RMM
Level
Level is a remote monitoring and management (RMM) tool. Threat Hunting Labs documented its malicious installation through an RVTools-themed SEO poisoning chain in 2026. An operator used Level to run discovery commands as SYSTEM and install the separate LightRmmAgent service. The report distinguishes Level's routine inventory from operator activity.
Tool overview
- Category
- RMM
- Research authors
- Christian Henriksen, ITM8 | Improsec
- Created
- 2024-02-11
- Last modified
- 2026-09-23
- Privileges
- User
- Free / availability
- Free
- Verification required
- True
- Supported platforms
Windows
Capabilities
Executables & installation paths
- Filename
- level.exe
- OriginalFileName
- Not recorded
- Description
- Not recorded
Installation paths
C:\Program Files\Level\*
Code signing
- signer name
- Level Software, Inc.
- certificate thumbprint
- 3C002DCBBCB603AE08699F4CEF973864AEB16860
- src file sha256
- 075b9694aa770850d54870e4a3a55fd11a26497ccb8de4f2ec7b2ecca2b88d83
- src file path
- downloaded_files/level/075b9694aa770850d54870e4a3a55fd11a26497ccb8de4f2ec7b2ecca2b88d83
FORENSIC EVIDENCE
Disk artifacts
- File
- C:\Program Files\Level\level.exe
- Description
- Level Binary
- OS
- Windows
- File
- C:\Program Files\Level\osqueryi.exe
- Description
- A tool used by level to collect machine state information.
- OS
- Windows
- File
- C:\Program Files\Level\level.log
- Description
- Client log file for Level.
- OS
- Windows
FORENSIC EVIDENCE
Event log artifacts
- EventID
- 4698
- ProviderName
- Microsoft-Windows-Security-Auditing
- LogFile
- Security.evtx
- TaskName
- Level Watchdog
- Location
- \Level
- Description
- To ensure the Level agent is always running, a scheduled task...
- EventID
- 4697
- ProviderName
- Microsoft-Windows-Security-Auditing
- LogFile
- Security.evtx
- ServiceName
- Level
- ServiceFileName
- C:\Program Files\Level\level.exe --key <KEY> --action=run
- ServiceAccount
- LocalSystem
- ServiceStartType
- 2
- Description
- The Level Agent Service ...
- EventID
- 4798
- ProviderName
- Microsoft-Windows-Security-Auditing
- LogFile
- Security.evtx
- CallerProcessName
- C:\Program Files\Level\osqueri.exe
- Description
- Evidence of osqueryi doing automatic user/group enumeration.
FORENSIC EVIDENCE
Network artifacts
- Description
- Known remote domains
- Domains
- level.io
- builds.level.io
- agents.level.io
- online.level.io
- downloads.level.io
- Ports
- 443
Detections
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/level_network_sigma.yml
- Description
- Detects potential network activity of Level RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/level_files_sigma.yml
- Description
- Detects potential files activity of Level RMM tool
References
Acknowledgements
- Person
- Kostas / Threat Hunting Labs
- Handle
- @Kostastsale
- Person
- Threat Hunting Labs
- Handle
- @ThruntingLabs
- Person
- Anna / MalBear Labs
- Handle
- @PandaRE__
- Person
- MalBear Labs
- Handle
- @malbearlabs