RMM

RG System (RG Supervision)

RG System Suite is a commercial remote monitoring and management platform from Septeo IT Solutions, also known as RG Supervision. It provides endpoint monitoring, remote script execution, patch management, and remote-access workflows. An inspected Windows deployment-kit agent was distributed under the name Adobe_Helper.exe from a third-party download location while retaining RG Supervision product metadata and a valid RG System publisher signature. The filename is a masquerading lead, not proof of unauthorized access or of a particular actor. Vendor domains and normal installation artifacts identify the product and should be assessed against approved remote-management usage.

Tool overview

Category
RMM
Research authors
Michael Haag
Created
2026-09-22
Last modified
2026-09-22
Privileges
Administrator required for Windows agent installation
Free / availability
No
Verification required
Vendor documentation establishes the management capabilities, deployment methods, service name, and example installation directory. Windows agent version 2.4.132 was inspected statically; its full-file SHA-256, PE metadata, Authenticode digest, and publisher signature were verified locally without executing the sample. A recorded download relationship preserves the Adobe_Helper.exe basename. Existing sandbox evidence corroborates the RG Systemes registry hierarchy, temporary rgsupv cache, and DNS lookup of lisa.rg-supervision.com; it does not demonstrate a completed installation or remote-control session. The inspected executable contains deployment-kit configuration; account and enrollment values are intentionally omitted. Linux and macOS support is vendor-documented. The Linux init-script artifact comes from legacy vendor documentation; it was not checked against a current package. macOS installation artifacts and Unix runtime behavior were not independently verified.
Supported platforms
LinuxWindowsmacOS

Capabilities

Endpoint monitoring and inventoryRemote script executionPatch managementRemote access through native protocols or the optional Assist service

Executables & installation paths

Filename
RG_Supervision.exe
OriginalFileName
rgsupvd
Description
RG Supervision Agent
Product
RG Supervision

Installation paths

C:\Program Files (x86)\RG-Supervision\*
C:\Program Files\RG-Supervision\*

Code signing

signer name
RG Systèmes SAS
certificate thumbprint
7E997EC20D1980963E55A567DE7B11ED4FA4D299
issuer
DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
valid from
2026-01-20T00:00:00Z
valid to
2027-01-26T23:59:59Z
tbs sha256
33d53aa1aa53b316481aff57d550f4fb8a97581b92c700e9d3302cffa2bf3240
tbs sha1
9ac6af3876e4ebc5a25118fdc00b6b57a80ae2a6
src file sha256
076b561bddf88c1482feefb2cbbc11a82b7829528988fd246a6e4a245eb48e73
src file path
Adobe_Helper.exe
src file company
RG System

search names

rgsupvd
RG-Setup.exe

company names

RG System

signer names

RG Systèmes SAS

File hashes

authenticode
  • file name
    rgsupvd
    sha256
    09d04663a7a6bb750241a3e84f7df599cbcf0b5fd28d273b749fe50515bcd9c3
    sha1
    Not recorded

FORENSIC EVIDENCE

Disk artifacts

File
*\RG-Supervision\RG_Supervision.exe
Description
Product executable named in the inspected agent's copy-error string, scoped to the vendor's example installation directory; the installation path is configurable.
OS
Windows
File
*\AppData\Local\Temp\rgsupv\cache\prepared
Description
Temporary cache artifact written by the inspected Windows sample in existing sandbox evidence.
OS
Windows
File
/etc/init.d/rgsupv
Description
SysV init script installed from rgsupv-init in the vendor's Linux monitoring-agent instructions; legacy documented artifact, not evidence of a current systemd unit.
OS
Linux

FORENSIC EVIDENCE

Registry artifacts

Path
HKLM\SOFTWARE\RG Systemes\RG Supervision
Description
Native-view Windows agent configuration hierarchy, corroborated by registry activity and embedded strings.
Path
HKLM\SOFTWARE\WOW6432Node\RG Systemes\RG Supervision
Description
32-bit Windows agent configuration hierarchy, also documented for the expected-host-name network setting.
Path
HKLM\SYSTEM\CurrentControlSet\Services\RG-Supervision
Description
Windows service configuration key inferred from the RG-Supervision service name in vendor deployment scripts.

FORENSIC EVIDENCE

Network artifacts

Description
Agent host present in the inspected deployment-kit configuration and observed DNS queries; no completed connection was established by the reviewed traffic summary.
Domains
  • lisa.rg-supervision.com
Ports
Not recorded
Description
HTTPS API URL embedded in the inspected agent; static reference, not an observed connection.
Domains
  • api.rg-supervision.com
Ports
  • 443
Description
Vendor dashboard, agent download, and support endpoint documented by the vendor and embedded in the agent.
Domains
  • dashboard.rg-supervision.com
Ports
  • 443

FORENSIC EVIDENCE

Other artifacts

Type
ServiceName
Value
RG-Supervision
Type
DocumentedLinuxServiceName
Value
rgsupv
Type
InspectedWindowsAgentSHA256
Value
076b561bddf88c1482feefb2cbbc11a82b7829528988fd246a6e4a245eb48e73
Type
InspectedWindowsAgentVersion
Value
2.4.132
Type
DeploymentKitFormat
Value
Embedded JSON deployment configuration delimited by ---BEGIN_BLOB--- and ---END_BLOB---; values are deployment-specific and excluded.

References

Acknowledgements

Person
patialavii
Handle
@patialavii