RMM

Go Mini RMM

Go Mini RMM is an open-source Go management server and endpoint agent. The agent sends heartbeats, connects to a controller WebSocket, executes remote commands, transfers files, lists and terminates processes, and checks for updates. The repository supplies a Linux systemd installer and a Windows scheduled-task installer. It is distinct from LOLRMM's existing Mini RMM entry, which documents a different .NET product.

Tool overview

Category
RMM
Research authors
Michael Haag
Created
2026-09-28
Last modified
2026-09-28
Privileges
The Windows installer requires Administrator and creates a scheduled task running as SYSTEM; the Linux installer requires root and creates a systemd service.
Free / availability
Open source
Verification required
Static source review only at repository commit 9b24b1749b5dac0a14bee4ce026181cec0843a08. No server, agent, installer, task, systemd unit, enrollment, or controller endpoint was executed or contacted. The product does not provide an independently validated, vendor-operated controller domain.
Supported platforms
LinuxWindows

Capabilities

System metrics heartbeatController WebSocket command executionFile transfer and file browsingProcess listing and terminationNetwork connection listingAgent update checks

Executables & installation paths

Filename
agent.exe
OriginalFileName
Not recorded
Description
Generic Windows agent filename used by the repository installer; filename-only process detection would be too broad.

Installation paths

FORENSIC EVIDENCE

Disk artifacts

File
C:\rmm\agent.exe
Description
Windows installer download location for the generically named agent binary.
OS
Windows
File
C:\rmm\config.json
Description
Windows installer configuration containing controller URL, agent key, and agent name.
OS
Windows
File
/opt/rmm/agent
Description
Linux installer agent path.
OS
Linux
File
/etc/systemd/system/rmm-agent.service
Description
Linux systemd unit written by the repository installer.
OS
Linux

FORENSIC EVIDENCE

Network artifacts

Description
Controller hostname and port are deployment-specific; deployments are operator-hosted and the agent uses the configured controller for HTTP API and WebSocket traffic.
Domains
Not recorded
Ports
Not recorded

FORENSIC EVIDENCE

Other artifacts

Type
GoModulePath
Value
github.com/cevrimxe/go-mini-rmm
Type
WindowsScheduledTaskName
Value
RMM-Agent
Type
LinuxSystemdServiceName
Value
rmm-agent.service
Type
ControllerHeartbeatPath
Value
/api/v1/heartbeat
Type
ControllerAgentWebSocketPath
Value
/ws/agent

References

Acknowledgements

Person
cevrimxe
Handle
@cevrimxe