RMM

BreezeRMM

BreezeRMM (Breeze) is an open-source remote monitoring and management platform developed by LanternOps, LLC. The vendor advertises remote access, fleet device management, patch management, script execution, software deployment, and monitoring across Windows, macOS, and Linux endpoints, with both self-hosted and managed cloud deployment options. Like other RMM agents, Breeze can be dropped and run by an operator to gain persistent remote access to endpoints. A Breeze agent sample is tracked on abuse.ch MalwareBazaar, and the on-disk artifacts below were reported in LOLRMM GitHub issue #235. A separately inspected unsigned Windows build identifies itself as PixoIT RMM Agent while retaining Breeze RMM Go module paths. Its product-specific filename is included as branded-build coverage; no PixoIT vendor affiliation or abuse of that build was established.

Tool overview

Category
RMM
Research authors
ChrisJr404
Created
2026-08-26
Last modified
2026-09-22
Privileges
User and SYSTEM
Free / availability
Yes
Verification required
The public Breeze website documents an open-source RMM with remote access, patching, script execution, and software deployment. The signer LanternOps, LLC and the on-disk artifacts are sourced from LOLRMM GitHub issue #235 and the linked abuse.ch MalwareBazaar sample. Static inspection of the separate PixoIT-branded version 0.105.5 build recovered github.com/breeze-rmm/agent module paths and coherent enrollment, heartbeat, remote desktop, terminal, file-transfer, inventory, and patch components. That sample's full-file SHA-256 was verified and it is unsigned; the LanternOps signer attribution does not apply to it. No PixoIT corporate relationship, installation path, live session, or abuse was established. Official Breeze v0.115.0 Linux and macOS release artifacts were inspected without execution. The Linux release binary and installer source confirm the systemd layout below. The notarized macOS package payload and its installer scripts confirm the LaunchDaemon, watchdog, desktop-helper LaunchAgents, binaries, Application Support directory, and log paths below. The PixoIT observations remain limited to the separately inspected Windows build; they do not establish PixoIT Linux or macOS support.
Supported platforms
LinuxWindowsmacOS

Capabilities

Remote accessRemote monitoringPatch managementScript executionSoftware deploymentMonitoring and alerting

Executables & installation paths

Filename
breeze-agent.exe
OriginalFileName
Not recorded
Description
Breeze RMM agent
Product
Breeze
Filename
breeze-watchdog.exe
OriginalFileName
Not recorded
Description
Breeze agent watchdog process
Product
Breeze
Filename
breeze-user-helper.exe
OriginalFileName
Not recorded
Description
Breeze user-context helper process
Product
Breeze
Filename
breeze-backup.exe
OriginalFileName
Not recorded
Description
Breeze agent backup component
Product
Breeze
Filename
PixoIT-agent.exe
OriginalFileName
PixoIT-agent.exe
Description
PixoIT RMM Agent
Product
PixoIT RMM Agent

Installation paths

C:\Program Files\Breeze\*
C:\ProgramData\Breeze\*
PixoIT-agent.exe
/usr/local/bin/breeze-agent
/usr/local/bin/breeze-watchdog
/usr/local/bin/breeze-backup
/usr/local/bin/breeze-desktop-helper
/etc/breeze/*
/var/lib/breeze/*
/var/log/breeze/*
/etc/systemd/system/breeze-agent.service
/Library/Application Support/Breeze/*
/Library/Logs/Breeze/*
/Library/LaunchDaemons/com.breeze.agent.plist
/Library/LaunchDaemons/com.breeze.watchdog.plist
/Library/LaunchAgents/com.breeze.desktop-helper-user.plist
/Library/LaunchAgents/com.breeze.desktop-helper-loginwindow.plist

Code signing

search names

breeze-agent.exe
breeze-watchdog.exe
breeze-user-helper.exe
breeze-backup.exe

company names

LanternOps, LLC

signer names

LanternOps, LLC

FORENSIC EVIDENCE

Disk artifacts

File
PixoIT-agent.exe
Description
Original filename of the unsigned PixoIT-branded Breeze RMM build, verified in PE resources; not an asserted standard installation path.
OS
Windows
File
C:\Program Files\Breeze\breeze-agent.exe
Description
Breeze RMM agent executable reported in issue 235.
OS
Windows
File
C:\Program Files\Breeze\breeze-watchdog.exe
Description
Breeze agent watchdog executable reported in issue 235.
OS
Windows
File
C:\Program Files\Breeze\breeze-user-helper.exe
Description
Breeze user-context helper executable reported in issue 235.
OS
Windows
File
C:\Program Files\Breeze\breeze-backup.exe
Description
Breeze agent backup executable reported in issue 235.
OS
Windows
File
C:\Program Files\Breeze\scripts\install\install-windows.ps1
Description
Breeze Windows install script reported in issue 235.
OS
Windows
File
C:\ProgramData\Breeze\agent.env
Description
Breeze agent environment configuration reported in issue 235.
OS
Windows
File
C:\ProgramData\Breeze\secrets.yaml
Description
Breeze agent secrets file reported in issue 235.
OS
Windows
File
C:\ProgramData\Breeze\logs\agent.log
Description
Breeze agent log file reported in issue 235.
OS
Windows
File
/usr/local/bin/breeze-agent
Description
Breeze agent binary installed by the official Linux installer and present in the official v0.115.0 macOS package payload.
OS
Linux/macOS
File
/usr/local/bin/breeze-watchdog
Description
Breeze watchdog binary installed by the official Linux installer when the matching helper binary is supplied, and present in the official v0.115.0 macOS package payload.
OS
Linux/macOS
File
/usr/local/bin/breeze-backup
Description
Breeze backup helper installed by the official Linux installer when the matching helper binary is supplied, and present in the official v0.115.0 macOS package payload.
OS
Linux/macOS
File
/usr/local/bin/breeze-desktop-helper
Description
Desktop helper present in the official v0.115.0 macOS package payload and referenced by its user-session and LoginWindow LaunchAgents.
OS
macOS
File
/etc/breeze/agent.yaml
Description
Default Breeze agent configuration path checked by the official Linux installer and referenced by the released Linux agent.
OS
Linux
File
/var/lib/breeze/*
Description
Breeze agent data directory created by the official Linux installer.
OS
Linux
File
/var/log/breeze/*
Description
Breeze log directory created by the official Linux installer; the released Linux agent references /var/log/breeze/agent.log.
OS
Linux
File
/var/run/breeze/agent.sock
Description
Breeze agent IPC socket path; the official Linux installer creates /var/run/breeze and the released Linux agent references agent.sock there.
OS
Linux
File
/etc/systemd/system/breeze-agent.service
Description
Official Breeze Linux systemd unit. It runs /usr/local/bin/breeze-agent start with /etc/breeze as its working directory and enables boot persistence.
OS
Linux
File
/usr/lib/systemd/user/breeze-agent-user.service
Description
Official per-user Breeze helper systemd unit installed when supplied with the Linux installer source.
OS
Linux
File
/etc/xdg/autostart/breeze-agent-user.desktop
Description
Official Breeze user-helper XDG autostart fallback installed by the Linux installer.
OS
Linux
File
/usr/lib/tmpfiles.d/breeze-agent.conf
Description
Official tmpfiles rule that creates /run/breeze at boot for Breeze agent IPC.
OS
Linux
File
/Library/Application Support/Breeze/*
Description
Breeze macOS configuration and IPC directory created by the v0.115.0 package postinstall script.
OS
macOS
File
/Library/Logs/Breeze/agent.log
Description
Standard output log path for the Breeze agent LaunchDaemon in the official v0.115.0 macOS package.
OS
macOS
File
/Library/Logs/Breeze/agent.err
Description
Standard error log path for the Breeze agent LaunchDaemon in the official v0.115.0 macOS package.
OS
macOS
File
/Library/Logs/Breeze/watchdog.log
Description
Standard output log path for the Breeze watchdog LaunchDaemon in the official v0.115.0 macOS package.
OS
macOS
File
/Library/Logs/Breeze/watchdog.err
Description
Standard error log path for the Breeze watchdog LaunchDaemon in the official v0.115.0 macOS package.
OS
macOS
File
/Library/LaunchDaemons/com.breeze.agent.plist
Description
Official Breeze macOS LaunchDaemon, label com.breeze.agent, that runs /usr/local/bin/breeze-agent run with RunAtLoad and KeepAlive.
OS
macOS
File
/Library/LaunchDaemons/com.breeze.watchdog.plist
Description
Official Breeze macOS watchdog LaunchDaemon, label com.breeze.watchdog, that runs /usr/local/bin/breeze-watchdog run with RunAtLoad and KeepAlive.
OS
macOS
File
/Library/LaunchAgents/com.breeze.desktop-helper-user.plist
Description
Official Breeze macOS Aqua-session LaunchAgent, label com.breeze.desktop-helper-user, that runs the desktop helper for user sessions.
OS
macOS
File
/Library/LaunchAgents/com.breeze.desktop-helper-loginwindow.plist
Description
Official Breeze macOS LoginWindow LaunchAgent, label com.breeze.desktop-helper-loginwindow, that runs the desktop helper before user login.
OS
macOS

FORENSIC EVIDENCE

Network artifacts

Description
Vendor-documented Breeze managed cloud service domains.
Domains
  • breezermm.com
  • breeze.app
  • us.2breeze.app
  • eu.2breeze.app
Ports
  • 443
Description
Self-hosted Breeze deployments use operator-supplied infrastructure; issue #235 notes network destinations depend on the build.
Domains
  • user_managed
Ports
  • 443

FORENSIC EVIDENCE

Other artifacts

Type
InspectedBrandedBuildSHA256
Value
74a9dc48d4d23983dbfc964422d57298c64234def5688a9b7e0f608b3043a66d
Type
BrandedBuildIdentity
Value
PixoIT RMM Agent 0.105.5; unsigned; compiled Go module github.com/breeze-rmm/agent.
Type
ObservedSHA256
Value
52dd8b2f9145907477a6ebc4ad406c1e4b221ea967f1c2ce8bc23faa83b663d8
Type
CodeSigningSigner
Value
LanternOps, LLC
Type
OfficialReleaseArtifactSHA256
Value
Breeze v0.115.0 Linux amd64 agent: bcf47edf1312f3480c172908fb36b1fc0b2a37f7c1df7a7434d99ae1850985af
Type
OfficialReleaseArtifactSHA256
Value
Breeze v0.115.0 macOS arm64 package: 8b32297661229f5173510ebbf1b6d656c85bd68fea930400808e138ce7c714d1

References

Acknowledgements

Person
Jason Killam
Handle
@rcKillam