{
  "Name": "Monitic",
  "Category": "RMM",
  "Description": "Monitic (monitic.com) is an EU/Turkey-based SaaS Remote Monitoring and Management (RMM) platform marketed at MSPs and IT departments. The product is operated by VAULT BİLİŞİM SİSTEMLERİ LTD.ŞTİ. (Turkish entity, Code Signing certificate via GlobalSign GCC R45 EV CodeSigning CA 2020) and exposes its tenant console at app.monitic.com with the agent control plane at api.monitic.com (both fronted by Cloudflare).\n\nThe Windows agent ships as two SYSTEM services installed under C:\\Program Files\\Monitic\\: a large (~50-60 MB) bundled `agent.exe` that embeds RustDesk dependencies (libvpx, WinPthreadGC) and the `kopia.io` backup engine for remote control, file transfer and backup, and a smaller (~6 MB) `amon.exe` watchdog/monitoring binary written in Go. A separate `MoniticInstaller.exe` bootstrapper (Themida-packed, signed by VAULT BİLİŞİM) is downloaded from app.monitic.com and uses `rundll32 url.dll,FileProtocolHandler https://app.monitic.com/installer` to drive the user through the install flow. An alternate silent installer is distributed as `agent_installer.bat` which downloads `installer.zip` from `https://api.monitic.com/api/ext/download-installer?t=<token>` via PowerShell `Net.WebClient.DownloadFile`, extracts it to `C:\\Program Files\\Monitic\\`, fetches `conf.json` from `https://api.monitic.com/api/ext/get-config?t=<token>`, then registers both services with `agent.exe install` and `amon.exe install`. A WebRTC TURN server is operated at `turn.monitic.com` (77.37.120.252) for RustDesk peer-to-peer relay.\n\nMonitic agents are flagged by the ProofPoint Emerging Threats Open ruleset (`ET INFO Observed RMM Domain in DNS Lookup ( * .monitic .com)` and `ET INFO Observed RMM Domain in TLS SNI ( * .monitic .com)`) and are classified as a remote-access tool that may be abused under MITRE ATT&CK T1219 (Remote Access Software). Sandbox engines (Zenbox, CAPE) frequently mis-classify the Themida-packed Go/.NET binaries as `Snake` / `Gocoder`, but Microsoft / Symantec / Kaspersky engine results are clean and the binaries are EV-code-signed.\n",
  "Author": "@MHaggis",
  "Created": "2026-05-04",
  "LastModified": "2026-05-04",
  "Details": {
    "Website": "https://www.monitic.com/",
    "PEMetadata": [
      {
        "Filename": "MoniticInstaller.exe",
        "OriginalFileName": "MoniticInstaller.exe",
        "Description": "Monitic agent bootstrap installer (Themida-packed Win32 PE, signed by VAULT BİLİŞİM SİSTEMLERİ LTD.ŞTİ. via GlobalSign GCC R45 EV CodeSigning CA 2020). Hosted at https://app.monitic.com/MoniticInstaller.exe; observed sha256 d641841cdf83037b32e699f01da16b66a9064221013dfec43d7a3bc993d6181d (3/2026) and 924238d5c8b4c882f236053c394d1a9510b6a1fe028ae5437eed7785774b1462 (7/2025). On launch it executes `rundll32 url.dll,FileProtocolHandler https://app.monitic.com/installer` to open the installer flow in the user's browser."
      },
      {
        "Filename": "amon.exe",
        "Description": "Monitic agent monitor / watchdog binary (~6 MB Go executable, Themida-packed, signed by VAULT BİLİŞİM SİSTEMLERİ LTD.ŞTİ.). Installed to C:\\Program Files\\Monitic\\amon.exe and registered as a SYSTEM service via `amon.exe install` then started with `amon.exe start`. Calls https://api.monitic.com/api/ext/check-sha256 for integrity check / config polling. Observed sha256 71cd67afd19f9f5d0cf00d92034c40b674e3b4d9888f5be6c2f401c52863a523 (10/2025)."
      },
      {
        "Filename": "agent.exe",
        "Description": "Monitic primary agent binary (~50-60 MB .NET executable, signed by VAULT BİLİŞİM SİSTEMLERİ LTD.ŞTİ.). Installed to C:\\Program Files\\Monitic\\agent.exe and registered as a SYSTEM service via `agent.exe install`. Bundles RustDesk for remote desktop (libvpx-1.dll, WinPthreadGC.dll observed in dropped-files), the kopia.io backup engine, and uses WMI (`Get-WmiObject Win32_BIOS / Win32_Processor / Win32_DiskDrive / Win32_BaseBoard`) for hardware fingerprinting. Spawns a child `tunnel.exe` (taskkill /IM tunnel.exe /F observed in lifecycle). Observed sha256 9c6b26fe30870775a42d02804c9094c83479850a87703d95ebd8631ad8188b8e (11/2025)."
      }
    ],
    "Privileges": "SYSTEM",
    "Free": "14-day free trial (no credit card)",
    "Verification": "Tenant signup required; corporate email accepted, no strict enforcement observed",
    "SupportedOS": [
      "Windows",
      "Linux",
      "MacOS"
    ],
    "Capabilities": [
      "Remote monitoring and management",
      "Remote access via bundled RustDesk (peer-to-peer with TURN relay at turn.monitic.com)",
      "Remote shell / command execution",
      "Patch management and Windows Update tracking",
      "Active Directory management and audit",
      "Hypervisor monitoring (Hyper-V, Docker)",
      "Network monitoring and management",
      "Asset inventory",
      "SMART / RAID disk health monitoring",
      "Antivirus monitoring and CVE detection",
      "Backup (kopia.io engine bundled in agent.exe)",
      "Event log management and security analytics",
      "API and web service uptime monitoring",
      "Certificate management",
      "Digital employee experience (DEX) monitoring"
    ],
    "Vulnerabilities": [],
    "InstallationPaths": [
      "C:\\Program Files\\Monitic\\*",
      "C:\\Program Files\\Monitic\\agent.exe",
      "C:\\Program Files\\Monitic\\amon.exe",
      "C:\\Program Files\\Monitic\\conf.json"
    ]
  },
  "Artifacts": {
    "Disk": [
      {
        "File": "C:\\Program Files\\Monitic\\agent.exe",
        "Description": "Monitic primary agent SYSTEM service binary (RustDesk + kopia bundle)",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files\\Monitic\\amon.exe",
        "Description": "Monitic monitor / watchdog SYSTEM service binary (Go, ~6 MB)",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files\\Monitic\\conf.json",
        "Description": "Per-tenant configuration file fetched from https://api.monitic.com/api/ext/get-config?t=<token> during install (referenced explicitly by agent_installer.bat)",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files\\Monitic\\*",
        "Description": "Monitic install directory — created/cleared by agent_installer.bat (`del /q \"C:\\Program Files\\Monitic\\*\"`) and populated from installer.zip",
        "OS": "Windows"
      },
      {
        "File": "%USERPROFILE%\\Desktop\\MoniticInstaller.exe",
        "Description": "Bootstrap installer download location when fetched manually from https://app.monitic.com/MoniticInstaller.exe (typical install layout — observed in CAPE/Zenbox sandbox traces)",
        "OS": "Windows"
      },
      {
        "File": "%TEMP%\\*\\agent_installer.bat",
        "Description": "Silent installer batch script — extracted to a temp directory before execution (observed path C:\\Users\\<user>\\AppData\\Local\\Temp\\<random>\\agent_installer.bat)",
        "OS": "Windows"
      },
      {
        "File": "%TEMP%\\*\\amon.exe",
        "Description": "Stage-1 amon.exe drop location (observed at C:\\Users\\user\\AppData\\Local\\Temp\\vx1nkas2.1am\\amon.exe before move to Program Files)",
        "OS": "Windows"
      },
      {
        "File": "%TEMP%\\*\\agent.exe",
        "Description": "Stage-1 agent.exe drop location (observed at C:\\Users\\user\\AppData\\Local\\Temp\\vx1nkas2.1am\\agent.exe before move to Program Files)",
        "OS": "Windows"
      },
      {
        "File": "%CD%\\installer.zip",
        "Description": "~58 MB ZIP downloaded from https://api.monitic.com/api/ext/download-installer?t=<token> via `powershell (New-Object Net.WebClient).DownloadFile(...)` — extracted to C:\\Program Files\\Monitic\\ via `[IO.Compression.ZipFile]::ExtractToDirectory()` then deleted (observed sha256 5a5303d57956589d2b6b27e70f8a2c9cb91b17954a3e52caf4549dd4e0863404)",
        "OS": "Windows"
      },
      {
        "File": "%CD%\\conf.json",
        "Description": "Transient configuration file downloaded from https://api.monitic.com/api/ext/get-config?t=<token> by agent_installer.bat then `copy`-ed to C:\\Program Files\\Monitic\\conf.json and deleted from working directory",
        "OS": "Windows"
      }
    ],
    "EventLog": [
      {
        "EventID": 7045,
        "ProviderName": "Service Control Manager",
        "LogFile": "System.evtx",
        "ImagePath": "\"C:\\\\Program Files\\\\Monitic\\\\agent.exe\"",
        "Description": "Service installation event resulting from `agent.exe install` invocation by Monitic agent_installer.bat (SYSTEM service registered for the primary RustDesk/kopia agent). The SCM service Name (Go service-installer subcommand value) was not directly observed — agent.exe is Themida-packed and no `services\\<name>` registry key surfaced in sandbox runs. Match on ImagePath."
      },
      {
        "EventID": 7045,
        "ProviderName": "Service Control Manager",
        "LogFile": "System.evtx",
        "ImagePath": "\"C:\\\\Program Files\\\\Monitic\\\\amon.exe\"",
        "Description": "Service installation event resulting from `amon.exe install` invocation by Monitic agent_installer.bat (SYSTEM service registered for the amon watchdog). Service Name not directly observed — match on ImagePath ending in `amon.exe`."
      },
      {
        "EventID": 4688,
        "ProviderName": "Microsoft-Windows-Security-Auditing",
        "LogFile": "Security.evtx",
        "CommandLine": "rundll32 url.dll,FileProtocolHandler https://app.monitic.com/installer",
        "Description": "MoniticInstaller.exe spawning rundll32 to open the installer enrollment URL via the default browser (observed in CAPE/Zenbox sandbox traces of the bootstrap installer)."
      },
      {
        "EventID": 4688,
        "ProviderName": "Microsoft-Windows-Security-Auditing",
        "LogFile": "Security.evtx",
        "CommandLine": "powershell -command \"& { (New-Object Net.WebClient).DownloadFile('https://api.monitic.com/api/ext/download-installer?t=<token>', 'installer.zip') }\"",
        "Description": "PowerShell download of installer.zip from api.monitic.com triggered by Monitic's agent_installer.bat."
      },
      {
        "EventID": 4688,
        "ProviderName": "Microsoft-Windows-Security-Auditing",
        "LogFile": "Security.evtx",
        "CommandLine": "powershell -command \"& { (New-Object Net.WebClient).DownloadFile('https://api.monitic.com/api/ext/get-config?t=<token>', 'conf.json') }\"",
        "Description": "PowerShell download of per-tenant conf.json from api.monitic.com triggered by Monitic's agent_installer.bat."
      },
      {
        "EventID": 4688,
        "ProviderName": "Microsoft-Windows-Security-Auditing",
        "LogFile": "Security.evtx",
        "CommandLine": "powershell -command \"& { Add-Type -A 'System.IO.Compression.FileSystem'; [IO.Compression.ZipFile]::ExtractToDirectory('installer.zip', 'C:\\Program Files\\Monitic') }\"",
        "Description": "PowerShell extraction of installer.zip into C:\\Program Files\\Monitic during Monitic install (observed verbatim in agent_installer.bat)."
      },
      {
        "EventID": 4688,
        "ProviderName": "Microsoft-Windows-Security-Auditing",
        "LogFile": "Security.evtx",
        "CommandLine": "\"C:\\\\Program Files\\\\Monitic\\\\agent.exe\" install",
        "Description": "Monitic agent.exe registering itself as a SYSTEM service via the `install` subcommand (called from agent_installer.bat)."
      },
      {
        "EventID": 4688,
        "ProviderName": "Microsoft-Windows-Security-Auditing",
        "LogFile": "Security.evtx",
        "CommandLine": "\"C:\\\\Program Files\\\\Monitic\\\\amon.exe\" install",
        "Description": "Monitic amon.exe registering itself as a SYSTEM service via the `install` subcommand (called from agent_installer.bat)."
      },
      {
        "EventID": 4688,
        "ProviderName": "Microsoft-Windows-Security-Auditing",
        "LogFile": "Security.evtx",
        "CommandLine": "\"C:\\\\Program Files\\\\Monitic\\\\amon.exe\" start",
        "Description": "Monitic amon.exe service start triggered by agent_installer.bat after installation."
      },
      {
        "EventID": 4688,
        "ProviderName": "Microsoft-Windows-Security-Auditing",
        "LogFile": "Security.evtx",
        "CommandLine": "powershell -NoProfile -NonInteractive -Command \"& {Get-WmiObject Win32_BIOS | Select-Object Manufacturer, SerialNumber | ConvertTo-Json -Compress}\"",
        "Description": "Hardware fingerprinting WMI query executed by Monitic agent.exe (observed in CAPE sandbox traces of agent.exe). Sibling queries seen for Win32_Processor, Win32_DiskDrive (Index=0) and Win32_BaseBoard."
      },
      {
        "EventID": 4688,
        "ProviderName": "Microsoft-Windows-Security-Auditing",
        "LogFile": "Security.evtx",
        "CommandLine": "taskkill /IM tunnel.exe /F",
        "Description": "Monitic agent.exe terminating its bundled tunnel.exe child during lifecycle / restart (observed in CAPE sandbox traces of agent.exe — `tunnel.exe` is the RustDesk tunneling helper)."
      }
    ],
    "Network": [
      {
        "Description": "Monitic agent control plane — config and installer download REST API (api.monitic.com/api/ext/get-config, /api/ext/download-installer, /api/ext/check-sha256, /api/ext/get-token)",
        "Domains": [
          "api.monitic.com"
        ],
        "Ports": [
          443
        ]
      },
      {
        "Description": "Monitic tenant web console / installer hosting (app.monitic.com/MoniticInstaller.exe, app.monitic.com/installer)",
        "Domains": [
          "app.monitic.com"
        ],
        "Ports": [
          443
        ]
      },
      {
        "Description": "Monitic developer / staging API (referenced in MoniticInstaller.exe embedded URLs — https://devapi.monitic.com/api/ext/download-installer)",
        "Domains": [
          "devapi.monitic.com"
        ],
        "Ports": [
          443
        ]
      },
      {
        "Description": "Monitic WebRTC TURN relay for RustDesk peer-to-peer remote control fallback (turn.monitic.com → 77.37.120.252)",
        "Domains": [
          "turn.monitic.com"
        ],
        "Ports": [
          443,
          3478
        ]
      },
      {
        "Description": "Monitic corporate / marketing site",
        "Domains": [
          "monitic.com",
          "www.monitic.com"
        ],
        "Ports": [
          443
        ]
      }
    ],
    "Other": [
      {
        "Type": "URL",
        "Value": "https://app.monitic.com/MoniticInstaller.exe"
      },
      {
        "Type": "URL",
        "Value": "https://app.monitic.com/installer"
      },
      {
        "Type": "URL",
        "Value": "https://api.monitic.com/api/ext/get-token"
      },
      {
        "Type": "URL",
        "Value": "https://api.monitic.com/api/ext/get-config"
      },
      {
        "Type": "URL",
        "Value": "https://api.monitic.com/api/ext/download-installer"
      },
      {
        "Type": "URL",
        "Value": "https://api.monitic.com/api/ext/check-sha256"
      },
      {
        "Type": "URL",
        "Value": "https://devapi.monitic.com/api/ext/download-installer"
      },
      {
        "Type": "IP",
        "Value": "77.37.120.252"
      },
      {
        "Type": "ProofpointETSignature",
        "Value": "ET INFO Observed RMM Domain in DNS Lookup ( * .monitic .com)"
      },
      {
        "Type": "ProofpointETSignature",
        "Value": "ET INFO Observed RMM Domain in TLS SNI ( * .monitic .com)"
      },
      {
        "Type": "CodeSigningSubject",
        "Value": "VAULT BİLİŞİM SİSTEMLERİ LTD.ŞTİ."
      },
      {
        "Type": "CodeSigningIssuer",
        "Value": "GlobalSign GCC R45 EV CodeSigning CA 2020"
      }
    ]
  },
  "Detections": [
    {
      "Sigma": "https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/monitic_files_sigma.yml",
      "Description": "Detects potential files activity of Monitic RMM tool"
    },
    {
      "Sigma": "https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/monitic_network_sigma.yml",
      "Description": "Detects potential network activity of Monitic RMM tool"
    },
    {
      "Sigma": "https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/monitic_processes_sigma.yml",
      "Description": "Detects potential processes activity of Monitic RMM tool"
    },
    {
      "Sigma": "https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/monitic_registry_sigma.yml",
      "Description": "Detects potential registry activity of Monitic RMM tool"
    }
  ],
  "References": [
    "https://www.monitic.com/",
    "https://www.monitic.com/en",
    "https://www.monitic.com/en/why-monitic",
    "https://www.monitic.com/faq",
    "https://www.monitic.com/en/features/streamlined-remote-access",
    "https://www.monitic.com/en/products/remote-access-and-control",
    "https://app.monitic.com/",
    "https://rules.emergingthreats.net/",
    "https://www.virustotal.com/gui/file/d641841cdf83037b32e699f01da16b66a9064221013dfec43d7a3bc993d6181d",
    "https://www.virustotal.com/gui/file/71cd67afd19f9f5d0cf00d92034c40b674e3b4d9888f5be6c2f401c52863a523",
    "https://www.virustotal.com/gui/file/9c6b26fe30870775a42d02804c9094c83479850a87703d95ebd8631ad8188b8e",
    "https://www.virustotal.com/gui/file/53cc6eb7f52e917e3d670337204e83c2dd68cb0e5c57384a1b3fe8d12d9a46bb",
    "https://www.virustotal.com/gui/domain/monitic.com",
    "https://www.virustotal.com/gui/domain/app.monitic.com",
    "https://www.virustotal.com/gui/domain/api.monitic.com",
    "https://www.virustotal.com/gui/domain/turn.monitic.com"
  ],
  "Acknowledgement": [
    {
      "Person": "Michael Haag",
      "Handle": "@M_haggis"
    }
  ]
}