RMM
RemotePulse
RemotePulse is a remote monitoring and management platform that advertises unattended remote access, terminal access, file transfer, chat, real-time monitoring, Windows patching, script automation, multi-tenancy, and silent agent deployment. Public abuse reporting observed RemotePulse agent installation under C:\Program Files (x86)\RemotePulseAgent with command-line execution pointing to remotepulse.io.
Tool overview
- Category
- RMM
- Research authors
- Jason Killam
- Created
- 2026-07-08
- Last modified
- 2026-07-08
- Privileges
- SYSTEM
- Free / availability
- Not recorded
- Verification required
- Public RemotePulse website documents RMM capabilities including silent deployment and unattended remote access. Reported abuse artifacts are sourced from GitHub issue #226 and the linked sandbox behavior report.
- Supported platforms
Linux
Windows
macOS
Capabilities
Executables & installation paths
- Filename
- InstallCore.exe
- OriginalFileName
- Not recorded
- Description
- RemotePulse agent installer component
Installation paths
C:\Program Files (x86)\RemotePulseAgent\InstallCore.exe
C:\Program Files (x86)\RemotePulseAgent\agent.ps1
C:\Program Files (x86)\RemotePulseAgent\defender-exclude.ps1
C:\Program Files (x86)\RemotePulseAgent\install.ps1
C:\Program Files (x86)\RemotePulseAgent\install.cmd
Code signing
search names
InstallCore.exe
company names
signer names
EIKON S.A.
FORENSIC EVIDENCE
Disk artifacts
- File
- C:\Program Files (x86)\RemotePulseAgent\InstallCore.exe
- Description
- RemotePulse agent installer component observed in issue 226.
- OS
- Windows
- File
- C:\Program Files (x86)\RemotePulseAgent\agent.ps1
- Description
- RemotePulse agent PowerShell script observed in issue 226.
- OS
- Windows
- File
- C:\Program Files (x86)\RemotePulseAgent\defender-exclude.ps1
- Description
- RemotePulse Defender exclusion script observed in issue 226.
- OS
- Windows
- File
- C:\Program Files (x86)\RemotePulseAgent\install.ps1
- Description
- RemotePulse PowerShell installer script observed in issue 226.
- OS
- Windows
- File
- C:\Program Files (x86)\RemotePulseAgent\install.cmd
- Description
- RemotePulse command installer wrapper observed in issue 226.
- OS
- Windows
FORENSIC EVIDENCE
Network artifacts
- Description
- Known RemotePulse service domains
- Domains
- remotepulse.io
- www.remotepulse.io
- Ports
- 443
FORENSIC EVIDENCE
Other artifacts
- Type
- ObservedCommandLine
- Value
- cmd.exe /c "C:\Program Files (x86)\RemotePulseAgent\install.cmd" "<tenant-id>" "https://remotepulse.io" "<original-lure-path>" "<lure-name>"
- Type
- CodeSigningSigner
- Value
- EIKON S.A.
- Type
- ObservedSHA256
- Value
- 4eab52778134487a4233915f30ddeeff9d165a4312a2d8c5256c20072cd8de53
References
Acknowledgements
- Person
- Jason Killam
- Handle
- rcKillam