RMM
Opale
Opale is an open-source, self-hosted remote monitoring and management platform. Its documented deployment uses a controller hosted by the organization and a Go Windows agent that enrolls with that controller, reports inventory, executes dispatched scripts, and supports signed agent updates. The public repository contains Linux and macOS agent-service code and cross-platform release assets, but its current README says endpoint management is Windows-only; this entry therefore records Windows as the supported endpoint platform.
Tool overview
- Category
- RMM
- Research authors
- Michael Haag
- Created
- 2026-09-28
- Last modified
- 2026-09-28
- Privileges
- Windows agent installation is documented to run as SYSTEM; the installed Windows service performs management actions in that context.
- Free / availability
- Open source
- Verification required
- Static source review only at repository commit 4bf1b7ad9dd810fa97e2d1c6dd09aeaca42ba692. No agent binary, installer, controller, enrollment token, or third-party endpoint was executed or contacted. Windows support is documented; source/release evidence for other platforms is not treated as supported endpoint management here.
- Supported platforms
Windows
Capabilities
Executables & installation paths
- Filename
- opale-agent.exe
- OriginalFileName
- Not recorded
- Description
- Default Windows agent filename copied by the repository installer; build-time branding can change this name.
Installation paths
C:\ProgramData\Opale\opale-agent.exe
FORENSIC EVIDENCE
Disk artifacts
- File
- C:\ProgramData\Opale\opale-agent.exe
- Description
- Default branded agent binary path; the source allows the data-directory and binary branding to be changed at build or deployment time.
- OS
- Windows
- File
- C:\ProgramData\Opale\config.json
- Description
- Agent configuration containing the enrollment token and controller URL.
- OS
- Windows
- File
- C:\ProgramData\Opale\state.json
- Description
- Persistent agent state file.
- OS
- Windows
- File
- C:\ProgramData\Opale\agent.log
- Description
- Default agent log file.
- OS
- Windows
FORENSIC EVIDENCE
Event log artifacts
- EventID
- 7045
- ProviderName
- Service Control Manager
- LogFile
- System.evtx
- ServiceName
- Opale-Agent
- ImagePath
- C:\ProgramData\Opale\opale-agent.exe
- Description
- A Windows service installation using the default source branding; the name and path are configurable.
FORENSIC EVIDENCE
Registry artifacts
- Path
- HKLM\SYSTEM\CurrentControlSet\Services\Opale-Agent
- Description
- SCM key expected when the default Opale-Agent Windows service is installed; its exact values vary with build-time branding and deployment path.
FORENSIC EVIDENCE
Network artifacts
- Description
- Controller endpoint is supplied during enrollment and stored in agent configuration; deployments are operator-hosted and have no shared vendor hostname.
- Domains
- Not recorded
- Ports
- Not recorded
FORENSIC EVIDENCE
Other artifacts
- Type
- DefaultWindowsServiceName
- Value
- Opale-Agent
- Type
- DefaultAgentUserAgentPrefix
- Value
- opale-agent-go
- Type
- DataDirectoryOverrideEnvironmentVariable
- Value
- RMM_DATA_DIR
References
- https://github.com/4rtefakt/opale
- https://github.com/4rtefakt/opale/blob/4bf1b7ad9dd810fa97e2d1c6dd09aeaca42ba692/README.md
- https://github.com/4rtefakt/opale/blob/4bf1b7ad9dd810fa97e2d1c6dd09aeaca42ba692/INSTALL.md
- https://github.com/4rtefakt/opale/blob/4bf1b7ad9dd810fa97e2d1c6dd09aeaca42ba692/agent-go/branding/branding.go
- https://github.com/4rtefakt/opale/blob/4bf1b7ad9dd810fa97e2d1c6dd09aeaca42ba692/agent-go/config.go
- https://github.com/4rtefakt/opale/blob/4bf1b7ad9dd810fa97e2d1c6dd09aeaca42ba692/agent-go/install.ps1
Acknowledgements
- Person
- 4rtefakt
- Handle
- @4rtefakt