RMM
Allocentra
Allocentra is an endpoint remote monitoring and management (RMM) and PSA platform. Vendor documentation describes agents for Windows, Linux, and macOS that provide endpoint telemetry, patch management, remote commands, scripts, and MeshCentral-backed remote-control sessions.
Tool overview
- Category
- RMM
- Research authors
- Michael Haag
- Created
- 2026-09-22
- Last modified
- 2026-09-22
- Privileges
- Windows installation requires elevation; the documented Linux and macOS installer is run with sudo.
- Free / availability
- Not recorded
- Verification required
- The Windows agent was inspected statically without execution. Its full-file SHA-256 and PE metadata identify Allocentra RMM Agent, company Allocentra, and allocentra-agent.exe; it was unsigned at the time of inspection. Vendor documentation independently establishes Windows, Linux, and macOS agent support, the documented HTTPS API host, and the listed management capabilities. The binary contains a separate API-domain string under a .io domain; that value is intentionally not included as a network indicator because it was not correlated to the vendor documentation or runtime traffic. Ghidra decompilation confirms installation to C:\Program Files\Allocentra\Agent\allocentra-agent.exe, the AllocentraAgent service with its svc argument, configuration reads and writes under HKLM\SOFTWARE\Allocentra\Agent, and remote-command dispatch to CMD or PowerShell. The generated allocentra-update.bat update script is also present. Linux and macOS support and the shell installer name are vendor-documented; no Unix package, installed path, systemd unit, or launchd label was verified in this review.
- Supported platforms
Linux
Windows
macOS
Capabilities
Executables & installation paths
- Filename
- allocentra-agent.exe
- OriginalFileName
- allocentra-agent.exe
- Description
- Allocentra RMM Agent
Installation paths
C:\Program Files\Allocentra\Agent\allocentra-agent.exe
allocentra-agent.exe
FORENSIC EVIDENCE
Disk artifacts
- File
- *\allocentra\agent\allocentra-agent.exe
- Description
- Windows agent install destination confirmed in the decompiled service-install routine.
- OS
- Windows
- File
- *\allocentra-update.bat
- Description
- Update-script basename confirmed in decompiled Windows update code; generated under the process temporary directory, whose absolute path varies.
- OS
- Windows
FORENSIC EVIDENCE
Registry artifacts
- Path
- HKLM\SOFTWARE\Allocentra\Agent
- Description
- Agent enrollment and connection configuration read and written by the inspected Windows code; values can contain credentials and must not be published.
- Path
- HKLM\SYSTEM\CurrentControlSet\Services\AllocentraAgent
- Description
- Windows service key inferred from the AllocentraAgent service configuration confirmed in decompiled installation code; not a runtime observation.
FORENSIC EVIDENCE
Network artifacts
- Description
- Vendor-documented outbound API endpoint for agent deployment and operation.
- Domains
- api.allocentra.co.za
- Ports
- 443
FORENSIC EVIDENCE
Other artifacts
- Type
- WindowsServiceName
- Value
- AllocentraAgent
- Type
- WindowsServiceArgument
- Value
- svc
- Type
- DocumentedLinuxMacOSInstaller
- Value
- install-allocentra-agent.sh
- Type
- InspectedWindowsAgentSHA256
- Value
- 24c8e21c6de8726b32d5deafadf69e2ad923d672ed09cdccf23c923544daf358