RMM

Opale

Opale is an open-source, self-hosted remote monitoring and management platform. Its documented deployment uses a controller hosted by the organization and a Go Windows agent that enrolls with that controller, reports inventory, executes dispatched scripts, and supports signed agent updates. The public repository contains Linux and macOS agent-service code and cross-platform release assets, but its current README says endpoint management is Windows-only; this entry therefore records Windows as the supported endpoint platform.

Tool overview

Category
RMM
Research authors
Michael Haag
Created
2026-09-28
Last modified
2026-09-28
Privileges
Windows agent installation is documented to run as SYSTEM; the installed Windows service performs management actions in that context.
Free / availability
Open source
Verification required
Static source review only at repository commit 4bf1b7ad9dd810fa97e2d1c6dd09aeaca42ba692. No agent binary, installer, controller, enrollment token, or third-party endpoint was executed or contacted. Windows support is documented; source/release evidence for other platforms is not treated as supported endpoint management here.
Supported platforms
Windows

Capabilities

Endpoint inventory and monitoringController-dispatched script executionLocal administrator password rotationSigned agent auto-update

Executables & installation paths

Filename
opale-agent.exe
OriginalFileName
Not recorded
Description
Default Windows agent filename copied by the repository installer; build-time branding can change this name.

Installation paths

C:\ProgramData\Opale\opale-agent.exe

FORENSIC EVIDENCE

Disk artifacts

File
C:\ProgramData\Opale\opale-agent.exe
Description
Default branded agent binary path; the source allows the data-directory and binary branding to be changed at build or deployment time.
OS
Windows
File
C:\ProgramData\Opale\config.json
Description
Agent configuration containing the enrollment token and controller URL.
OS
Windows
File
C:\ProgramData\Opale\state.json
Description
Persistent agent state file.
OS
Windows
File
C:\ProgramData\Opale\agent.log
Description
Default agent log file.
OS
Windows

FORENSIC EVIDENCE

Event log artifacts

EventID
7045
ProviderName
Service Control Manager
LogFile
System.evtx
ServiceName
Opale-Agent
ImagePath
C:\ProgramData\Opale\opale-agent.exe
Description
A Windows service installation using the default source branding; the name and path are configurable.

FORENSIC EVIDENCE

Registry artifacts

Path
HKLM\SYSTEM\CurrentControlSet\Services\Opale-Agent
Description
SCM key expected when the default Opale-Agent Windows service is installed; its exact values vary with build-time branding and deployment path.

FORENSIC EVIDENCE

Network artifacts

Description
Controller endpoint is supplied during enrollment and stored in agent configuration; deployments are operator-hosted and have no shared vendor hostname.
Domains
Not recorded
Ports
Not recorded

FORENSIC EVIDENCE

Other artifacts

Type
DefaultWindowsServiceName
Value
Opale-Agent
Type
DefaultAgentUserAgentPrefix
Value
opale-agent-go
Type
DataDirectoryOverrideEnvironmentVariable
Value
RMM_DATA_DIR

References

Acknowledgements

Person
4rtefakt
Handle
@4rtefakt