RMM
Remotely
Remotely is an open-source remote control and remote scripting solution built with .NET, Blazor, and SignalR. It uses a self-hosted server plus endpoint agent and desktop clients for remote support, unattended access, remote terminal or scripting, chat, and file transfer. Public reporting has observed Remotely abuse for persistent access in intrusions.
Tool overview
- Category
- RMM
- Research authors
- @0x6d786f
- Created
- 2026-05-24
- Last modified
- 2026-06-15
- Privileges
- Windows unattended installation requires elevation and creates an automatic Remotely_Service service. Linux and macOS installers create root-level systemd or launchd agents.
- Free / availability
- Yes
- Verification required
- Confirmed against the official immense/Remotely repository, installer scripts, project metadata, release metadata, and public abuse reporting. No file hashes were added because current upstream releases do not publish a stable standalone agent hash.
- Supported platforms
Linux
Windows
macOS
Capabilities
Executables & installation paths
- Filename
- Remotely_Agent.exe
- OriginalFileName
- Remotely_Agent.exe
- Description
- Background service that maintains a connection to the Remotely server.
- Filename
- Remotely_Desktop.exe
- OriginalFileName
- Remotely_Desktop.exe
- Description
- Desktop client for allowing an IT administrator to provide remote support.
Installation paths
C:\Program Files\Remotely\Remotely_Agent.exe
C:\Program Files\Remotely\Desktop\Remotely_Desktop.exe
C:\Program Files\Remotely\ConnectionInfo.json
C:\Program Files\Remotely\etag.txt
/usr/local/bin/Remotely/Remotely_Agent
/usr/local/bin/Remotely/Desktop/Remotely_Desktop
/usr/local/bin/Remotely/ConnectionInfo.json
/etc/systemd/system/remotely-agent.service
/Library/LaunchDaemons/remotely-agent.plist
FORENSIC EVIDENCE
Disk artifacts
- File
- C:\Program Files\Remotely\Remotely_Agent.exe
- Description
- Windows unattended agent installed by Install-Remotely.ps1 and configured as the Remotely_Service service binary.
- OS
- Windows
- File
- C:\Program Files\Remotely\Desktop\Remotely_Desktop.exe
- Description
- Windows remote desktop client bundled under the Remotely installation directory.
- OS
- Windows
- File
- C:\Program Files\Remotely\ConnectionInfo.json
- Description
- Remotely agent configuration containing device, organization, and server connection information.
- OS
- Windows
- File
- C:\Program Files\Remotely\etag.txt
- Description
- ETag marker written by the Windows installer for update tracking.
- OS
- Windows
- File
- %TEMP%\Remotely_Install.txt
- Description
- Windows Remotely installer log path used by Install-Remotely.ps1.
- OS
- Windows
- File
- /usr/local/bin/Remotely/Remotely_Agent
- Description
- Linux and macOS Remotely agent binary path used by upstream installers.
- OS
- Linux/macOS
- File
- /usr/local/bin/Remotely/Desktop/Remotely_Desktop
- Description
- Linux and macOS remote desktop client path used by upstream installers.
- OS
- Linux/macOS
- File
- /usr/local/bin/Remotely/ConnectionInfo.json
- Description
- Linux and macOS Remotely agent configuration file.
- OS
- Linux/macOS
- File
- /var/log/remotely/Agent_Install.log
- Description
- Linux and macOS installer log path used by upstream shell installers.
- OS
- Linux/macOS
- File
- /etc/systemd/system/remotely-agent.service
- Description
- Linux systemd service file created by the upstream Ubuntu and Manjaro installers.
- OS
- Linux
- File
- /Library/LaunchDaemons/remotely-agent.plist
- Description
- macOS LaunchDaemon created by upstream macOS installers.
- OS
- macOS
FORENSIC EVIDENCE
Event log artifacts
- EventID
- 7045
- ProviderName
- Service Control Manager
- LogFile
- System
- ServiceName
- Remotely_Service
- ImagePath
- C:\Program Files\Remotely\Remotely_Agent.exe
- Description
- Windows service installation event for Remotely unattended agent persistence.
FORENSIC EVIDENCE
Network artifacts
- Description
- Remotely agents connect to an operator-controlled/self-hosted server over the configured web listener. Docker quickstart maps TCP 5000; internet-facing deployments are commonly reverse-proxied over HTTPS.
- Domains
- Not recorded
- Ports
- 443
- 5000
FORENSIC EVIDENCE
Other artifacts
- Type
- Windows Service Name
- Value
- Remotely_Service
- Type
- Linux systemd service
- Value
- remotely-agent.service
- Type
- macOS LaunchDaemon label
- Value
- com.translucency.remotely-agent
- Type
- Remotely Agent SignalR hub
- Value
- /hubs/service
Detections
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/remotely_files_sigma.yml
- Description
- Detects potential files activity of Remotely RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/remotely_processes_sigma.yml
- Description
- Detects potential processes activity of Remotely RMM tool
References
- https://github.com/immense/Remotely
- https://github.com/immense/Remotely/blob/master/README.md
- https://github.com/immense/Remotely/blob/master/Agent/Agent.csproj
- https://github.com/immense/Remotely/blob/master/Desktop.Win/Desktop.Win.csproj
- https://github.com/immense/Remotely/blob/master/Shared/Utilities/EnvironmentHelper.cs
- https://github.com/immense/Remotely/blob/master/Server/wwwroot/Content/Install-Remotely.ps1
- https://github.com/immense/Remotely/blob/master/Server/wwwroot/Content/Install-Ubuntu-x64.sh
- https://github.com/immense/Remotely/blob/master/Server/wwwroot/Content/Install-MacOS-x64.sh
- https://socprime.com/active-threats/voicemail-lure-leads-to-remote-access/
- https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-agenda
Acknowledgements
- Person
- 0x6d786f
- Handle
- @0x6d786f