RMM

Roster

Roster is an AGPL-3.0-licensed, self-hosted endpoint-inventory and remote management project. Its Go server distributes enrollment-specific agents; the reviewed deployment code installs Windows, Linux, and macOS agents with inventory, monitoring, remote-operation, and task capabilities. This entry records source-defined artifacts and does not establish a delivery relationship or malicious use.

Tool overview

Category
RMM
Research authors
Michael Haag
Created
2026-09-28
Last modified
2026-09-28
Privileges
The documented Windows startup script and Linux/macOS service installation require administrative privileges; the source was not executed.
Free / availability
Yes
Verification required
Static source review at commit 4d753560c9fdb6e9b066eb934ccf07ab394c31a4. Deployment scripts directly define the listed Windows service, Linux systemd unit, macOS LaunchDaemon, executable locations, configuration, and log path. The server URL and enrollment token are generated by an operator deployment, so they are intentionally not generic network indicators. No release binary, installation, enrollment, or remote operation was executed. This is a young project; source presence is not independent deployment or maturity validation.
Supported platforms
LinuxWindowsmacOS

Capabilities

Endpoint inventory and monitoringRemote terminal and scripted tasksFile and service operationsWindows remote controlSelf-hosted server with enrollment-specific agents

Executables & installation paths

Filename
agent-windows-amd64.exe
OriginalFileName
Not recorded
Description
Windows distribution filename specified by the repository deployment script; no PE metadata was inspected.

Installation paths

C:\Program Files\Roster\*
C:\ProgramData\Roster\agent.yaml
C:\ProgramData\Roster\agent-state.json
/usr/local/bin/roster-agent
/etc/roster/agent.yaml
/etc/systemd/system/roster-agent.service
/Library/LaunchDaemons/com.roster.agent.plist
/var/log/roster-agent.log

FORENSIC EVIDENCE

Disk artifacts

File
C:\Program Files\Roster\agent.exe
Description
Windows agent destination specified by deploy/windows/install-agent.ps1.
OS
Windows
File
C:\ProgramData\Roster\agent.yaml
Description
Windows agent configuration written by the deployment script.
OS
Windows
File
C:\ProgramData\Roster\agent-state.json
Description
Windows agent state path configured by the deployment script.
OS
Windows
File
/usr/local/bin/roster-agent
Description
Linux agent executable path in the supplied systemd unit.
OS
Linux
File
/usr/local/bin/roster-agent
Description
macOS agent executable path in the supplied LaunchDaemon plist.
OS
macOS
File
/etc/roster/agent.yaml
Description
Linux agent configuration path in the supplied systemd unit.
OS
Linux
File
/etc/roster/agent.yaml
Description
macOS agent configuration path in the supplied LaunchDaemon plist.
OS
macOS
File
/etc/systemd/system/roster-agent.service
Description
Linux systemd unit supplied by the project.
OS
Linux
File
/Library/LaunchDaemons/com.roster.agent.plist
Description
macOS LaunchDaemon plist supplied by the project.
OS
macOS
File
/var/log/roster-agent.log
Description
Standard output and error path in the macOS LaunchDaemon plist.
OS
macOS

FORENSIC EVIDENCE

Event log artifacts

EventID
7045
ProviderName
Service Control Manager
LogFile
System
ServiceName
roster-agent
ImagePath
C:\Program Files\Roster\agent.exe
Description
Windows deployment script invokes the agent to install the roster-agent service from this executable path.
CommandLine
C:\Program Files\Roster\agent.exe -config C:\ProgramData\Roster\agent.yaml install

FORENSIC EVIDENCE

Other artifacts

Type
WindowsServiceName
Value
roster-agent
Type
LinuxSystemdUnit
Value
roster-agent.service
Type
macOSLaunchDaemonLabel
Value
com.roster.agent

References