RMM

Mini RMM Agent

Mini RMM Agent is a custom Windows endpoint-management agent. Its inspected code self-installs as a Windows service, registers and sends heartbeats to a management server, polls for remote tasks, runs PowerShell, and supports software installation and testing workflows. The assembly identifies Senin Firman as its company, but no independently verified publisher or product source was identified. This entry documents statically confirmed RMM behavior and host artifacts only; it does not establish a legitimate commercial vendor, malware classification, or observed abuse.

Tool overview

Category
RMM
Research authors
Michael Haag
Created
2026-09-22
Last modified
2026-09-22
Privileges
Administrator required by the self-install code to create and start the Windows service
Free / availability
Unknown
Verification required
A 5,691,392-byte .NET 8 Windows sample was downloaded for static analysis only and its SHA-256 was verified. Decompilation confirms self-installation to a fixed Program Files path, an auto-starting Windows service, registration and heartbeat logic, remote task polling and results, PowerShell execution, software installation, and verification/testing workflows. The embedded resources also include SmartScreen-test and Defender-exclusion scripts. The assembly's company field names Senin Firman, but no reliable independent vendor or source identity was found. No live installation, endpoint contact, remote task, or delivery-abuse relationship was tested or established.
Supported platforms
Windows

Capabilities

Self-installation and auto-starting Windows serviceEndpoint registration, heartbeat, task polling, and result reportingRemote PowerShell executionRemote software download and installation workflowsSoftware verification and SmartScreen-test workflows

Executables & installation paths

Filename
MiniRmmAgent.exe
OriginalFileName
Not recorded
Description
Mini RMM Agent (self-identified in assembly metadata)

Installation paths

C:\Program Files\MiniRMM\MiniRmmAgent.exe
C:\ProgramData\MiniRMM\SmartScreenTest.ps1
C:\ProgramData\MiniRMM\Invoke-AVExclusions.ps1

FORENSIC EVIDENCE

Disk artifacts

File
C:\Program Files\MiniRMM\MiniRmmAgent.exe
Description
Fixed executable destination in the statically inspected self-install routine.
OS
Windows
File
C:\ProgramData\MiniRMM\SmartScreenTest.ps1
Description
Embedded SmartScreen-test script extracted by the agent at runtime.
OS
Windows
File
C:\ProgramData\MiniRMM\Invoke-AVExclusions.ps1
Description
Embedded Defender-exclusion script extracted by the agent at runtime; included as an artifact, not as a conclusion about use or intent.
OS
Windows

FORENSIC EVIDENCE

Registry artifacts

Path
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MiniRMMAgent
Description
Startup value set by the inspected agent code to its current executable path.
Path
HKLM\SYSTEM\CurrentControlSet\Services\MiniRmmAgent
Description
Windows service configuration key inferred from the inspected self-install code.

FORENSIC EVIDENCE

Other artifacts

Type
ServiceName
Value
MiniRmmAgent
Type
ServiceDisplayName
Value
Mini RMM Agent
Type
InspectedSampleSHA256
Value
89ea754708f2be80b2d8e39533d9b98e9a8bdc588f5d732687ee7b5ce18201e7
Type
ProductVersion
Value
0.4.3.0
Type
ClaimedAssemblyCompany
Value
Senin Firman
Type
PublisherStatus
Value
No independently verified publisher or product source identified.

References

Not recorded