RMM

GLPI Agent

GLPI Agent is the open-source generic management agent maintained by the GLPI Project (Teclib'). It performs IT asset inventory, network discovery, network inventory (SNMP), VMware ESX inventory, software deployment, remote inventory and remote command/script collection on behalf of a GLPI server, communicating over HTTP/HTTPS. The agent is shipped as a Perl-based service / daemon for Windows, Linux and macOS, and is a fork of the FusionInventory agent. Network endpoints are tenant-configured: the agent talks to whatever GLPI server URL the operator specifies via the `server` parameter (or the MSI `SERVER` property). There is no centralised vendor cloud — every install can point at a different self-hosted (or Teclib-hosted GLPI Network) endpoint, which makes the agent attractive for both legitimate self-hosted IT shops and threat actors who stand up their own GLPI server for inventory/deploy abuse. The agent also embeds an HTTP daemon (default port 62354/tcp) for server-initiated triggers.

Tool overview

Category
RMM
Research authors
@MHaggis
Created
2026-05-04
Last modified
2026-05-04
Privileges
SYSTEM
Free / availability
Yes
Verification required
None (open source — anyone can download and operate a GLPI server + agent)
Supported platforms
LinuxWindowsmacOS

Capabilities

IT asset / hardware / software inventory (Inventory task)SNMP network discovery (NetDiscovery task)SNMP network inventory (NetInventory task)VMware ESX inventory (ESX task)Software deployment (Deploy task — push files / execute commands on managed endpoints)Remote inventory over SSH / WinRM (RemoteInventory task)Data collection from arbitrary registry keys, files and WMI queries (Collect task)Wake-on-LAN (WakeOnLan task)Embedded HTTP daemon for server-initiated task triggers (default 62354/tcp)Self-hosted / on-premise — agent talks to operator-configured GLPI server URL (no centralised vendor cloud)

Executables & installation paths

Filename
glpi-agent
Description
Main GLPI Agent executable / Perl entrypoint
Filename
glpi-win32-service
Description
Windows service wrapper that hosts the GLPI Agent as a Windows service (only available on win32)
Filename
glpi-inventory
Description
Standalone inventory collector (offline / one-shot inventory)
Filename
glpi-netdiscovery
Description
SNMP-based network discovery task binary
Filename
glpi-netinventory
Description
SNMP-based network inventory task binary
Filename
glpi-esx
Description
VMware ESX inventory task binary
Filename
glpi-injector
Description
Inventory data injection / push utility
Filename
glpi-remote
Description
Remote agent management utility (SSH / WinRM remote inventory)

Installation paths

C:\Program Files\GLPI-Agent\*
C:\Program Files\GLPI-Agent\perl\bin\*
C:\Program Files\GLPI-Agent\etc\*
C:\Program Files\GLPI-Agent\var\*
C:\Program Files\GLPI-Agent\logs\*
/usr/bin/glpi-agent
/usr/local/bin/glpi-agent
/etc/glpi-agent/*
/var/lib/glpi-agent/*
/Applications/GLPI-Agent/*
/Applications/GLPI-Agent/etc/*

FORENSIC EVIDENCE

Disk artifacts

File
C:\Program Files\GLPI-Agent\perl\bin\glpi-agent
Description
GLPI Agent main Perl entrypoint (Windows install)
OS
Windows
File
C:\Program Files\GLPI-Agent\perl\bin\glpi-win32-service.bat
Description
Windows service wrapper script that hosts the agent as a Windows service
OS
Windows
File
C:\Program Files\GLPI-Agent\perl\bin\glpi-inventory
Description
Standalone inventory collector (offline / one-shot)
OS
Windows
File
C:\Program Files\GLPI-Agent\perl\bin\glpi-netdiscovery
Description
SNMP network discovery task binary
OS
Windows
File
C:\Program Files\GLPI-Agent\perl\bin\glpi-netinventory
Description
SNMP network inventory task binary
OS
Windows
File
C:\Program Files\GLPI-Agent\perl\bin\glpi-esx
Description
VMware ESX inventory task binary
OS
Windows
File
C:\Program Files\GLPI-Agent\perl\bin\glpi-injector
Description
Inventory data injection / push utility
OS
Windows
File
C:\Program Files\GLPI-Agent\perl\bin\glpi-remote
Description
Remote agent management utility (SSH / WinRM-based remote inventory)
OS
Windows
File
C:\Program Files\GLPI-Agent\perl\bin\perl.exe
Description
Strawberry Perl interpreter bundled with the GLPI Agent MSI
OS
Windows
File
C:\Program Files\GLPI-Agent\perl\bin\wperl.exe
Description
Strawberry Perl windowless interpreter bundled with the GLPI Agent MSI
OS
Windows
File
C:\Program Files\GLPI-Agent\etc\agent.cfg
Description
GLPI Agent configuration file (Windows portable mode and override location)
OS
Windows
File
C:\Program Files\GLPI-Agent\logs\glpi-agent.log
Description
Default GLPI Agent log file path on Windows
OS
Windows
File
C:\Program Files\GLPI-Agent\var\*
Description
GLPI Agent variable / state directory (cached inventory, last-run state)
OS
Windows
File
/usr/bin/glpi-agent
Description
GLPI Agent main binary on Linux package installs (.deb / .rpm)
OS
Linux
File
/usr/local/bin/glpi-agent
Description
GLPI Agent main binary on Linux AppImage installs (default --installpath)
OS
Linux
File
/etc/glpi-agent/agent.cfg
Description
GLPI Agent main configuration file on Linux (FHS layout)
OS
Linux
File
/etc/glpi-agent/conf.d/*
Description
GLPI Agent configuration overrides directory (preserved across package upgrades)
OS
Linux
File
/var/lib/glpi-agent/*
Description
GLPI Agent variable / state directory on Linux (cached inventory, last-run state)
OS
Linux
File
/lib/systemd/system/glpi-agent.service
Description
systemd unit file shipped by glpi-agent .deb / .rpm packages — ExecStart=/usr/bin/glpi-agent --daemon --no-fork $OPTIONS
OS
Linux
File
/Applications/GLPI-Agent/etc/agent.cfg
Description
GLPI Agent main configuration file on macOS
OS
MacOS
File
/Applications/GLPI-Agent/etc/conf.d/*
Description
GLPI Agent configuration overrides directory on macOS
OS
MacOS

FORENSIC EVIDENCE

Event log artifacts

EventID
7045
ProviderName
Service Control Manager
LogFile
System.evtx
ServiceName
glpi-agent
ImagePath
C:\\Program Files\\GLPI-Agent\\perl\\bin\\perl.exe "C:\\Program Files\\GLPI-Agent\\perl\\bin\\glpi-win32-service"
Description
Service installation event recorded when the GLPI Agent MSI installs in service mode (EXECMODE=1) — service Name=`glpi-agent` (DisplayName "GLPI Agent") confirmed via msiinfo against GLPI-Agent-1.17-x64.msi ServiceInstall table; hosted by glpi-win32-service running under perl.exe.
EventID
11707
ProviderName
MsiInstaller
LogFile
Application.evtx
Data
Product: GLPI Agent <version> -- Installation completed successfully.
Description
MSI installer success event from the GLPI-Agent-<version>-x64.msi package. ProductName is versioned in the actual log Data string (e.g. `Product: GLPI Agent 1.17 --`); confirmed against the MSI Property table.
EventID
4688
ProviderName
Microsoft-Windows-Security-Auditing
LogFile
Security.evtx
CommandLine
C:\\Program Files\\GLPI-Agent\\perl\\bin\\perl.exe "C:\\Program Files\\GLPI-Agent\\perl\\bin\\glpi-agent" --server=<URL> --tag=<TAG>
Description
Process creation observed when the GLPI Agent runs an inventory or task — perl.exe spawned with the glpi-agent script and the operator-configured server URL.

FORENSIC EVIDENCE

Registry artifacts

Path
HKLM\SOFTWARE\GLPI-Agent
Description
GLPI Agent root configuration key on 64-bit Windows agents (server URL, tag, httpd-port, tasks, log paths and every other agent.cfg parameter are mirrored here by the MSI)
Path
HKLM\SOFTWARE\WOW6432Node\GLPI-Agent
Description
GLPI Agent root configuration key on 32-bit-on-64 installs (mirrors HKLM\SOFTWARE\GLPI-Agent)
Path
HKLM\SOFTWARE\GLPI-Agent\Installer
Description
GLPI Agent installer state — Version, InstallDir, ExecMode, RunNow, AddFirewallException, TaskFrequency etc.
Path
HKLM\SOFTWARE\GLPI-Agent\Installer\Version
Description
Installed GLPI Agent version string — checked by glpi-agent-deployment.vbs to decide install / repair / reconfigure
Path
HKLM\SOFTWARE\WOW6432Node\GLPI-Agent\Installer\Version
Description
Installed GLPI Agent version string (32-bit registry view)
Path
HKLM\SOFTWARE\GLPI-Agent\Monitor
Description
GLPI-Agent-Monitor (system tray monitor) settings
Path
HKLM\SOFTWARE\GLPI-Agent\server
Description
server parameter — operator-configured GLPI server URL(s) the agent reports to
Path
HKLM\SOFTWARE\GLPI-Agent\httpd-port
Description
Embedded HTTP daemon listen port (default 62354)
Path
HKLM\SOFTWARE\GLPI-Agent\httpd-ip
Description
Embedded HTTP daemon listen address (default 0.0.0.0)
Path
HKLM\SOFTWARE\GLPI-Agent\httpd-trust
Description
Trusted IPs allowed to trigger tasks via the embedded HTTP daemon without authentication
Path
HKLM\SOFTWARE\GLPI-Agent\tag
Description
Computer identification tag pushed with inventory
Path
HKLM\SOFTWARE\GLPI-Agent\tasks
Description
Comma-separated task list the agent will execute (Inventory, NetInventory, NetDiscovery, ESX, Deploy, Collect, RemoteInventory, WakeOnLan)

FORENSIC EVIDENCE

Network artifacts

Description
Embedded HTTP daemon listen port — the GLPI server (or the operator) connects to this port to trigger tasks on the endpoint. Default `httpd-port=62354` per the MSI properties; configurable.
Domains
Not recorded
Ports
  • 62354
Description
Outbound connection from agent to the operator-configured GLPI server (`server` parameter / MSI `SERVER` property). Endpoints are tenant-configured, not centralised — the agent talks to whatever URL the operator specifies (self-hosted GLPI, GLPI Network or attacker-controlled server).
Domains
  • <operator-configured GLPI server>
Ports
  • 80
  • 443
Description
Official GLPI Project website — referenced from the agent (URLAbout) and used to download the agent installer
Domains
  • glpi-project.org
  • www.glpi-project.org
Ports
  • 443
Description
GLPI Project nightly build server — referenced by the bundled glpi-agent-deployment.vbs as `SetupNightlyLocation` (alternative install source)
Domains
  • nightly.glpi-project.org
Ports
  • 443
Description
GLPI Project community forum — bundled in MSI metadata as the support URL
Domains
  • forum.glpi-project.org
Ports
  • 443
Description
Teclib commercial offering for GLPI (paid services, plugins, support) — operated by Teclib', the company that maintains GLPI and the GLPI Agent
Domains
  • glpi-network.com
  • services.glpi-network.com
Ports
  • 443
Description
GitHub release host for the GLPI Agent installers (MSI / PKG / DEB / RPM / AppImage downloaded from this host by deployment scripts)
Domains
  • github.com
  • objects.githubusercontent.com
Ports
  • 443

FORENSIC EVIDENCE

Other artifacts

Type
Other
Value
MSI default install path: C:\Program Files\GLPI-Agent (INSTALLDIR property)
Type
Other
Value
MSI execution modes: EXECMODE=1 (Service), EXECMODE=2 (Task scheduler), EXECMODE=3 (Manual)
Type
Other
Value
MSI public properties used to silently configure the agent at install time: SERVER, TAG, USER, PASSWORD, TIMEOUT, RUNNOW, EXECMODE, HTTPD_IP, HTTPD_PORT, HTTPD_TRUST, ADDLOCAL
Type
Other
Value
systemd unit on Linux: glpi-agent.service (ExecStart=/usr/bin/glpi-agent --daemon --no-fork $OPTIONS, After=syslog.target network.target, CapabilityBoundingSet=~CAP_SYS_PTRACE)
Type
Other
Value
Default embedded HTTP daemon listen port: 62354/tcp (httpd-port parameter)
Type
Other
Value
Code-signing publisher: Teclib' (per MSI Manufacturer string in Variables-v2.wxi.tt — Manufacturer="Teclib'")
Type
Other
Value
GLPI Agent 1.17 x64 MSI SHA-256: db2661a14359931a2d14ed7268f9b90763da4f2bec97b5ed8d51b9bb655d730c (signed via GlobalSign GCC R45 EV CodeSigning CA 2020 — OCSP host ocsp.globalsign.com)

Detections

Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/glpi_files_sigma.yml
Description
Detects potential files activity of GLPI RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/glpi_network_sigma.yml
Description
Detects potential network activity of GLPI RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/glpi_processes_sigma.yml
Description
Detects potential processes activity of GLPI RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/glpi_registry_sigma.yml
Description
Detects potential registry activity of GLPI RMM tool

References

Acknowledgements

Person
Michael Haag
Handle
@M_haggis