RMM

Obliance

Obliance is a self-hosted remote monitoring and management project with a Go endpoint agent. Its reviewed source provides Windows, Linux, and macOS installers and implements endpoint monitoring, remote shell, file, process, service, update, and remote-control functions. This entry records source-confirmed artifacts only; it does not establish a delivery relationship or malicious use.

Tool overview

Category
RMM
Research authors
Michael Haag
Created
2026-09-28
Last modified
2026-09-28
Privileges
Windows MSI installation creates a LocalSystem service and scheduled task; Linux and macOS installation create system services and require administrative privileges. The source was not executed.
Free / availability
Unknown
Verification required
Static source review at commit f1eb7e886df9b16d46f13d19cec4b7d6cedcf4ac. Windows WiX source, Windows service source, and Unix installer source define the listed files, service, task, registry locations, and macOS LaunchDaemon. No installer, agent, server, remote session, or update workflow was executed. Server URLs and API keys are deployment configuration and are intentionally not generic network indicators. The reviewed repository did not provide a license file, so licensing is recorded as Unknown.
Supported platforms
LinuxWindowsmacOS

Capabilities

Endpoint monitoring and inventoryRemote shell and script executionFile, process, and service managementUpdate and compliance managementBrowser-mediated remote-control functionsSelf-hosted server deployment

Executables & installation paths

Filename
obliance-agent.exe
OriginalFileName
Not recorded
Description
Windows MSI source names this endpoint service executable; no PE metadata was inspected.

Installation paths

C:\Program Files\OblianceAgent\obliance-agent.exe
C:\Program Files\OblianceAgent\obliance-tray.exe
C:\Program Files\OblianceAgent\obliance-watchdog.exe
C:\ProgramData\OblianceAgent\config.json
C:\ProgramData\OblianceAgent\agent.log
C:\ProgramData\OblianceAgent\watchdog.json
/opt/obliance-agent/obliance-agent
/etc/obliance-agent/config.json
/etc/systemd/system/obliance-agent.service
/etc/systemd/system/obliance-watchdog.service
/Library/LaunchDaemons/com.obliance.agent.plist
/usr/local/bin/obliance-agent
/var/log/obliance-agent.log

FORENSIC EVIDENCE

Disk artifacts

File
C:\Program Files\OblianceAgent\obliance-agent.exe
Description
Windows MSI service executable destination.
OS
Windows
File
C:\Program Files\OblianceAgent\obliance-tray.exe
Description
Windows MSI tray executable destination.
OS
Windows
File
C:\Program Files\OblianceAgent\obliance-watchdog.exe
Description
Windows MSI watchdog executable destination.
OS
Windows
File
C:\ProgramData\OblianceAgent\config.json
Description
Windows agent configuration path.
OS
Windows
File
C:\ProgramData\OblianceAgent\agent.log
Description
Windows service log path.
OS
Windows
File
C:\ProgramData\OblianceAgent\watchdog.json
Description
Windows watchdog state path.
OS
Windows
File
/opt/obliance-agent/obliance-agent
Description
Linux installer endpoint executable path.
OS
Linux
File
/etc/obliance-agent/config.json
Description
Linux agent configuration path.
OS
Linux
File
/etc/obliance-agent/config.json
Description
macOS agent configuration path.
OS
macOS
File
/etc/systemd/system/obliance-agent.service
Description
Linux systemd unit installed by the project script.
OS
Linux
File
/etc/systemd/system/obliance-watchdog.service
Description
Linux watchdog systemd unit installed by the project script.
OS
Linux
File
/Library/LaunchDaemons/com.obliance.agent.plist
Description
macOS LaunchDaemon plist installed by the project script.
OS
macOS
File
/usr/local/bin/obliance-agent
Description
macOS agent executable path in the project service source.
OS
macOS
File
/var/log/obliance-agent.log
Description
macOS LaunchDaemon log path.
OS
macOS

FORENSIC EVIDENCE

Event log artifacts

EventID
7045
ProviderName
Service Control Manager
LogFile
System
ServiceName
OblianceAgent
ImagePath
C:\Program Files\OblianceAgent\obliance-agent.exe
Description
Windows MSI source installs this automatic LocalSystem service.
CommandLine
Not recorded

FORENSIC EVIDENCE

Registry artifacts

Path
HKLM\SOFTWARE\OblianceAgent
Description
Windows MSI writes initial ServerUrl and ApiKey values, and agent code reads them if config.json is absent. Values can contain credentials and should not be published.
Path
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OblianceTray
Description
Windows MSI registers obliance-tray.exe for user-session startup.
Path
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\OblianceAgent
Description
Windows MSI and service source register the service for Safe Mode with Networking.
Path
HKLM\SYSTEM\CurrentControlSet\Services\OblianceAgent
Description
Windows service configuration key inferred from the MSI ServiceInstall definition.

FORENSIC EVIDENCE

Other artifacts

Type
WindowsServiceName
Value
OblianceAgent
Type
WindowsScheduledTask
Value
OblianceWatchdog
Type
LinuxSystemdUnit
Value
obliance-agent.service
Type
LinuxSystemdUnit
Value
obliance-watchdog.service
Type
macOSLaunchDaemonLabel
Value
com.obliance.agent

References