RMM

Level

Level is a remote monitoring and management (RMM) tool. Threat Hunting Labs documented its malicious installation through an RVTools-themed SEO poisoning chain in 2026. An operator used Level to run discovery commands as SYSTEM and install the separate LightRmmAgent service. The report distinguishes Level's routine inventory from operator activity.

Tool overview

Category
RMM
Research authors
Christian Henriksen, ITM8 | Improsec
Created
2024-02-11
Last modified
2026-09-23
Privileges
User
Free / availability
Free
Verification required
True
Supported platforms
Windows

Capabilities

File TransferFile System AccessRemote ControlAutomation & Scripting

Executables & installation paths

Filename
level.exe
OriginalFileName
Not recorded
Description
Not recorded

Installation paths

C:\Program Files\Level\*

Code signing

signer name
Level Software, Inc.
certificate thumbprint
3C002DCBBCB603AE08699F4CEF973864AEB16860
src file sha256
075b9694aa770850d54870e4a3a55fd11a26497ccb8de4f2ec7b2ecca2b88d83
src file path
downloaded_files/level/075b9694aa770850d54870e4a3a55fd11a26497ccb8de4f2ec7b2ecca2b88d83

FORENSIC EVIDENCE

Disk artifacts

File
C:\Program Files\Level\level.exe
Description
Level Binary
OS
Windows
File
C:\Program Files\Level\osqueryi.exe
Description
A tool used by level to collect machine state information.
OS
Windows
File
C:\Program Files\Level\level.log
Description
Client log file for Level.
OS
Windows

FORENSIC EVIDENCE

Event log artifacts

EventID
4698
ProviderName
Microsoft-Windows-Security-Auditing
LogFile
Security.evtx
TaskName
Level Watchdog
Location
\Level
Description
To ensure the Level agent is always running, a scheduled task...
EventID
4697
ProviderName
Microsoft-Windows-Security-Auditing
LogFile
Security.evtx
ServiceName
Level
ServiceFileName
C:\Program Files\Level\level.exe --key <KEY> --action=run
ServiceAccount
LocalSystem
ServiceStartType
2
Description
The Level Agent Service ...
EventID
4798
ProviderName
Microsoft-Windows-Security-Auditing
LogFile
Security.evtx
CallerProcessName
C:\Program Files\Level\osqueri.exe
Description
Evidence of osqueryi doing automatic user/group enumeration.

FORENSIC EVIDENCE

Network artifacts

Description
Known remote domains
Domains
  • level.io
  • builds.level.io
  • agents.level.io
  • online.level.io
  • downloads.level.io
Ports
  • 443

Detections

Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/level_network_sigma.yml
Description
Detects potential network activity of Level RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/level_files_sigma.yml
Description
Detects potential files activity of Level RMM tool

References

Acknowledgements

Person
Kostas / Threat Hunting Labs
Handle
@Kostastsale
Person
Threat Hunting Labs
Handle
@ThruntingLabs
Person
Anna / MalBear Labs
Handle
@PandaRE__
Person
MalBear Labs
Handle
@malbearlabs