RMM

RemotePulse

RemotePulse is a remote monitoring and management platform that advertises unattended remote access, terminal access, file transfer, chat, real-time monitoring, Windows patching, script automation, multi-tenancy, and silent agent deployment. Public abuse reporting observed RemotePulse agent installation under C:\Program Files (x86)\RemotePulseAgent with command-line execution pointing to remotepulse.io.

Tool overview

Category
RMM
Research authors
Jason Killam
Created
2026-07-08
Last modified
2026-07-08
Privileges
SYSTEM
Free / availability
Not recorded
Verification required
Public RemotePulse website documents RMM capabilities including silent deployment and unattended remote access. Reported abuse artifacts are sourced from GitHub issue #226 and the linked sandbox behavior report.
Supported platforms
LinuxWindowsmacOS

Capabilities

Unattended remote desktopRemote terminalFile transferReal-time endpoint monitoringWindows patch managementScript automationSilent agent deployment

Executables & installation paths

Filename
InstallCore.exe
OriginalFileName
Not recorded
Description
RemotePulse agent installer component

Installation paths

C:\Program Files (x86)\RemotePulseAgent\InstallCore.exe
C:\Program Files (x86)\RemotePulseAgent\agent.ps1
C:\Program Files (x86)\RemotePulseAgent\defender-exclude.ps1
C:\Program Files (x86)\RemotePulseAgent\install.ps1
C:\Program Files (x86)\RemotePulseAgent\install.cmd

Code signing

search names

InstallCore.exe

company names

signer names

EIKON S.A.

FORENSIC EVIDENCE

Disk artifacts

File
C:\Program Files (x86)\RemotePulseAgent\InstallCore.exe
Description
RemotePulse agent installer component observed in issue 226.
OS
Windows
File
C:\Program Files (x86)\RemotePulseAgent\agent.ps1
Description
RemotePulse agent PowerShell script observed in issue 226.
OS
Windows
File
C:\Program Files (x86)\RemotePulseAgent\defender-exclude.ps1
Description
RemotePulse Defender exclusion script observed in issue 226.
OS
Windows
File
C:\Program Files (x86)\RemotePulseAgent\install.ps1
Description
RemotePulse PowerShell installer script observed in issue 226.
OS
Windows
File
C:\Program Files (x86)\RemotePulseAgent\install.cmd
Description
RemotePulse command installer wrapper observed in issue 226.
OS
Windows

FORENSIC EVIDENCE

Network artifacts

Description
Known RemotePulse service domains
Domains
  • remotepulse.io
  • www.remotepulse.io
Ports
  • 443

FORENSIC EVIDENCE

Other artifacts

Type
ObservedCommandLine
Value
cmd.exe /c "C:\Program Files (x86)\RemotePulseAgent\install.cmd" "<tenant-id>" "https://remotepulse.io" "<original-lure-path>" "<lure-name>"
Type
CodeSigningSigner
Value
EIKON S.A.
Type
ObservedSHA256
Value
4eab52778134487a4233915f30ddeeff9d165a4312a2d8c5256c20072cd8de53

References

Acknowledgements

Person
Jason Killam
Handle
rcKillam