RMM

RMMmax

RMMmax is a remote monitoring and management platform that integrates with existing RMM products or manages devices through its standalone agents. It supports remote command and script execution, software deployment, patch management, and system monitoring across Windows, macOS, and Linux.

Tool overview

Category
RMM
Research authors
Jose Hernandez
Created
2026-09-09
Last modified
2026-09-09
Privileges
Administrator for Windows installation; LocalSystem for the Windows service; root for Linux and macOS daemons
Free / availability
Yes
Verification required
Statically verified from user-provided Windows, macOS, and Linux packages on 2026-09-09; package hashes are recorded below. The Windows 0.2.0.4 installer contains RMMmaxAgentService.exe, which implements both the service and tray UI. Its PE OriginalFilename matches the extracted filename. Both Windows binaries pass embedded Authenticode signature and image-digest verification and carry the Plugins4 LLC certificate. The macOS UI executable is RMMmax Agent. Linux and macOS launch rmmmax_agent.py through a Python 3 wrapper named rmmmax-agent. Paths and service names come from installer metadata, decompiled Windows code, shell installers, systemd units, and launchd plists. No agent was installed or executed.
Supported platforms
LinuxWindowsmacOS

Capabilities

Remote monitoringCommand executionScript executionSoftware deploymentPatch management

Executables & installation paths

Filename
RMMmaxAgentSetup.exe
OriginalFileName
Not recorded
Description
RMMmax Agent Service Setup
Product
RMMmax Agent Service
Filename
RMMmaxAgentService.exe
OriginalFileName
RMMmaxAgentService.exe
Description
RMMmax Agent Service
Product
RMMmax Agent Service

Installation paths

RMMmaxAgentSetup.exe
%ProgramData%\rmmmax\AgentService\RMMmaxAgentService.exe
/var/rmmmax/agentservice/rmmmax_agent.py
/usr/local/bin/rmmmax-agent
/Applications/RMMmax Agent.app/Contents/MacOS/RMMmax Agent

Code signing

src file path
RMMmaxAgentService.exe
src file sha256
9361b9b740474203f1a27be1f24cb91be7235fe2f358b791fc82fad46a1c7946
src file company
RMMmax
signer name
Plugins4 LLC
issuer
Sectigo Public Code Signing CA R36
certificate thumbprint
7fd6a08189c32c34b514b158ef59752c58ca29fb
tbs sha256
ec89ca7df4a77f624083614fcfb0e34f2f25e0a7ea9a5f4c0ba5cd53be5c0d02
tbs sha1
981735579f9101ddd4b182e6283c4263a22f8658
valid from
2025-02-19T00:00:00+00:00
valid to
2027-02-19T23:59:59+00:00

search names

RMMmaxAgentSetup.exe
RMMmaxAgentService.exe

company names

RMMmax

signer names

Plugins4 LLC

File hashes

authenticode
  • file name
    RMMmaxAgentSetup.exe
    sha256
    a03e35f8814e9216dff5c02717826b27ee0c7866fc1ffa5943c37708e15cf093
  • file name
    RMMmaxAgentService.exe
    sha256
    074c33e7057676c507262afe0b75deec1867065a7b4596bdb7e60eec3128c410

FORENSIC EVIDENCE

Disk artifacts

File
%ProgramData%\rmmmax\AgentService\RMMmaxAgentService.exe
Description
Windows service and tray UI executable; destination confirmed by the supplied Inno Setup installer.
OS
Windows
File
%ProgramData%\RMMmax\AgentService\activity.log
Description
Windows agent activity log path confirmed in the decompiled agent.
OS
Windows
File
%SystemRoot%\Temp\rmmmax_*.ps1
Description
Temporary PowerShell command scripts created by the Windows agent and deleted after execution.
OS
Windows
File
/var/rmmmax/agentservice/rmmmax_agent.py
Description
Linux agent script executed by Python 3; installed by the supplied shell installer.
OS
Linux
File
/usr/local/bin/rmmmax-agent
Description
Linux CLI wrapper generated by install.sh; executes python3 with the agent script.
OS
Linux
File
/etc/systemd/system/rmmmax-agent.service
Description
Linux systemd unit; runs /usr/local/bin/rmmmax-agent run as root.
OS
Linux
File
/var/rmmmax/agentservice/config.json
Description
Linux agent registration state and rotating authentication token.
OS
Linux
File
/var/rmmmax/agentservice/activity.log
Description
Linux agent activity log.
OS
Linux
File
/Applications/RMMmax Agent.app/Contents/MacOS/RMMmax Agent
Description
macOS UI executable confirmed by the app bundle and launchd UI plist; universal x86_64 and arm64 binary with an ad hoc signature.
OS
macOS
File
/var/rmmmax/agentservice/rmmmax_agent.py
Description
macOS daemon script; launchd executes it with /usr/bin/python3 and the run argument.
OS
macOS
File
/usr/local/bin/rmmmax-agent
Description
macOS CLI wrapper generated by install.sh; executes /usr/bin/python3 with the agent script.
OS
macOS
File
/Library/LaunchDaemons/com.rmmmax.agentservice.plist
Description
macOS launchd daemon configuration; starts the Python agent as root at boot.
OS
macOS
File
/Library/LaunchAgents/com.rmmmax.agentui.plist
Description
macOS launchd UI configuration; starts RMMmax Agent with --tray at GUI login.
OS
macOS
File
/var/rmmmax/agentservice/config.json
Description
macOS agent registration state and authentication tokens.
OS
macOS
File
/var/rmmmax/agentservice/state.json
Description
macOS daemon's sanitized state file for the unprivileged UI.
OS
macOS
File
/var/rmmmax/agentservice/activity.log
Description
macOS agent activity log.
OS
macOS

FORENSIC EVIDENCE

Event log artifacts

ProviderName
RMMmaxAgentService
LogFile
Application.evtx
Description
Windows agent creates the RMMmaxAgentService event source in the Application log.

FORENSIC EVIDENCE

Registry artifacts

Path
HKLM\SOFTWARE\RMMmax\AgentService
Description
Logical configuration key used by the Windows installer and agent; stores registration state and DPAPI-protected tokens in the process registry view.
Path
HKLM\SYSTEM\CurrentControlSet\Services\RMMmaxAgentService
Description
Windows service registered by the agent through sc.exe create with obj= LocalSystem and start= auto.
Path
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\RMMmaxAgentService
Description
Windows tray UI startup value; invokes the agent executable with /tray when the service is installed.

FORENSIC EVIDENCE

Network artifacts

Description
Default HTTPS API host embedded in all three supplied agents; enrollment can configure a different API base URL.
Domains
  • api.rmmmax.com
Ports
  • 443

FORENSIC EVIDENCE

Other artifacts

Type
WindowsInstallerSHA256 (RMMmaxAgentSetup.exe)
Value
5185359f18b9b0dba1b86cd1cfca6fbbe523611ce248742223ed9f6a446186c3
Type
WindowsAgentSHA256 (RMMmaxAgentService.exe)
Value
9361b9b740474203f1a27be1f24cb91be7235fe2f358b791fc82fad46a1c7946
Type
MacOSInstallerSHA256 (RMMmax-Agent-Installer.dmg)
Value
982ddbb150b3c4b64e4f741ea522b2e4528380e64ed9a274e0d0b235168553c4
Type
LinuxPackageSHA256 (rmmmax_linux_agent.tgz)
Value
9b29df09e57aad8cb7bdb96686c494814386e01a0469b69a85eec4e5b1b79ae2
Type
WindowsTrayMutex
Value
RMMMaxAgentService_TrayInstance

References