RMM

Borealis

Borealis is an AGPL-3.0-licensed, self-hosted remote management, monitoring, and automation platform with a Linux-hosted Engine and a Go endpoint agent. Its reviewed source implements remote shell, file, process, service, and software operations, with Windows and Linux agent support. This entry records source-confirmed artifacts only; it does not establish a delivery relationship or malicious use.

Tool overview

Category
RMM
Research authors
Michael Haag
Created
2026-09-28
Last modified
2026-09-28
Privileges
Windows service registration and Linux installation to /opt with systemd units require administrative privileges; the source was not executed.
Free / availability
Yes
Verification required
Static source review at commit 19288159199132f29d276e4dbbbfa694807987ff. The build script emits Agent.exe for Windows and Agent for Linux; runtime source defines the BorealisAgent Windows service, default C:\Borealis bootstrap directory, agent.json alongside the executable, and the listed Linux path and units. No release binary, Engine deployment, enrollment, tunnel, or remote operation was run. Engine addresses, enrollment codes, and WireGuard settings are operator deployment data and are intentionally not generic network indicators. The project is actively developed; source review is not independent deployment or maturity validation.
Supported platforms
LinuxWindows

Capabilities

Endpoint inventory and telemetryRemote shell and signed script executionFile, process, service, and software operationsWindows remote desktopManaged WireGuard remote-operation tunnelSelf-hosted Linux Engine

Executables & installation paths

Filename
Not recorded
OriginalFileName
Not recorded
Description
The source build output is the generic name Agent.exe, so it is not retained as a filename detection selector; no PE metadata was inspected.

Installation paths

C:\Borealis\*
C:\Borealis\agent.json
C:\Borealis\Logs\Agent\agent.log
/opt/Borealis/Agent/Agent
/opt/Borealis/Agent/agent.json
/opt/Borealis/Agent/Logs/Agent/agent.log
/etc/systemd/system/borealis-agent.service
/etc/systemd/system/borealis-agent-updater.service
/etc/systemd/system/borealis-agent-watchdog.service

FORENSIC EVIDENCE

Disk artifacts

File
C:\Borealis\Agent.exe
Description
Default Windows bootstrap installation directory and agent filename in reviewed source.
OS
Windows
File
C:\Borealis\agent.json
Description
Agent configuration defaults beside Agent.exe.
OS
Windows
File
C:\Borealis\Logs\Agent\agent.log
Description
Agent log path is derived from the configuration directory.
OS
Windows
File
/opt/Borealis/Agent/Agent
Description
Linux agent service executable path.
OS
Linux
File
/opt/Borealis/Agent/agent.json
Description
Agent configuration defaults beside the Linux executable.
OS
Linux
File
/opt/Borealis/Agent/Logs/Agent/agent.log
Description
Agent log path is derived from the configuration directory.
OS
Linux
File
/etc/systemd/system/borealis-agent.service
Description
Linux agent systemd unit written by runtime source.
OS
Linux
File
/etc/systemd/system/borealis-agent-updater.service
Description
Linux updater systemd unit written by runtime source.
OS
Linux
File
/etc/systemd/system/borealis-agent-watchdog.service
Description
Linux watchdog systemd unit written by runtime source.
OS
Linux

FORENSIC EVIDENCE

Event log artifacts

EventID
7045
ProviderName
Service Control Manager
LogFile
System
ServiceName
BorealisAgent
ImagePath
C:\Borealis\Agent.exe
Description
Windows runtime creates this automatic service from the configured executable path; the default bootstrap path is C:\Borealis.
CommandLine
Not recorded

FORENSIC EVIDENCE

Other artifacts

Type
WindowsServiceName
Value
BorealisAgent
Type
LinuxSystemdUnit
Value
borealis-agent.service
Type
LinuxSystemdUnit
Value
borealis-agent-updater.service
Type
LinuxSystemdUnit
Value
borealis-agent-watchdog.service

References