        "File": "/Library/Logs/Breeze/watchdog.log",
        "Description": "Standard output log path for the Breeze watchdog LaunchDaemon in the official v0.115.0 macOS package.",
        "OS": "macOS"
      },
      {
        "File": "/Library/Logs/Breeze/watchdog.err",
        "Description": "Standard error log path for the Breeze watchdog LaunchDaemon in the official v0.115.0 macOS package.",
        "OS": "macOS"
      },
      {
        "File": "/Library/LaunchDaemons/com.breeze.agent.plist",
        "Description": "Official Breeze macOS LaunchDaemon, label com.breeze.agent, that runs /usr/local/bin/breeze-agent run with RunAtLoad and KeepAlive.",
        "OS": "macOS"
      },
      {
        "File": "/Library/LaunchDaemons/com.breeze.watchdog.plist",
        "Description": "Official Breeze macOS watchdog LaunchDaemon, label com.breeze.watchdog, that runs /usr/local/bin/breeze-watchdog run with RunAtLoad and KeepAlive.",
        "OS": "macOS"
      },
      {
        "File": "/Library/LaunchAgents/com.breeze.desktop-helper-user.plist",
        "Description": "Official Breeze macOS Aqua-session LaunchAgent, label com.breeze.desktop-helper-user, that runs the desktop helper for user sessions.",
        "OS": "macOS"
      },
      {
        "File": "/Library/LaunchAgents/com.breeze.desktop-helper-loginwindow.plist",
        "Description": "Official Breeze macOS LoginWindow LaunchAgent, label com.breeze.desktop-helper-loginwindow, that runs the desktop helper before user login.",
        "OS": "macOS"
      }
    ],
    "EventLog": [],
    "Registry": [],
    "Network": [
      {
        "Description": "Vendor-documented Breeze managed cloud service domains.",
        "Domains": [
          "breezermm.com",
          "breeze.app",
          "us.2breeze.app",
          "eu.2breeze.app"
        ],
        "Ports": [
          443
        ]
      },
      {
        "Description": "Self-hosted Breeze deployments use operator-supplied infrastructure; issue #235 notes network destinations depend on the build.\n",
        "Domains": [
          "user_managed"
        ],
        "Ports": [
          443
        ]
      }
    ],
    "Other": [
      {
        "Type": "InspectedBrandedBuildSHA256",
        "Value": "74a9dc48d4d23983dbfc964422d57298c64234def5688a9b7e0f608b3043a66d"
      },
      {
        "Type": "BrandedBuildIdentity",
        "Value": "PixoIT RMM Agent 0.105.5; unsigned; compiled Go module github.com/breeze-rmm/agent."
      },
      {
        "Type": "ObservedSHA256",
        "Value": "52dd8b2f9145907477a6ebc4ad406c1e4b221ea967f1c2ce8bc23faa83b663d8"
      },
      {
        "Type": "CodeSigningSigner",
        "Value": "LanternOps, LLC"
      },
      {
        "Type": "OfficialReleaseArtifactSHA256",
        "Value": "Breeze v0.115.0 Linux amd64 agent: bcf47edf1312f3480c172908fb36b1fc0b2a37f7c1df7a7434d99ae1850985af"
      },
      {
        "Type": "OfficialReleaseArtifactSHA256",
        "Value": "Breeze v0.115.0 macOS arm64 package: 8b32297661229f5173510ebbf1b6d656c85bd68fea930400808e138ce7c714d1"
      }
    ]
  },
  "Detections": [],
  "References": [
    "https://breezermm.com/",
    "https://breeze.app/",
    "https://github.com/LanternOps/breeze",
    "https://github.com/LanternOps/breeze/releases/tag/v0.115.0",
    "https://github.com/LanternOps/breeze/blob/v0.115.0/agent/scripts/install/install-linux.sh",
    "https://bazaar.abuse.ch/sample/52dd8b2f9145907477a6ebc4ad406c1e4b221ea967f1c2ce8bc23faa83b663d8/",
    "https://github.com/magicsword-io/LOLRMM/issues/235"
  ],
  "Acknowledgement": [
    {
      "Person": "Jason Killam",
      "Handle": "@rcKillam"
    }
  ],
  "CodeSigning": {
    "search_names": [
      "breeze-agent.exe",
      "breeze-watchdog.exe",
      "breeze-user-helper.exe",
      "breeze-backup.exe"
    ],
    "company_names": [
      "LanternOps, LLC"
    ],
    "signer_names": [
      "LanternOps, LLC"
    ],
    "certificates": []
  }
}