RMM

Sentinel RMM

Sentinel RMM is an open-source, self-hosted management console and agent. Its Python agent reports inventory and health data, polls its configured controller for jobs, and can execute controller-dispatched jobs only when the controller enables remote execution. The project documents packaged Windows, macOS, and Linux agents for tagged releases, but this review found no published GitHub release at the reviewed commit.

Tool overview

Category
RMM
Research authors
Michael Haag
Created
2026-09-28
Last modified
2026-09-28
Privileges
Depends on the actions dispatched by the configured controller; the reviewed source does not establish a fixed service account.
Free / availability
Open source
Verification required
Static source review only at repository commit 554a21d64ab3a03df81520e1519ecb97cc1466bf. No package build, agent, controller, job, enrollment, or network service was run or contacted. Cross-platform support is documented and reflected in platform-specific source logic; availability of a published release was not established.
Supported platforms
LinuxWindowsmacOS

Capabilities

Endpoint inventory and health reportingController-polled remote jobsOptional remote command executionInstalled-software inventoryWake-on-LAN relay

Executables & installation paths

Filename
sentinel-agent.exe
OriginalFileName
Not recorded
Description
Windows filename configured by the repository PyInstaller specification; Linux and macOS builds use sentinel-agent.

Installation paths

C:\ProgramData\SentinelAgent\sentinel-agent.exe
/usr/local/sentinel-agent/sentinel-agent
/opt/sentinel-agent/sentinel-agent

FORENSIC EVIDENCE

Disk artifacts

File
C:\ProgramData\SentinelAgent\sentinel-agent.exe
Description
Windows self-install destination used by the reviewed agent source.
OS
Windows
File
/usr/local/sentinel-agent/sentinel-agent
Description
macOS self-install destination used by the reviewed agent source.
OS
macOS
File
/Library/LaunchDaemons/fr.sentinel.agent.plist
Description
macOS LaunchDaemon written by the reviewed agent source.
OS
macOS
File
/opt/sentinel-agent/sentinel-agent
Description
Linux self-install destination used by the reviewed agent source.
OS
Linux
File
/etc/systemd/system/sentinel-agent.service
Description
Linux systemd unit written by the reviewed agent source.
OS
Linux

FORENSIC EVIDENCE

Registry artifacts

Path
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SentinelAgent
Description
Task Scheduler cache key expected after the Windows self-installer creates the SentinelAgent task.

FORENSIC EVIDENCE

Network artifacts

Description
Controller URL and agent token are supplied at deployment; deployments are operator-hosted and have no shared vendor hostname.
Domains
Not recorded
Ports
Not recorded

FORENSIC EVIDENCE

Other artifacts

Type
SourceBinaryConfigurationMarker
Value
SENTINELCFG1
Type
RemoteExecutionFeatureFlag
Value
SENTINEL_ALLOW_EXEC=1
Type
ControllerUrlEnvironmentVariable
Value
SENTINEL_URL
Type
AgentTokenEnvironmentVariable
Value
SENTINEL_AGENT_TOKEN
Type
WindowsScheduledTaskName
Value
SentinelAgent
Type
macOSLaunchDaemonLabel
Value
fr.sentinel.agent
Type
LinuxSystemdServiceName
Value
sentinel-agent.service

References

Acknowledgements

Person
codexX64
Handle
@codexX64