RMM

Lavawall

Lavawall is a commercial remote monitoring, management, and security platform developed by ThreeShield Information Security Corporation. It supports Windows, macOS, and Linux endpoints, with browser-based remote desktop control, background administration, remote shell access, file transfer, scripting, patch management, and device inventory. Windows deployments use LavawallWin.exe and a separate remote-support component. Signed Windows agent samples have been submitted under Zoom and Adobe installer names; those names alone do not establish malicious use and are not included as detection artifacts. An unexpected installation should be investigated in the context of the organization's approved remote-access tools.

Tool overview

Category
RMM
Research authors
Michael Haag
Created
2026-09-21
Last modified
2026-09-21
Privileges
Administrator for installation; SYSTEM on Windows; root on macOS/Linux
Free / availability
No
Verification required
Vendor documentation confirms the RMM capabilities and supported platforms. Windows artifacts were checked against the signed LavawallWin.exe version 1.0.162.440 and the vendor's remote-support archive version 2.0.0.16. File hashes and Authenticode signatures were verified locally without executing the agents. Installation, service, task, registry, and API details come from static analysis; temporary extraction paths are corroborated by sandbox reports. macOS/Linux installation artifacts and a complete remote session were not independently tested. The commercial platform offers a free trial.
Supported platforms
LinuxWindowsmacOS

Capabilities

Remote desktop controlBackground administrationRemote shell accessFile transferRemote script executionApplication and operating-system patch managementHardware and software inventoryEndpoint health and configuration monitoring

Executables & installation paths

Filename
LavawallWin.exe
OriginalFileName
LavawallWin.dll
Description
LavawallWin
Product
Lavawall Windows Agent

Installation paths

C:\Program Files\Lavawall\LavawallWin.exe
C:\Program Files (x86)\Lavawall\LavawallWin.exe
C:\Lavawall\LavawallWin.exe

Code signing

signer name
ThreeShield Information Security Corporation
certificate thumbprint
BA19F4C2488F6CA83A23BB4B5DC765991E699080
issuer
DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
valid from
2026-01-19T00:00:00Z
valid to
2029-01-18T23:59:59Z
tbs sha256
850a06b73b2efb25a211b84650c0ff6ddb299eb351639095cc93948fbf243430
tbs sha1
30c4804959fc95cc1a42252672bffac612a24d69
src file sha256
1e395934cbef22846dd0dd2daf868429b0a5b86313f9721543b03a66cfc25e77
src file path
LavawallWin.exe
src file company
ThreeShield Information Security Corporation

search names

LavawallWin.exe
LavawallWin.dll

company names

ThreeShield Information Security Corporation

signer names

ThreeShield Information Security Corporation

File hashes

authenticode
  • file name
    LavawallWin.exe
    sha256
    e577759c8198c9597527022502d044e6ee396e2faa55a5fa7bdc12578cc053fc
    sha1
    Not recorded
  • file name
    remote-agent.exe
    sha256
    b2cf0fa2f55b8ee50133d2d6e692cc1f12514e85482ec637fb00ae9148d5b9fa
    sha1
    Not recorded
  • file name
    uihelper.exe
    sha256
    f30b6ef99434bc51672182b4baefc27ba7d0739cab5777ab4682edd032705922
    sha1
    Not recorded

FORENSIC EVIDENCE

Disk artifacts

File
*\Lavawall\LavawallWin.exe
Description
Canonically named Windows management agent. The inspected code selects Program Files, then Program Files (x86), then C:\Lavawall as fallback locations. Initial installation can preserve the launched executable's basename.
OS
Windows
File
*\Lavawall\remote-agent\remote-agent.exe
Description
Remote-support executable extracted beneath the management agent's installation directory. Keep the Lavawall directory context because remote-agent.exe is not a product-specific filename.
OS
Windows
File
*\Lavawall\remote-agent\uihelper.exe
Description
Remote-support UI helper shipped alongside remote-agent.exe in the signed vendor package. The filename alone is not specific to Lavawall.
OS
Windows
File
*\Lavawall\LavawallCheckAndStartService.ps1
Description
PowerShell watchdog script that starts the management service if it is stopped.
OS
Windows
File
*\Lavawall\Storage\UserAgentData.db
Description
Local SQLite storage used by the Windows management agent.
OS
Windows
File
*\LavawallWin.dll
Description
Managed assembly extracted by the self-contained Windows executable, observed in sandbox reports. Parent directories vary with the launched filename and bundle extraction directory.
OS
Windows
Example
  • C:\Users\user\AppData\Local\Temp\.net\file\1bb0\LavawallWin.dll
File
*\LavawallWin.runtimeconfig.json
Description
Runtime configuration extracted alongside the managed assembly in sandbox reports.
OS
Windows
Example
  • C:\Users\user\AppData\Local\Temp\.net\file\1bb0\LavawallWin.runtimeconfig.json

FORENSIC EVIDENCE

Registry artifacts

Path
HKLM\SOFTWARE\WOW6432Node\LavaWall\Agent
Description
Agent registration and configuration key, including DeviceId, CompanyGuid, and IsRegistered values, confirmed in the inspected code.
Path
HKLM\SYSTEM\CurrentControlSet\Services\Lavawall Support Agent
Description
Automatic-start Windows management service. Its description is Patch and configuration monitoring and management.
Path
HKLM\SYSTEM\CurrentControlSet\Services\LavaWallRemoteAgent
Description
Windows remote-support service identified in both inspected agent components.

FORENSIC EVIDENCE

Network artifacts

Description
Default Windows management API and secure WebSocket endpoint embedded in the inspected agent, using /go/ and /go/ws respectively. These are code-confirmed endpoints, not a claim of observed sandbox connections.
Domains
  • api-ca-1.lavawall.com
Ports
  • 443
Description
Vendor remote-support update host. The management agent retrieves version.json, which identifies the remote-agent.zip download and hash.
Domains
  • lavawinupdate.lavawall.com
Ports
  • 443
Description
Default remote-support server and port embedded in the signed remote-agent.exe version 2.0.0.16. Live session traffic was not tested.
Domains
  • caremote1.lavawall.com
Ports
  • 8443

FORENSIC EVIDENCE

Other artifacts

Type
ServiceName
Value
Lavawall Support Agent
Type
ServiceName
Value
LavaWallRemoteAgent
Type
ScheduledTask
Value
LavawallCheckAndStartServiceTask
Type
ScheduledTaskBehavior
Value
Runs LavawallCheckAndStartService.ps1 as SYSTEM every five minutes to start the management service if stopped, as defined in the agent.
Type
Mutex
Value
Global\LavawallAgentCompanyCredentialsV2
Type
ObservedAgentSHA256
Value
1e395934cbef22846dd0dd2daf868429b0a5b86313f9721543b03a66cfc25e77
Type
ObservedRemoteAgentSHA256
Value
d494ac927c3a98f67a035a418c5e89e9a97397a837fb8cc9bedbb44d25ad3670
Type
ObservedUIHelperSHA256
Value
3c56c3cca03efdcd2044a48d588ab27f68fa1b7e577874a490ff4ada241cec3e

References

Acknowledgements

Person
patialavii
Handle
@patialavii