InvGate
InvGate is an Argentinian (Buenos Aires) IT operations vendor whose product family includes InvGate Service Management (formerly InvGate Service Desk) and InvGate Asset Management (formerly InvGate Insight, rebranded on 2024-10-07). InvGate Asset Management ships an endpoint Agent for Windows, Linux, macOS, and Android that performs hardware/software inventory, software metering, software deployment, vulnerability detection, and remote support — including a one-click "remote desktop connection from your inventory" feature. The Agent is distributed primarily as an MSI on Windows and is configured at install time with the tenant's Insight/IGAM URL plus an optional on-prem Proxy security token; agents in cloud tenants typically reach the platform via a per-tenant subdomain on invgate.net (load-balanced through lb-insight-001.invgate.net). The historic Windows agent installs under C:\Program Files (x86)\Inventec\InvGate.net Client\ (the "Inventec" folder name is a holdover from the original product line) and registers a SYSTEM service named InvClient. For remote agent push, InvGate's Remote-via-Proxy uses WMI/PsExec on Windows and SSH on Linux/macOS. Threat actors abusing legitimate RMM tooling for initial access, persistence, and remote command execution can stand up InvGate tenants and deliver the standard MSI agent — once installed, the agent runs as SYSTEM, persists as the InvClient service, beacons to the configured tenant URL every 8–12 hours, and exposes interactive remote desktop and software-deployment capabilities (MSI/EXE/.bat/.ps1 push) from the InvGate console.
Tool overview
- Category
- RMM
- Research authors
- @MHaggis
- Created
- 2026-05-04
- Last modified
- 2026-05-04
- Privileges
- SYSTEM
- Free / availability
- 30 day trial
- Verification required
- Tenant signup required (corporate email; not strictly enforced)
- Supported platforms
Android
Linux
Windows
macOS
Capabilities
Executables & installation paths
- Filename
- InvGate-ED.exe
- OriginalFileName
- InvGate-ED.exe
- Description
- InvGate Assets Client primary endpoint binary; runs as the InvClient SYSTEM service. Vendor "InvGate"; reported sample sha256 d35d852924b97126cfbf9a2d8c3384d848dbb090a9d9264e26dd766370b474e8 (Win32 EXE, ~932 KB, version 4.004.001).
- Filename
- InvGateAssetsRD.exe
- OriginalFileName
- InvGateAssetsRD.exe
- Description
- InvGate Assets remote-desktop / remote-support helper invoked from the agent (size ~1.32 MB on v5.001.071 builds).
- Filename
- InvGateRD.exe
- OriginalFileName
- InvGateRD.exe
- Description
- InvGate Assets RD helper located under \files\ within the install directory.
- Filename
- DepHlp.exe
- OriginalFileName
- DepHlp.exe
- Description
- InvGate Assets deployment helper used by the software-deployment module.
Installation paths
FORENSIC EVIDENCE
Disk artifacts
- File
- C:\Program Files (x86)\Inventec\InvGate.net Client\InvGate-ED.exe
- Description
- InvGate Assets Client SYSTEM service binary (registered as the InvClient service)
- OS
- Windows
- File
- C:\Program Files (x86)\Inventec\InvGate.net Client\DepHlp.exe
- Description
- InvGate Assets deployment helper used by the software-deployment module
- OS
- Windows
- File
- C:\Program Files (x86)\Inventec\InvGate.net Client\files\InvGateAssetsRD.exe
- Description
- InvGate Assets remote-desktop / remote-support helper invoked by the agent
- OS
- Windows
- File
- C:\Program Files (x86)\Inventec\InvGate.net Client\files\InvGateRD.exe
- Description
- InvGate Assets RD helper binary
- OS
- Windows
- File
- C:\Program Files (x86)\Inventec\InvGate.net Client\files\sas.dll
- Description
- Bundled DLL shipped under the agent's files directory
- OS
- Windows
- File
- C:\Program Files (x86)\Inventec\InvGate.net Client\Software Matt.dll
- Description
- Software metering DLL ("Software Matt") loaded by the agent
- OS
- Windows
- File
- C:\Program Files (x86)\Inventec\InvGate.net Client\InvClient-Log.txt
- Description
- Top-level InvClient service log
- OS
- Windows
- File
- C:\Program Files (x86)\Inventec\InvGate.net Client\logs\InvClient-Log.txt
- Description
- InvClient service log (rotated copy under \logs\)
- OS
- Windows
- File
- C:\Program Files (x86)\Inventec\InvGate.net Client\logs\InvClient-Log_SoftwareMet.txt
- Description
- Software metering subsystem log written by the agent during execution (observed in install layout per advanceduninstaller.com inventory)
- OS
- Windows
- File
- C:\Program Files (x86)\Inventec\InvGate.net Client\logs\InvClient-Log_Service.txt
- Description
- InvClient service log written by the agent during execution (observed in install layout per advanceduninstaller.com inventory)
- OS
- Windows
- File
- C:\Program Files (x86)\Inventec\InvGate.net Client\logs\*
- Description
- InvGate agent logs directory (multiple per-subsystem logs)
- OS
- Windows
- File
- C:\Program Files (x86)\Inventec\InvGate.net Client\build.txt
- Description
- InvGate Assets Client build identifier file
- OS
- Windows
- File
- C:\Program Files (x86)\Inventec\InvGate.net Client\invid
- Description
- Per-endpoint InvGate Agent ID — unique value linking the endpoint to its asset record in the tenant
- OS
- Windows
- File
- C:\Program Files (x86)\Inventec\InvGate.net Client\sm_rep.inv
- Description
- Software metering report inventory file
- OS
- Windows
- File
- C:\Program Files (x86)\Inventec\InvGate.net Client\sm_temp.inv
- Description
- Software metering temporary inventory file
- OS
- Windows
- File
- C:\Program Files (x86)\Inventec\InvGate.net Client\usbFiles\usbLog.txt
- Description
- USB device tracking log written by the agent
- OS
- Windows
- File
- C:\Program Files (x86)\Inventec\InvGate.net Client\4.002.004.ver
- Description
- Per-version marker file dropped by the agent installer/updater
- OS
- Windows
- File
- C:\Program Files (x86)\Inventec\InvGate.net Client\5.001.004.ver
- Description
- Per-version marker file dropped by the agent installer/updater
- OS
- Windows
- File
- C:\Windows\Installer\{41F5BB80-6416-4AF4-B67B-FA36C29DB4C4}\ARPPRODUCTICON.exe
- Description
- Add/Remove Programs icon cached by Windows Installer for the InvGate Assets Client v5.001.004 product GUID
- OS
- Windows
FORENSIC EVIDENCE
Event log artifacts
- EventID
- 7045
- ProviderName
- Service Control Manager
- LogFile
- System.evtx
- ServiceName
- InvClient
- ImagePath
- "C:\\Program Files (x86)\\Inventec\\InvGate.net Client\\InvGate-ED.exe"
- Description
- Service installation event recorded when the InvGate Assets Client agent registers its SYSTEM service.
- EventID
- 11707
- ProviderName
- MsiInstaller
- LogFile
- Application.evtx
- Data
- Product: InvGate Assets Client -- Installation completed successfully.
- Description
- Successful MSI installation of the InvGate Assets Client agent.
- EventID
- 4697
- ProviderName
- Microsoft-Windows-Security-Auditing
- LogFile
- Security.evtx
- ServiceName
- InvClient
- ImagePath
- "C:\\Program Files (x86)\\Inventec\\InvGate.net Client\\InvGate-ED.exe"
- Description
- Service installation auditing event for the InvClient SYSTEM service.
- EventID
- 1033
- ProviderName
- MsiInstaller
- LogFile
- Application.evtx
- Data
- Windows Installer installed the product. Product Name: InvGate Assets Client. Product Version: <ver>. Manufacturer: InvGate.
- Description
- MsiInstaller success event recorded when the InvGate Assets Client MSI completes.
FORENSIC EVIDENCE
Registry artifacts
- Path
- HKLM\SYSTEM\CurrentControlSet\Services\InvClient
- Description
- InvGate Assets Client SYSTEM service registration (service name "InvClient", ImagePath points to InvGate-ED.exe under Inventec\InvGate.net Client)
- Path
- HKLM\SYSTEM\CurrentControlSet\Services\InvClient\ImagePath
- Description
- ImagePath value for the InvClient service — observed value "C:\Program Files (x86)\Inventec\InvGate.net Client\InvGate-ED.exe"
- Path
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{41F5BB80-6416-4AF4-B67B-FA36C29DB4C4}
- Description
- Add/Remove Programs uninstall key for InvGate Assets Client v5.001.004 (Publisher = InvGate)
- Path
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0076285-D0E2-4B49-92BD-25E0B7B27DF6}
- Description
- Add/Remove Programs uninstall key for InvGate Assets Client v4.004.011 — uninstall command "MsiExec.exe /I{F0076285-D0E2-4B49-92BD-25E0B7B27DF6}"
- Path
- HKLM\SOFTWARE\Classes\Installer\Products\08BB5F1461464FA46BB7AF632CD94B4C
- Description
- Windows Installer product key (packed GUID form of {41F5BB80-6416-4AF4-B67B-FA36C29DB4C4})
- Path
- HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{41F5BB80-6416-4AF4-B67B-FA36C29DB4C4}
- Description
- 32-bit-on-64 view of the InvGate Assets Client uninstall key (the agent is a 32-bit MSI, so the canonical Uninstall entry is mirrored under WOW6432Node)
FORENSIC EVIDENCE
Network artifacts
- Description
- InvGate corporate / marketing site (referenced from agent installer and tenant console)
- Domains
- invgate.com
- www.invgate.com
- Ports
- 443
- Description
- InvGate cloud tenant base domain — Insight / IGAM tenants are hosted as per-tenant subdomains on invgate.net (configured at agent install time as the Insight/IGAM URL); cloud agents reach the platform via a regional load balancer (lb-insight-001.invgate.net resolves to AWS elb in eu-central-1)
- Domains
- *.invgate.net
- invgate.net
- Ports
- 443
- Description
- InvGate Insight / Asset Management cloud load balancer (CNAME prd-insight-000-999663879.eu-central-1.elb.amazonaws.com) — primary agent-to-platform endpoint for cloud tenants
- Domains
- lb-insight-001.invgate.net
- Ports
- 443
- Description
- InvGate trust / status portal (Vanta-hosted at vantatrust.com)
- Domains
- trust.invgate.com
- trust-access.invgate.com
- Ports
- 443
- Description
- InvGate tenant management endpoints used during provisioning / instance lookup
- Domains
- instances-info.invgate.com
- instances-list.invgate.com
- Ports
- 443
- Description
- InvGate releases / developer / public docs portals referenced by the agent and integrators
- Domains
- releases.invgate.com
- docs.invgate.net
- help.invgate.com
- Ports
- 443
- Description
- InvGate Service Management Developer Manual (Service Desk REST API) — host used by integrations and bots talking to a tenant
- Domains
- releases.invgate.com
- Ports
- 443
FORENSIC EVIDENCE
Other artifacts
- Type
- Other
- Value
- Windows service name: InvClient
- Type
- Other
- Value
- Vendor service display name: InvGate Assets Client
- Type
- Other
- Value
- Windows Installer product GUIDs observed: {41F5BB80-6416-4AF4-B67B-FA36C29DB4C4} (v5.001.004), {F0076285-D0E2-4B49-92BD-25E0B7B27DF6} (v4.004.011)
- Type
- Other
- Value
- Default install root: C:\Program Files (x86)\Inventec\InvGate.net Client (the "Inventec" parent folder is a vendor naming holdover from the original product line and is preserved in modern Insight / Asset Management agent builds)
- Type
- Other
- Value
- Agent ID file: C:\Program Files (x86)\Inventec\InvGate.net Client\invid — unique per-endpoint identifier persisted by the agent and used by the tenant to dedupe/refresh asset records
- Type
- Other
- Value
- Reporting cadence: cloud agent reports back to the InvGate Asset Management server every 8–12 hours; if the host is offline at the scheduled report time the agent reports immediately on next boot
- Type
- Other
- Value
- Remote-via-Proxy push uses WMI/PsExec on Windows and SSH on Linux/macOS; deployment plans support up to 5,000 assets and accept .msi, .exe, .bat, .ps1 payloads
- Type
- Other
- Value
- Install-time bypass flag observed in vendor docs: VERIFY_CERTS=false (Windows MSI property) and --verify_certs false (Linux/macOS), used to skip TLS validation when the agent connects to a self-signed on-prem Insight/IGAM URL
- Type
- Other
- Value
- Android mobile agent: Google Play package com.invgate.insight.agent (publisher InvGate)
- Type
- SHA256
- Value
- d35d852924b97126cfbf9a2d8c3384d848dbb090a9d9264e26dd766370b474e8
- Type
- MD5
- Value
- e515948c8ede1192926e87df1740f876
Detections
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/invgate_files_sigma.yml
- Description
- Detects potential files activity of InvGate RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/invgate_network_sigma.yml
- Description
- Detects potential network activity of InvGate RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/invgate_processes_sigma.yml
- Description
- Detects potential processes activity of InvGate RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/invgate_registry_sigma.yml
- Description
- Detects potential registry activity of InvGate RMM tool
References
- https://invgate.com/
- https://invgate.com/asset-management
- https://invgate.com/asset-management/remote-management
- https://invgate.com/asset-management/software-deployment
- https://invgate.com/asset-management/product-tour/remote-it-support
- https://invgate.com/itdb/invgate-asset-management
- https://invgate.com/service-management
- https://blog.invgate.com/invgate-asset-management-agent
- https://blog.invgate.com/launching-software-deployment-capabilities-on-invgate-asset-management
- https://blog.invgate.com/agentless-discovery-for-windows-devices-on-invgate-asset-management
- https://blog.invgate.com/introducing-invgate-service-and-asset-management
- https://blog.invgate.com/whats-new-with-invgate-march-2024
- https://releases.invgate.com/service-desk/api/
- https://play.google.com/store/apps/details?id=com.invgate.insight.agent
- https://www.advanceduninstaller.com/InvGate-Assets-Client-2f4c0513ea2872f134927af517dacc3c-application.htm
- https://www.advanceduninstaller.com/InvGate-Assets-Client-196dfb9b5b25fa914ceffa42ee216d05-application.htm
- https://www.advanceduninstaller.com/InvGate-Assets-Client-d803c0bfcc9fdf1f0811a1a8e8e3ff3d-application.htm
- https://www.shouldiremoveit.com/InvGate-Assets-Client-35975-program.aspx
- https://www.virustotal.com/gui/file/d35d852924b97126cfbf9a2d8c3384d848dbb090a9d9264e26dd766370b474e8
Acknowledgements
- Person
- Michael Haag
- Handle
- @M_haggis