RMM

Endar

Endar is an open-source, self-hosted RMM platform focused on endpoint monitoring and compliance policies. Its controller source exposes agent registration, policy retrieval, compliance-result, and data-collection endpoints. Static extraction of the sole GitHub 1.0.0 release asset identifies a Linux x86-64 PyInstaller endpoint agent with registration, policy, data-collection, and compliance-task code. The source for that agent is not in the repository, and the asset does not establish a default installation directory or service; this entry records only supported release evidence.

Tool overview

Category
RMM
Research authors
Michael Haag
Created
2026-09-28
Last modified
2026-09-28
Privileges
Depends on the commands in compliance policies; exact agent execution context was not established from the available source and release metadata.
Free / availability
Open source
Verification required
Static review of controller source at repository commit 359a4495cd13711c82419e944abee14cb5c04979 and GitHub release metadata for 1.0.0 (published 2022-10-27). The sole release asset was downloaded for inert metadata, hash, string, and PyInstaller archive review; it was not executed. SHA-256: 18f1d3189486cdcefb55e38edbe00462ea3b21b676714bf67dfec97d7c978327. Despite its .exe name and README claims for Windows, Linux, and macOS, the reviewed asset is Linux x86-64 only and no Windows or macOS agent artifact was available.
Supported platforms
Linux

Capabilities

Agent registration with a self-hosted controllerEndpoint metric collectionCompliance policy retrievalValidation and enforcement task reporting

Executables & installation paths

Filename
endar.exe
OriginalFileName
Not recorded
Description
Misleading release filename: the reviewed endar.exe is a stripped Linux x86-64 ELF PyInstaller executable, not a Windows PE. It bundles Python 3.8 and an endar.pyc entry point.

Installation paths

FORENSIC EVIDENCE

Network artifacts

Description
Documentation uses a self-hosted controller on TCP 5000 by default; a deployment can place it behind TLS or a reverse proxy. It has no shared vendor hostname.
Domains
Not recorded
Ports
Not recorded

FORENSIC EVIDENCE

Other artifacts

Type
ControllerDefaultPort
Value
5000
Type
AgentEntryPoint
Value
AppServerSvc
Type
BundledRuntime
Value
PyInstaller Python 3.8 on Linux x86-64
Type
CronPersistenceOption
Value
--cron
Type
ReviewedReleaseSHA256
Value
18f1d3189486cdcefb55e38edbe00462ea3b21b676714bf67dfec97d7c978327
Type
ControllerRegistrationRoute
Value
/api/v1/agent/register
Type
ControllerPolicyRoute
Value
/api/v1/agent/policy
Type
ControllerComplianceRoute
Value
/api/v1/agent/compliance
Type
ControllerDataCollectionRoute
Value
/api/v1/agent/collection

References

Acknowledgements

Person
tomkeene
Handle
@tomkeene