RMM

InvGate

InvGate is an Argentinian (Buenos Aires) IT operations vendor whose product family includes InvGate Service Management (formerly InvGate Service Desk) and InvGate Asset Management (formerly InvGate Insight, rebranded on 2024-10-07). InvGate Asset Management ships an endpoint Agent for Windows, Linux, macOS, and Android that performs hardware/software inventory, software metering, software deployment, vulnerability detection, and remote support — including a one-click "remote desktop connection from your inventory" feature. The Agent is distributed primarily as an MSI on Windows and is configured at install time with the tenant's Insight/IGAM URL plus an optional on-prem Proxy security token; agents in cloud tenants typically reach the platform via a per-tenant subdomain on invgate.net (load-balanced through lb-insight-001.invgate.net). The historic Windows agent installs under C:\Program Files (x86)\Inventec\InvGate.net Client\ (the "Inventec" folder name is a holdover from the original product line) and registers a SYSTEM service named InvClient. For remote agent push, InvGate's Remote-via-Proxy uses WMI/PsExec on Windows and SSH on Linux/macOS. Threat actors abusing legitimate RMM tooling for initial access, persistence, and remote command execution can stand up InvGate tenants and deliver the standard MSI agent — once installed, the agent runs as SYSTEM, persists as the InvClient service, beacons to the configured tenant URL every 8–12 hours, and exposes interactive remote desktop and software-deployment capabilities (MSI/EXE/.bat/.ps1 push) from the InvGate console.

Tool overview

Category
RMM
Research authors
@MHaggis
Created
2026-05-04
Last modified
2026-05-04
Privileges
SYSTEM
Free / availability
30 day trial
Verification required
Tenant signup required (corporate email; not strictly enforced)
Supported platforms
AndroidLinuxWindowsmacOS

Capabilities

IT asset management and inventoryHardware and software discoverySoftware meteringSoftware deployment (MSI / EXE / .bat / .ps1 push, up to 5,000 assets per plan)Remote monitoring and managementRemote desktop / remote support from the inventory consoleVulnerability detection (CVE scanning of installed software)Helpdesk and ticketing (InvGate Service Management)Self-service portalWorkflow automation (Service Management ↔ Asset Management integration)Network discovery (agentless and agent-based)Mobile / Android agent (com.invgate.insight.agent)Remote-via-Proxy agent push using WMI/PsExec on Windows and SSH on Linux/macOS

Executables & installation paths

Filename
InvGate-ED.exe
OriginalFileName
InvGate-ED.exe
Description
InvGate Assets Client primary endpoint binary; runs as the InvClient SYSTEM service. Vendor "InvGate"; reported sample sha256 d35d852924b97126cfbf9a2d8c3384d848dbb090a9d9264e26dd766370b474e8 (Win32 EXE, ~932 KB, version 4.004.001).
Filename
InvGateAssetsRD.exe
OriginalFileName
InvGateAssetsRD.exe
Description
InvGate Assets remote-desktop / remote-support helper invoked from the agent (size ~1.32 MB on v5.001.071 builds).
Filename
InvGateRD.exe
OriginalFileName
InvGateRD.exe
Description
InvGate Assets RD helper located under \files\ within the install directory.
Filename
DepHlp.exe
OriginalFileName
DepHlp.exe
Description
InvGate Assets deployment helper used by the software-deployment module.

Installation paths

C:\Program Files (x86)\Inventec\InvGate.net Client\*
C:\Program Files (x86)\Inventec\InvGate.net Client\InvGate-ED.exe
C:\Program Files (x86)\Inventec\InvGate.net Client\DepHlp.exe
C:\Program Files (x86)\Inventec\InvGate.net Client\files\InvGateAssetsRD.exe
C:\Program Files (x86)\Inventec\InvGate.net Client\files\InvGateRD.exe
C:\Program Files (x86)\Inventec\InvGate.net Client\files\sas.dll
C:\Program Files (x86)\Inventec\InvGate.net Client\Software Matt.dll

FORENSIC EVIDENCE

Disk artifacts

File
C:\Program Files (x86)\Inventec\InvGate.net Client\InvGate-ED.exe
Description
InvGate Assets Client SYSTEM service binary (registered as the InvClient service)
OS
Windows
File
C:\Program Files (x86)\Inventec\InvGate.net Client\DepHlp.exe
Description
InvGate Assets deployment helper used by the software-deployment module
OS
Windows
File
C:\Program Files (x86)\Inventec\InvGate.net Client\files\InvGateAssetsRD.exe
Description
InvGate Assets remote-desktop / remote-support helper invoked by the agent
OS
Windows
File
C:\Program Files (x86)\Inventec\InvGate.net Client\files\InvGateRD.exe
Description
InvGate Assets RD helper binary
OS
Windows
File
C:\Program Files (x86)\Inventec\InvGate.net Client\files\sas.dll
Description
Bundled DLL shipped under the agent's files directory
OS
Windows
File
C:\Program Files (x86)\Inventec\InvGate.net Client\Software Matt.dll
Description
Software metering DLL ("Software Matt") loaded by the agent
OS
Windows
File
C:\Program Files (x86)\Inventec\InvGate.net Client\InvClient-Log.txt
Description
Top-level InvClient service log
OS
Windows
File
C:\Program Files (x86)\Inventec\InvGate.net Client\logs\InvClient-Log.txt
Description
InvClient service log (rotated copy under \logs\)
OS
Windows
File
C:\Program Files (x86)\Inventec\InvGate.net Client\logs\InvClient-Log_SoftwareMet.txt
Description
Software metering subsystem log written by the agent during execution (observed in install layout per advanceduninstaller.com inventory)
OS
Windows
File
C:\Program Files (x86)\Inventec\InvGate.net Client\logs\InvClient-Log_Service.txt
Description
InvClient service log written by the agent during execution (observed in install layout per advanceduninstaller.com inventory)
OS
Windows
File
C:\Program Files (x86)\Inventec\InvGate.net Client\logs\*
Description
InvGate agent logs directory (multiple per-subsystem logs)
OS
Windows
File
C:\Program Files (x86)\Inventec\InvGate.net Client\build.txt
Description
InvGate Assets Client build identifier file
OS
Windows
File
C:\Program Files (x86)\Inventec\InvGate.net Client\invid
Description
Per-endpoint InvGate Agent ID — unique value linking the endpoint to its asset record in the tenant
OS
Windows
File
C:\Program Files (x86)\Inventec\InvGate.net Client\sm_rep.inv
Description
Software metering report inventory file
OS
Windows
File
C:\Program Files (x86)\Inventec\InvGate.net Client\sm_temp.inv
Description
Software metering temporary inventory file
OS
Windows
File
C:\Program Files (x86)\Inventec\InvGate.net Client\usbFiles\usbLog.txt
Description
USB device tracking log written by the agent
OS
Windows
File
C:\Program Files (x86)\Inventec\InvGate.net Client\4.002.004.ver
Description
Per-version marker file dropped by the agent installer/updater
OS
Windows
File
C:\Program Files (x86)\Inventec\InvGate.net Client\5.001.004.ver
Description
Per-version marker file dropped by the agent installer/updater
OS
Windows
File
C:\Windows\Installer\{41F5BB80-6416-4AF4-B67B-FA36C29DB4C4}\ARPPRODUCTICON.exe
Description
Add/Remove Programs icon cached by Windows Installer for the InvGate Assets Client v5.001.004 product GUID
OS
Windows

FORENSIC EVIDENCE

Event log artifacts

EventID
7045
ProviderName
Service Control Manager
LogFile
System.evtx
ServiceName
InvClient
ImagePath
"C:\\Program Files (x86)\\Inventec\\InvGate.net Client\\InvGate-ED.exe"
Description
Service installation event recorded when the InvGate Assets Client agent registers its SYSTEM service.
EventID
11707
ProviderName
MsiInstaller
LogFile
Application.evtx
Data
Product: InvGate Assets Client -- Installation completed successfully.
Description
Successful MSI installation of the InvGate Assets Client agent.
EventID
4697
ProviderName
Microsoft-Windows-Security-Auditing
LogFile
Security.evtx
ServiceName
InvClient
ImagePath
"C:\\Program Files (x86)\\Inventec\\InvGate.net Client\\InvGate-ED.exe"
Description
Service installation auditing event for the InvClient SYSTEM service.
EventID
1033
ProviderName
MsiInstaller
LogFile
Application.evtx
Data
Windows Installer installed the product. Product Name: InvGate Assets Client. Product Version: <ver>. Manufacturer: InvGate.
Description
MsiInstaller success event recorded when the InvGate Assets Client MSI completes.

FORENSIC EVIDENCE

Registry artifacts

Path
HKLM\SYSTEM\CurrentControlSet\Services\InvClient
Description
InvGate Assets Client SYSTEM service registration (service name "InvClient", ImagePath points to InvGate-ED.exe under Inventec\InvGate.net Client)
Path
HKLM\SYSTEM\CurrentControlSet\Services\InvClient\ImagePath
Description
ImagePath value for the InvClient service — observed value "C:\Program Files (x86)\Inventec\InvGate.net Client\InvGate-ED.exe"
Path
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{41F5BB80-6416-4AF4-B67B-FA36C29DB4C4}
Description
Add/Remove Programs uninstall key for InvGate Assets Client v5.001.004 (Publisher = InvGate)
Path
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0076285-D0E2-4B49-92BD-25E0B7B27DF6}
Description
Add/Remove Programs uninstall key for InvGate Assets Client v4.004.011 — uninstall command "MsiExec.exe /I{F0076285-D0E2-4B49-92BD-25E0B7B27DF6}"
Path
HKLM\SOFTWARE\Classes\Installer\Products\08BB5F1461464FA46BB7AF632CD94B4C
Description
Windows Installer product key (packed GUID form of {41F5BB80-6416-4AF4-B67B-FA36C29DB4C4})
Path
HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{41F5BB80-6416-4AF4-B67B-FA36C29DB4C4}
Description
32-bit-on-64 view of the InvGate Assets Client uninstall key (the agent is a 32-bit MSI, so the canonical Uninstall entry is mirrored under WOW6432Node)

FORENSIC EVIDENCE

Network artifacts

Description
InvGate corporate / marketing site (referenced from agent installer and tenant console)
Domains
  • invgate.com
  • www.invgate.com
Ports
  • 443
Description
InvGate cloud tenant base domain — Insight / IGAM tenants are hosted as per-tenant subdomains on invgate.net (configured at agent install time as the Insight/IGAM URL); cloud agents reach the platform via a regional load balancer (lb-insight-001.invgate.net resolves to AWS elb in eu-central-1)
Domains
  • *.invgate.net
  • invgate.net
Ports
  • 443
Description
InvGate Insight / Asset Management cloud load balancer (CNAME prd-insight-000-999663879.eu-central-1.elb.amazonaws.com) — primary agent-to-platform endpoint for cloud tenants
Domains
  • lb-insight-001.invgate.net
Ports
  • 443
Description
InvGate trust / status portal (Vanta-hosted at vantatrust.com)
Domains
  • trust.invgate.com
  • trust-access.invgate.com
Ports
  • 443
Description
InvGate tenant management endpoints used during provisioning / instance lookup
Domains
  • instances-info.invgate.com
  • instances-list.invgate.com
Ports
  • 443
Description
InvGate releases / developer / public docs portals referenced by the agent and integrators
Domains
  • releases.invgate.com
  • docs.invgate.net
  • help.invgate.com
Ports
  • 443
Description
InvGate Service Management Developer Manual (Service Desk REST API) — host used by integrations and bots talking to a tenant
Domains
  • releases.invgate.com
Ports
  • 443

FORENSIC EVIDENCE

Other artifacts

Type
Other
Value
Windows service name: InvClient
Type
Other
Value
Vendor service display name: InvGate Assets Client
Type
Other
Value
Windows Installer product GUIDs observed: {41F5BB80-6416-4AF4-B67B-FA36C29DB4C4} (v5.001.004), {F0076285-D0E2-4B49-92BD-25E0B7B27DF6} (v4.004.011)
Type
Other
Value
Default install root: C:\Program Files (x86)\Inventec\InvGate.net Client (the "Inventec" parent folder is a vendor naming holdover from the original product line and is preserved in modern Insight / Asset Management agent builds)
Type
Other
Value
Agent ID file: C:\Program Files (x86)\Inventec\InvGate.net Client\invid — unique per-endpoint identifier persisted by the agent and used by the tenant to dedupe/refresh asset records
Type
Other
Value
Reporting cadence: cloud agent reports back to the InvGate Asset Management server every 8–12 hours; if the host is offline at the scheduled report time the agent reports immediately on next boot
Type
Other
Value
Remote-via-Proxy push uses WMI/PsExec on Windows and SSH on Linux/macOS; deployment plans support up to 5,000 assets and accept .msi, .exe, .bat, .ps1 payloads
Type
Other
Value
Install-time bypass flag observed in vendor docs: VERIFY_CERTS=false (Windows MSI property) and --verify_certs false (Linux/macOS), used to skip TLS validation when the agent connects to a self-signed on-prem Insight/IGAM URL
Type
Other
Value
Android mobile agent: Google Play package com.invgate.insight.agent (publisher InvGate)
Type
SHA256
Value
d35d852924b97126cfbf9a2d8c3384d848dbb090a9d9264e26dd766370b474e8
Type
MD5
Value
e515948c8ede1192926e87df1740f876

Detections

Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/invgate_files_sigma.yml
Description
Detects potential files activity of InvGate RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/invgate_network_sigma.yml
Description
Detects potential network activity of InvGate RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/invgate_processes_sigma.yml
Description
Detects potential processes activity of InvGate RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/invgate_registry_sigma.yml
Description
Detects potential registry activity of InvGate RMM tool

References

Acknowledgements

Person
Michael Haag
Handle
@M_haggis