RMM

Remotely

Remotely is an open-source remote control and remote scripting solution built with .NET, Blazor, and SignalR. It uses a self-hosted server plus endpoint agent and desktop clients for remote support, unattended access, remote terminal or scripting, chat, and file transfer. Public reporting has observed Remotely abuse for persistent access in intrusions.

Tool overview

Category
RMM
Research authors
@0x6d786f
Created
2026-05-24
Last modified
2026-06-15
Privileges
Windows unattended installation requires elevation and creates an automatic Remotely_Service service. Linux and macOS installers create root-level systemd or launchd agents.
Free / availability
Yes
Verification required
Confirmed against the official immense/Remotely repository, installer scripts, project metadata, release metadata, and public abuse reporting. No file hashes were added because current upstream releases do not publish a stable standalone agent hash.
Supported platforms
LinuxWindowsmacOS

Capabilities

Remote controlRemote scriptingRemote terminalFile transferChatUnattended accessSelf-hosted server

Executables & installation paths

Filename
Remotely_Agent.exe
OriginalFileName
Remotely_Agent.exe
Description
Background service that maintains a connection to the Remotely server.
Filename
Remotely_Desktop.exe
OriginalFileName
Remotely_Desktop.exe
Description
Desktop client for allowing an IT administrator to provide remote support.

Installation paths

C:\Program Files\Remotely\Remotely_Agent.exe
C:\Program Files\Remotely\Desktop\Remotely_Desktop.exe
C:\Program Files\Remotely\ConnectionInfo.json
C:\Program Files\Remotely\etag.txt
/usr/local/bin/Remotely/Remotely_Agent
/usr/local/bin/Remotely/Desktop/Remotely_Desktop
/usr/local/bin/Remotely/ConnectionInfo.json
/etc/systemd/system/remotely-agent.service
/Library/LaunchDaemons/remotely-agent.plist

FORENSIC EVIDENCE

Disk artifacts

File
C:\Program Files\Remotely\Remotely_Agent.exe
Description
Windows unattended agent installed by Install-Remotely.ps1 and configured as the Remotely_Service service binary.
OS
Windows
File
C:\Program Files\Remotely\Desktop\Remotely_Desktop.exe
Description
Windows remote desktop client bundled under the Remotely installation directory.
OS
Windows
File
C:\Program Files\Remotely\ConnectionInfo.json
Description
Remotely agent configuration containing device, organization, and server connection information.
OS
Windows
File
C:\Program Files\Remotely\etag.txt
Description
ETag marker written by the Windows installer for update tracking.
OS
Windows
File
%TEMP%\Remotely_Install.txt
Description
Windows Remotely installer log path used by Install-Remotely.ps1.
OS
Windows
File
/usr/local/bin/Remotely/Remotely_Agent
Description
Linux and macOS Remotely agent binary path used by upstream installers.
OS
Linux/macOS
File
/usr/local/bin/Remotely/Desktop/Remotely_Desktop
Description
Linux and macOS remote desktop client path used by upstream installers.
OS
Linux/macOS
File
/usr/local/bin/Remotely/ConnectionInfo.json
Description
Linux and macOS Remotely agent configuration file.
OS
Linux/macOS
File
/var/log/remotely/Agent_Install.log
Description
Linux and macOS installer log path used by upstream shell installers.
OS
Linux/macOS
File
/etc/systemd/system/remotely-agent.service
Description
Linux systemd service file created by the upstream Ubuntu and Manjaro installers.
OS
Linux
File
/Library/LaunchDaemons/remotely-agent.plist
Description
macOS LaunchDaemon created by upstream macOS installers.
OS
macOS

FORENSIC EVIDENCE

Event log artifacts

EventID
7045
ProviderName
Service Control Manager
LogFile
System
ServiceName
Remotely_Service
ImagePath
C:\Program Files\Remotely\Remotely_Agent.exe
Description
Windows service installation event for Remotely unattended agent persistence.

FORENSIC EVIDENCE

Network artifacts

Description
Remotely agents connect to an operator-controlled/self-hosted server over the configured web listener. Docker quickstart maps TCP 5000; internet-facing deployments are commonly reverse-proxied over HTTPS.
Domains
Not recorded
Ports
  • 443
  • 5000

FORENSIC EVIDENCE

Other artifacts

Type
Windows Service Name
Value
Remotely_Service
Type
Linux systemd service
Value
remotely-agent.service
Type
macOS LaunchDaemon label
Value
com.translucency.remotely-agent
Type
Remotely Agent SignalR hub
Value
/hubs/service

Detections

Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/remotely_files_sigma.yml
Description
Detects potential files activity of Remotely RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/remotely_processes_sigma.yml
Description
Detects potential processes activity of Remotely RMM tool

References

Acknowledgements

Person
0x6d786f
Handle
@0x6d786f