RMM

Beacon (Synertek)

Beacon is an AGPL-3.0-licensed remote monitoring and management project from Synertek Cloud Services. It is unrelated to Cobalt Strike Beacon. Its reviewed source installs a Go agent as a Windows service, Linux systemd unit, or macOS LaunchDaemon and uses an operator-controlled Cloudflare Workers/D1/R2 backend. This entry records source-confirmed artifacts only; it does not establish a delivery relationship or malicious use.

Tool overview

Category
RMM
Research authors
Michael Haag
Created
2026-09-28
Last modified
2026-09-28
Privileges
Installation creates a Windows service, Linux systemd unit, or macOS LaunchDaemon and requires administrative privileges; the source was not executed.
Free / availability
Yes
Verification required
Static source review at commit e3b790b72d18ed6243cc18759839ee2059022f6a. The service installer and credential store define the listed executable, service/unit/plist, credentials, and log paths. The project labels platform support as beta; no installer, backend, enrollment, or remote action was executed. The backend URL is supplied by an operator at installation, so it is intentionally not a generic network indicator.
Supported platforms
LinuxWindowsmacOS

Capabilities

Endpoint monitoring and inventoryRemote shell and scripted automationRemote management commandsSelf-hosted backend and enrollment

Executables & installation paths

Filename
beacon-agent.exe
OriginalFileName
Not recorded
Description
Windows service binary name set by the reviewed installer source; no PE metadata was inspected.

Installation paths

C:\Program Files\Beacon\beacon-agent.exe
C:\ProgramData\Beacon\credential.json
C:\ProgramData\Beacon\agent.log
/usr/local/bin/beacon-agent
/etc/systemd/system/beacon-agent.service
/etc/beacon/credential.json
/etc/beacon/agent.log
/Library/LaunchDaemons/com.beacon.agent.plist
/Library/Application Support/Beacon/credential.json
/Library/Application Support/Beacon/agent.log
/var/log/beacon-agent.log

FORENSIC EVIDENCE

Disk artifacts

File
C:\Program Files\Beacon\beacon-agent.exe
Description
Windows service installer destination.
OS
Windows
File
C:\ProgramData\Beacon\credential.json
Description
Windows system-service credential store path.
OS
Windows
File
C:\ProgramData\Beacon\agent.log
Description
Windows system-service log path, colocated with the credential store.
OS
Windows
File
/usr/local/bin/beacon-agent
Description
Linux agent executable destination.
OS
Linux
File
/usr/local/bin/beacon-agent
Description
macOS agent executable destination.
OS
macOS
File
/etc/systemd/system/beacon-agent.service
Description
Linux systemd unit written by the installer.
OS
Linux
File
/etc/beacon/credential.json
Description
Linux root-service credential store path.
OS
Linux
File
/etc/beacon/agent.log
Description
Linux root-service log path, colocated with the credential store.
OS
Linux
File
/Library/LaunchDaemons/com.beacon.agent.plist
Description
macOS LaunchDaemon plist written by the installer.
OS
macOS
File
/Library/Application Support/Beacon/credential.json
Description
macOS root-service credential store path.
OS
macOS
File
/Library/Application Support/Beacon/agent.log
Description
macOS root-service log path, colocated with the credential store.
OS
macOS
File
/var/log/beacon-agent.log
Description
Standard output and error path in the macOS LaunchDaemon plist.
OS
macOS

FORENSIC EVIDENCE

Event log artifacts

EventID
7045
ProviderName
Service Control Manager
LogFile
System
ServiceName
BeaconAgent
ImagePath
C:\Program Files\Beacon\beacon-agent.exe
Description
Windows installer creates the BeaconAgent automatic service from this binary; its server URL argument is operator supplied.
CommandLine
Not recorded

FORENSIC EVIDENCE

Other artifacts

Type
WindowsServiceName
Value
BeaconAgent
Type
LinuxSystemdUnit
Value
beacon-agent.service
Type
macOSLaunchDaemonLabel
Value
com.beacon.agent

References