RMM

Faronics Core

Faronics Core is the legacy on-premises endpoint management platform from Faronics Corporation (Vancouver, BC, Canada). It uses a four-tier architecture - Core Console (admin UI), Core Server (logic), Core Database (workstation inventory), and Core Agent (endpoint). The Core Agent (FaronicsCoreAgent.exe / CoreAgentService.exe) installs as a SYSTEM service on managed workstations and brokers communication between the Core Console / Server and the workstation, allowing remote task execution, software inventory, and loadout of Faronics modules (Deep Freeze, Anti-Executable, Anti-Virus, Power Save, WINSelect). Although mostly superseded by Faronics Deploy / Faronics Cloud, the Core Agent is still seen on long-running enterprise / education fleets and is part of the Faronics product family per LOLRMM issue 151.

Tool overview

Category
RMM
Research authors
@MHaggis
Created
2026-05-04
Last modified
2026-05-04
Privileges
SYSTEM
Free / availability
No
Verification required
Signed - 'Faronics Corporation' (DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 / DigiCert SHA2 Assured ID Code Signing CA / VeriSign Class 3 Code Signing 2010 CA)
Supported platforms
Windows

Capabilities

Centralized workstation management (legacy on-prem console)Software / hardware inventoryTask and command execution against managed workstationsLoadouts for Deep Freeze, Anti-Executable, Anti-Virus, Power Save, WINSelect, Insight, and other Faronics modulesMSI-based mass deployment of the Core Agent

Executables & installation paths

Filename
FaronicsCoreAgent.exe
OriginalFileName
FaronicsCoreAgent.exe
Description
Faronics Core Agent (workstation)
Filename
CoreAgentService.exe
OriginalFileName
CoreAgentService.exe
Description
Faronics Core Agent service host
Filename
FCAForStartupMonitor.msi
OriginalFileName
FCAForStartupMonitor.msi
Description
Faronics Core Agent startup-monitor MSI

Installation paths

C:\Program Files\Faronics\Faronics Core\*
C:\Program Files\Faronics\Faronics Core\Workstation Agent\*
C:\Program Files\Faronics\Core\Console\*
C:\Program Files (x86)\Faronics\Faronics Core\*
*\Faronics\Faronics Core\Workstation Agent\FaronicsCoreAgent.exe
*\Faronics\Faronics Core\Workstation Agent\CoreAgentService.exe
C:\ProgramData\Faronics\FCAForStartupMonitor.msi
FaronicsCoreAgent.exe
CoreAgentService.exe

FORENSIC EVIDENCE

Disk artifacts

File
C:\Program Files\Faronics\Faronics Core\Workstation Agent\FaronicsCoreAgent.exe
Description
Faronics Core Agent main executable
OS
Windows
File
C:\Program Files\Faronics\Faronics Core\Workstation Agent\CoreAgentService.exe
Description
Faronics Core Agent service host
OS
Windows
File
C:\ProgramData\Faronics\FCAForStartupMonitor.msi
Description
Faronics Core Agent startup-monitor MSI installer
OS
Windows

FORENSIC EVIDENCE

Event log artifacts

EventID
7045
ProviderName
Service Control Manager
LogFile
System.evtx
ServiceName
FaronicsCoreAgent
ImagePath
"C:\Program Files\Faronics\Faronics Core\Workstation Agent\FaronicsCoreAgent.exe"
Description
Service installation event for the Faronics Core Agent.

FORENSIC EVIDENCE

Registry artifacts

Path
HKLM\SYSTEM\CurrentControlSet\Services\FaronicsCoreAgent
Description
Faronics Core Agent Windows service registration
Path
HKLM\SOFTWARE\Faronics\Faronics Core 3
Description
Faronics Core 3 product configuration root
Path
HKLM\SOFTWARE\WOW6432Node\Faronics\Faronics Core 3
Description
Faronics Core 3 product configuration root (32-bit on 64-bit hosts)
Path
HKLM\SOFTWARE\Faronics
Description
Top-level Faronics product registry hive

FORENSIC EVIDENCE

Network artifacts

Description
Faronics Core legacy update / activation infrastructure
Domains
  • upd.faronicslabs.com
  • faronics.com
  • www.faronics.com
Ports
  • 80
  • 443
Description
Faronics Core Server <-> Core Agent on-prem communication. The Core Server hostname/IP is administrator-supplied (no fixed vendor domain) — hunt on TCP/7751-7752 to/from on-prem Core Server hosts and pair with the Disk / Registry / Process artifacts above. Default Faronics Core Server listener and Core Agent ports are documented by Faronics.
Domains
  • user_managed
Ports
  • 7751
  • 7752

Detections

Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/faronics_core_files_sigma.yml
Description
Detects potential files activity of Faronics Core RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/faronics_core_network_sigma.yml
Description
Detects potential network activity of Faronics Core RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/faronics_core_processes_sigma.yml
Description
Detects potential processes activity of Faronics Core RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/faronics_core_registry_sigma.yml
Description
Detects potential registry activity of Faronics Core RMM tool

References

Acknowledgements

Person
cbecks2
Handle
cbecks2
Person
Michael Haag
Handle
@MHaggis