RMM
ProxiPort
ProxiPort is an open-source, self-hosted remote management and reverse- tunnel project with a server and endpoint agent. It supports remote command execution, script execution, file transfer, system monitoring, and tunnels. It is a distinct continuation of RPort/OpenRPort; this entry does not assign RPort abuse reporting or RealVNC signing metadata to ProxiPort.
Tool overview
- Category
- RMM
- Research authors
- Michael Haag
- Created
- 2026-09-28
- Last modified
- 2026-09-28
- Privileges
- The packaged endpoint agent installs as an automatic operating-system service; Linux uses the dedicated proxiport-agent account.
- Free / availability
- Yes
- Verification required
- Static review of pinned upstream source and documentation; no local binary, controller, or sample execution was performed. Windows MSI and Linux package sources establish the paths and service metadata below. The upstream documentation lists Linux, macOS, and Windows agents. No stable macOS installation path or service label was established in the pinned source, so no macOS artifact is asserted. No public malicious-use report was established in this review.
- Supported platforms
Linux
Windows
macOS
Capabilities
Executables & installation paths
- Filename
- proxiport.exe
- OriginalFileName
- Not recorded
- Description
- ProxiPort client for Windows
Installation paths
C:\Program Files\ProxiPort\proxiport.exe
C:\Program Files\ProxiPort\proxiport.conf
/usr/bin/proxiport
/etc/proxiport/proxiport.conf
/lib/systemd/system/proxiport.service
FORENSIC EVIDENCE
Disk artifacts
- File
- C:\Program Files\ProxiPort\proxiport.exe
- Description
- Windows MSI endpoint executable installed under the product directory.
- OS
- Windows
- File
- C:\Program Files\ProxiPort\proxiport.conf
- Description
- Windows MSI endpoint configuration file installed beside the client executable.
- OS
- Windows
- File
- /usr/bin/proxiport
- Description
- Linux agent executable installed by the package/manual install instructions.
- OS
- Linux
- File
- /etc/proxiport/proxiport.conf
- Description
- Linux agent configuration file.
- OS
- Linux
- File
- /var/lib/proxiport-agent
- Description
- Linux agent state directory created by the package/manual install instructions.
- OS
- Linux
- File
- /var/log/proxiport-agent
- Description
- Linux agent log directory created by the package/manual install instructions.
- OS
- Linux
- File
- /lib/systemd/system/proxiport.service
- Description
- Linux systemd unit for the packaged endpoint agent.
- OS
- Linux
FORENSIC EVIDENCE
Event log artifacts
- EventID
- 7045
- ProviderName
- Service Control Manager
- LogFile
- System
- ServiceName
- proxiport
- ImagePath
- C:\Program Files\ProxiPort\proxiport.exe -c C:\Program Files\ProxiPort\proxiport.conf
- Description
- Windows MSI installs an automatic proxiport service with the configuration file as its argument.
FORENSIC EVIDENCE
Registry artifacts
- Path
- HKLM\SYSTEM\CurrentControlSet\Services\proxiport
- Description
- Windows Service Control Manager key for the packaged endpoint agent.
FORENSIC EVIDENCE
Network artifacts
- Description
- Endpoint dials an administrator-configured ProxiPort server; the documented seeded server listener is TCP 80.
- Domains
- Not recorded
- Ports
- 80
FORENSIC EVIDENCE
Other artifacts
- Type
- WindowsServiceName
- Value
- proxiport
- Type
- LinuxSystemdService
- Value
- proxiport.service
- Type
- LinuxServiceAccount
- Value
- proxiport-agent
- Type
- ConfiguredServerField
- Value
- client.server
References
- https://github.com/proximile/proxiport/blob/1dfd4a9e1ca10be24fa2ee287b92d0967a2c7962/README.md
- https://github.com/proximile/proxiport/blob/1dfd4a9e1ca10be24fa2ee287b92d0967a2c7962/docs/install.md
- https://github.com/proximile/proxiport/blob/1dfd4a9e1ca10be24fa2ee287b92d0967a2c7962/opt/resource/Product.wxs
- https://github.com/proximile/proxiport/blob/1dfd4a9e1ca10be24fa2ee287b92d0967a2c7962/opt/systemd/proxiport.service
- https://github.com/proximile/proxiport/blob/1dfd4a9e1ca10be24fa2ee287b92d0967a2c7962/cmd/proxiport/servicemanagement/service.go
- https://github.com/proximile/proxiport/blob/1dfd4a9e1ca10be24fa2ee287b92d0967a2c7962/docs/changes-from-openrport.md