RMM

Monitic

Monitic (monitic.com) is an EU/Turkey-based SaaS Remote Monitoring and Management (RMM) platform marketed at MSPs and IT departments. The product is operated by VAULT BİLİŞİM SİSTEMLERİ LTD.ŞTİ. (Turkish entity, Code Signing certificate via GlobalSign GCC R45 EV CodeSigning CA 2020) and exposes its tenant console at app.monitic.com with the agent control plane at api.monitic.com (both fronted by Cloudflare). The Windows agent ships as two SYSTEM services installed under C:\Program Files\Monitic\: a large (~50-60 MB) bundled `agent.exe` that embeds RustDesk dependencies (libvpx, WinPthreadGC) and the `kopia.io` backup engine for remote control, file transfer and backup, and a smaller (~6 MB) `amon.exe` watchdog/monitoring binary written in Go. A separate `MoniticInstaller.exe` bootstrapper (Themida-packed, signed by VAULT BİLİŞİM) is downloaded from app.monitic.com and uses `rundll32 url.dll,FileProtocolHandler https://app.monitic.com/installer` to drive the user through the install flow. An alternate silent installer is distributed as `agent_installer.bat` which downloads `installer.zip` from `https://api.monitic.com/api/ext/download-installer?t=<token>` via PowerShell `Net.WebClient.DownloadFile`, extracts it to `C:\Program Files\Monitic\`, fetches `conf.json` from `https://api.monitic.com/api/ext/get-config?t=<token>`, then registers both services with `agent.exe install` and `amon.exe install`. A WebRTC TURN server is operated at `turn.monitic.com` (77.37.120.252) for RustDesk peer-to-peer relay. Monitic agents are flagged by the ProofPoint Emerging Threats Open ruleset (`ET INFO Observed RMM Domain in DNS Lookup ( * .monitic .com)` and `ET INFO Observed RMM Domain in TLS SNI ( * .monitic .com)`) and are classified as a remote-access tool that may be abused under MITRE ATT&CK T1219 (Remote Access Software). Sandbox engines (Zenbox, CAPE) frequently mis-classify the Themida-packed Go/.NET binaries as `Snake` / `Gocoder`, but Microsoft / Symantec / Kaspersky engine results are clean and the binaries are EV-code-signed.

Tool overview

Category
RMM
Research authors
@MHaggis
Created
2026-05-04
Last modified
2026-05-04
Privileges
SYSTEM
Free / availability
14-day free trial (no credit card)
Verification required
Tenant signup required; corporate email accepted, no strict enforcement observed
Supported platforms
LinuxWindowsmacOS

Capabilities

Remote monitoring and managementRemote access via bundled RustDesk (peer-to-peer with TURN relay at turn.monitic.com)Remote shell / command executionPatch management and Windows Update trackingActive Directory management and auditHypervisor monitoring (Hyper-V, Docker)Network monitoring and managementAsset inventorySMART / RAID disk health monitoringAntivirus monitoring and CVE detectionBackup (kopia.io engine bundled in agent.exe)Event log management and security analyticsAPI and web service uptime monitoringCertificate managementDigital employee experience (DEX) monitoring

Executables & installation paths

Filename
MoniticInstaller.exe
OriginalFileName
MoniticInstaller.exe
Description
Monitic agent bootstrap installer (Themida-packed Win32 PE, signed by VAULT BİLİŞİM SİSTEMLERİ LTD.ŞTİ. via GlobalSign GCC R45 EV CodeSigning CA 2020). Hosted at https://app.monitic.com/MoniticInstaller.exe; observed sha256 d641841cdf83037b32e699f01da16b66a9064221013dfec43d7a3bc993d6181d (3/2026) and 924238d5c8b4c882f236053c394d1a9510b6a1fe028ae5437eed7785774b1462 (7/2025). On launch it executes `rundll32 url.dll,FileProtocolHandler https://app.monitic.com/installer` to open the installer flow in the user's browser.
Filename
amon.exe
Description
Monitic agent monitor / watchdog binary (~6 MB Go executable, Themida-packed, signed by VAULT BİLİŞİM SİSTEMLERİ LTD.ŞTİ.). Installed to C:\Program Files\Monitic\amon.exe and registered as a SYSTEM service via `amon.exe install` then started with `amon.exe start`. Calls https://api.monitic.com/api/ext/check-sha256 for integrity check / config polling. Observed sha256 71cd67afd19f9f5d0cf00d92034c40b674e3b4d9888f5be6c2f401c52863a523 (10/2025).
Filename
agent.exe
Description
Monitic primary agent binary (~50-60 MB .NET executable, signed by VAULT BİLİŞİM SİSTEMLERİ LTD.ŞTİ.). Installed to C:\Program Files\Monitic\agent.exe and registered as a SYSTEM service via `agent.exe install`. Bundles RustDesk for remote desktop (libvpx-1.dll, WinPthreadGC.dll observed in dropped-files), the kopia.io backup engine, and uses WMI (`Get-WmiObject Win32_BIOS / Win32_Processor / Win32_DiskDrive / Win32_BaseBoard`) for hardware fingerprinting. Spawns a child `tunnel.exe` (taskkill /IM tunnel.exe /F observed in lifecycle). Observed sha256 9c6b26fe30870775a42d02804c9094c83479850a87703d95ebd8631ad8188b8e (11/2025).

Installation paths

C:\Program Files\Monitic\*
C:\Program Files\Monitic\agent.exe
C:\Program Files\Monitic\amon.exe
C:\Program Files\Monitic\conf.json

FORENSIC EVIDENCE

Disk artifacts

File
C:\Program Files\Monitic\agent.exe
Description
Monitic primary agent SYSTEM service binary (RustDesk + kopia bundle)
OS
Windows
File
C:\Program Files\Monitic\amon.exe
Description
Monitic monitor / watchdog SYSTEM service binary (Go, ~6 MB)
OS
Windows
File
C:\Program Files\Monitic\conf.json
Description
Per-tenant configuration file fetched from https://api.monitic.com/api/ext/get-config?t=<token> during install (referenced explicitly by agent_installer.bat)
OS
Windows
File
C:\Program Files\Monitic\*
Description
Monitic install directory — created/cleared by agent_installer.bat (`del /q "C:\Program Files\Monitic\*"`) and populated from installer.zip
OS
Windows
File
%USERPROFILE%\Desktop\MoniticInstaller.exe
Description
Bootstrap installer download location when fetched manually from https://app.monitic.com/MoniticInstaller.exe (typical install layout — observed in CAPE/Zenbox sandbox traces)
OS
Windows
File
%TEMP%\*\agent_installer.bat
Description
Silent installer batch script — extracted to a temp directory before execution (observed path C:\Users\<user>\AppData\Local\Temp\<random>\agent_installer.bat)
OS
Windows
File
%TEMP%\*\amon.exe
Description
Stage-1 amon.exe drop location (observed at C:\Users\user\AppData\Local\Temp\vx1nkas2.1am\amon.exe before move to Program Files)
OS
Windows
File
%TEMP%\*\agent.exe
Description
Stage-1 agent.exe drop location (observed at C:\Users\user\AppData\Local\Temp\vx1nkas2.1am\agent.exe before move to Program Files)
OS
Windows
File
%CD%\installer.zip
Description
~58 MB ZIP downloaded from https://api.monitic.com/api/ext/download-installer?t=<token> via `powershell (New-Object Net.WebClient).DownloadFile(...)` — extracted to C:\Program Files\Monitic\ via `[IO.Compression.ZipFile]::ExtractToDirectory()` then deleted (observed sha256 5a5303d57956589d2b6b27e70f8a2c9cb91b17954a3e52caf4549dd4e0863404)
OS
Windows
File
%CD%\conf.json
Description
Transient configuration file downloaded from https://api.monitic.com/api/ext/get-config?t=<token> by agent_installer.bat then `copy`-ed to C:\Program Files\Monitic\conf.json and deleted from working directory
OS
Windows

FORENSIC EVIDENCE

Event log artifacts

EventID
7045
ProviderName
Service Control Manager
LogFile
System.evtx
ImagePath
"C:\\Program Files\\Monitic\\agent.exe"
Description
Service installation event resulting from `agent.exe install` invocation by Monitic agent_installer.bat (SYSTEM service registered for the primary RustDesk/kopia agent). The SCM service Name (Go service-installer subcommand value) was not directly observed — agent.exe is Themida-packed and no `services\<name>` registry key surfaced in sandbox runs. Match on ImagePath.
EventID
7045
ProviderName
Service Control Manager
LogFile
System.evtx
ImagePath
"C:\\Program Files\\Monitic\\amon.exe"
Description
Service installation event resulting from `amon.exe install` invocation by Monitic agent_installer.bat (SYSTEM service registered for the amon watchdog). Service Name not directly observed — match on ImagePath ending in `amon.exe`.
EventID
4688
ProviderName
Microsoft-Windows-Security-Auditing
LogFile
Security.evtx
CommandLine
rundll32 url.dll,FileProtocolHandler https://app.monitic.com/installer
Description
MoniticInstaller.exe spawning rundll32 to open the installer enrollment URL via the default browser (observed in CAPE/Zenbox sandbox traces of the bootstrap installer).
EventID
4688
ProviderName
Microsoft-Windows-Security-Auditing
LogFile
Security.evtx
CommandLine
powershell -command "& { (New-Object Net.WebClient).DownloadFile('https://api.monitic.com/api/ext/download-installer?t=<token>', 'installer.zip') }"
Description
PowerShell download of installer.zip from api.monitic.com triggered by Monitic's agent_installer.bat.
EventID
4688
ProviderName
Microsoft-Windows-Security-Auditing
LogFile
Security.evtx
CommandLine
powershell -command "& { (New-Object Net.WebClient).DownloadFile('https://api.monitic.com/api/ext/get-config?t=<token>', 'conf.json') }"
Description
PowerShell download of per-tenant conf.json from api.monitic.com triggered by Monitic's agent_installer.bat.
EventID
4688
ProviderName
Microsoft-Windows-Security-Auditing
LogFile
Security.evtx
CommandLine
powershell -command "& { Add-Type -A 'System.IO.Compression.FileSystem'; [IO.Compression.ZipFile]::ExtractToDirectory('installer.zip', 'C:\Program Files\Monitic') }"
Description
PowerShell extraction of installer.zip into C:\Program Files\Monitic during Monitic install (observed verbatim in agent_installer.bat).
EventID
4688
ProviderName
Microsoft-Windows-Security-Auditing
LogFile
Security.evtx
CommandLine
"C:\\Program Files\\Monitic\\agent.exe" install
Description
Monitic agent.exe registering itself as a SYSTEM service via the `install` subcommand (called from agent_installer.bat).
EventID
4688
ProviderName
Microsoft-Windows-Security-Auditing
LogFile
Security.evtx
CommandLine
"C:\\Program Files\\Monitic\\amon.exe" install
Description
Monitic amon.exe registering itself as a SYSTEM service via the `install` subcommand (called from agent_installer.bat).
EventID
4688
ProviderName
Microsoft-Windows-Security-Auditing
LogFile
Security.evtx
CommandLine
"C:\\Program Files\\Monitic\\amon.exe" start
Description
Monitic amon.exe service start triggered by agent_installer.bat after installation.
EventID
4688
ProviderName
Microsoft-Windows-Security-Auditing
LogFile
Security.evtx
CommandLine
powershell -NoProfile -NonInteractive -Command "& {Get-WmiObject Win32_BIOS | Select-Object Manufacturer, SerialNumber | ConvertTo-Json -Compress}"
Description
Hardware fingerprinting WMI query executed by Monitic agent.exe (observed in CAPE sandbox traces of agent.exe). Sibling queries seen for Win32_Processor, Win32_DiskDrive (Index=0) and Win32_BaseBoard.
EventID
4688
ProviderName
Microsoft-Windows-Security-Auditing
LogFile
Security.evtx
CommandLine
taskkill /IM tunnel.exe /F
Description
Monitic agent.exe terminating its bundled tunnel.exe child during lifecycle / restart (observed in CAPE sandbox traces of agent.exe — `tunnel.exe` is the RustDesk tunneling helper).

FORENSIC EVIDENCE

Network artifacts

Description
Monitic agent control plane — config and installer download REST API (api.monitic.com/api/ext/get-config, /api/ext/download-installer, /api/ext/check-sha256, /api/ext/get-token)
Domains
  • api.monitic.com
Ports
  • 443
Description
Monitic tenant web console / installer hosting (app.monitic.com/MoniticInstaller.exe, app.monitic.com/installer)
Domains
  • app.monitic.com
Ports
  • 443
Description
Monitic developer / staging API (referenced in MoniticInstaller.exe embedded URLs — https://devapi.monitic.com/api/ext/download-installer)
Domains
  • devapi.monitic.com
Ports
  • 443
Description
Monitic WebRTC TURN relay for RustDesk peer-to-peer remote control fallback (turn.monitic.com → 77.37.120.252)
Domains
  • turn.monitic.com
Ports
  • 443
  • 3478
Description
Monitic corporate / marketing site
Domains
  • monitic.com
  • www.monitic.com
Ports
  • 443

FORENSIC EVIDENCE

Other artifacts

Type
IP
Value
77.37.120.252
Type
ProofpointETSignature
Value
ET INFO Observed RMM Domain in DNS Lookup ( * .monitic .com)
Type
ProofpointETSignature
Value
ET INFO Observed RMM Domain in TLS SNI ( * .monitic .com)
Type
CodeSigningSubject
Value
VAULT BİLİŞİM SİSTEMLERİ LTD.ŞTİ.
Type
CodeSigningIssuer
Value
GlobalSign GCC R45 EV CodeSigning CA 2020

Detections

Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/monitic_files_sigma.yml
Description
Detects potential files activity of Monitic RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/monitic_network_sigma.yml
Description
Detects potential network activity of Monitic RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/monitic_processes_sigma.yml
Description
Detects potential processes activity of Monitic RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/monitic_registry_sigma.yml
Description
Detects potential registry activity of Monitic RMM tool

References

Acknowledgements

Person
Michael Haag
Handle
@M_haggis