RMM
Borealis
Borealis is an AGPL-3.0-licensed, self-hosted remote management, monitoring, and automation platform with a Linux-hosted Engine and a Go endpoint agent. Its reviewed source implements remote shell, file, process, service, and software operations, with Windows and Linux agent support. This entry records source-confirmed artifacts only; it does not establish a delivery relationship or malicious use.
Tool overview
- Category
- RMM
- Research authors
- Michael Haag
- Created
- 2026-09-28
- Last modified
- 2026-09-28
- Privileges
- Windows service registration and Linux installation to /opt with systemd units require administrative privileges; the source was not executed.
- Free / availability
- Yes
- Verification required
- Static source review at commit 19288159199132f29d276e4dbbbfa694807987ff. The build script emits Agent.exe for Windows and Agent for Linux; runtime source defines the BorealisAgent Windows service, default C:\Borealis bootstrap directory, agent.json alongside the executable, and the listed Linux path and units. No release binary, Engine deployment, enrollment, tunnel, or remote operation was run. Engine addresses, enrollment codes, and WireGuard settings are operator deployment data and are intentionally not generic network indicators. The project is actively developed; source review is not independent deployment or maturity validation.
- Supported platforms
Linux
Windows
Capabilities
Executables & installation paths
- Filename
- Not recorded
- OriginalFileName
- Not recorded
- Description
- The source build output is the generic name Agent.exe, so it is not retained as a filename detection selector; no PE metadata was inspected.
Installation paths
C:\Borealis\*
C:\Borealis\agent.json
C:\Borealis\Logs\Agent\agent.log
/opt/Borealis/Agent/Agent
/opt/Borealis/Agent/agent.json
/opt/Borealis/Agent/Logs/Agent/agent.log
/etc/systemd/system/borealis-agent.service
/etc/systemd/system/borealis-agent-updater.service
/etc/systemd/system/borealis-agent-watchdog.service
FORENSIC EVIDENCE
Disk artifacts
- File
- C:\Borealis\Agent.exe
- Description
- Default Windows bootstrap installation directory and agent filename in reviewed source.
- OS
- Windows
- File
- C:\Borealis\agent.json
- Description
- Agent configuration defaults beside Agent.exe.
- OS
- Windows
- File
- C:\Borealis\Logs\Agent\agent.log
- Description
- Agent log path is derived from the configuration directory.
- OS
- Windows
- File
- /opt/Borealis/Agent/Agent
- Description
- Linux agent service executable path.
- OS
- Linux
- File
- /opt/Borealis/Agent/agent.json
- Description
- Agent configuration defaults beside the Linux executable.
- OS
- Linux
- File
- /opt/Borealis/Agent/Logs/Agent/agent.log
- Description
- Agent log path is derived from the configuration directory.
- OS
- Linux
- File
- /etc/systemd/system/borealis-agent.service
- Description
- Linux agent systemd unit written by runtime source.
- OS
- Linux
- File
- /etc/systemd/system/borealis-agent-updater.service
- Description
- Linux updater systemd unit written by runtime source.
- OS
- Linux
- File
- /etc/systemd/system/borealis-agent-watchdog.service
- Description
- Linux watchdog systemd unit written by runtime source.
- OS
- Linux
FORENSIC EVIDENCE
Event log artifacts
- EventID
- 7045
- ProviderName
- Service Control Manager
- LogFile
- System
- ServiceName
- BorealisAgent
- ImagePath
- C:\Borealis\Agent.exe
- Description
- Windows runtime creates this automatic service from the configured executable path; the default bootstrap path is C:\Borealis.
- CommandLine
- Not recorded
FORENSIC EVIDENCE
Other artifacts
- Type
- WindowsServiceName
- Value
- BorealisAgent
- Type
- LinuxSystemdUnit
- Value
- borealis-agent.service
- Type
- LinuxSystemdUnit
- Value
- borealis-agent-updater.service
- Type
- LinuxSystemdUnit
- Value
- borealis-agent-watchdog.service
References
- https://github.com/bunny-lab-io/Borealis/blob/19288159199132f29d276e4dbbbfa694807987ff/README.md
- https://github.com/bunny-lab-io/Borealis/blob/19288159199132f29d276e4dbbbfa694807987ff/Data/Agent/build-agent.sh
- https://github.com/bunny-lab-io/Borealis/blob/19288159199132f29d276e4dbbbfa694807987ff/Data/Agent/internal/runtime/service.go
- https://github.com/bunny-lab-io/Borealis/blob/19288159199132f29d276e4dbbbfa694807987ff/Data/Agent/internal/runtime/service_windows.go
- https://github.com/bunny-lab-io/Borealis/blob/19288159199132f29d276e4dbbbfa694807987ff/Data/Agent/internal/runtime/service_unix.go
- https://github.com/bunny-lab-io/Borealis/blob/19288159199132f29d276e4dbbbfa694807987ff/Data/Agent/cmd/agent/bootstrap-config.go