Teramind
Teramind is a US-based employee/user activity monitoring (UAM), insider-threat and DLP platform that ships with a tightly integrated remote monitoring and management agent for Windows and macOS. The endpoint agent is delivered in two flavours — a "Revealed" agent installed under C:\Program Files / C:\ProgramData\Teramind Agent that surfaces a tray UI, and a "Hidden" / "Stealth" agent installed under C:\ProgramData\{4CEC2908-5CE4-48F0-A717-8FC833D8017A} which is intentionally absent from Add/Remove Programs and renames its core processes (default rename: dwm.exe for the agent, clm.exe for the clipboard monitor). The Windows service is registered as tsvchst, with tmagentsvc.exe as the actual on-disk service binary. Cloud tenants reach the platform over TLS/WebSocket on tcp/443 to `<tenant>.teramind.co` plus rt.teramind.co and www.teramind.co; on-premise tenants additionally use TCP 10000 (proprietary TLS) and 10000-11000 to the App Server. The hidden agent and renamed binaries make Teramind attractive both as an authorised covert workplace surveillance tool and as a dual-use remote-access capability that threat actors and rogue insiders can plant for persistent monitoring, screen recording and remote command execution. The Teramind Inc. code-signing certificate (issued by DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1) signs every component, which trivially defeats publisher-based allow-listing if the certificate is permitted. Proofpoint Emerging Threats Open ships ET INFO rules covering the teramind.co domain in DNS Lookup and TLS SNI traffic, which is the easiest network-side telemetry to turn on for hunting unauthorised deployments. This catalogue entry distinguishes endpoint artifacts (services, on-disk paths, registry, control-plane traffic) from the cloud / SaaS-only features (e.g. AI behaviour analytics, compliance dashboards) which run server-side and produce no endpoint footprint of their own.
Tool overview
- Category
- RMM
- Research authors
- @MHaggis
- Created
- 2026-05-04
- Last modified
- 2026-06-15
- Privileges
- SYSTEM
- Free / availability
- 14 day trial; subsequent paid subscription
- Verification required
- Tenant signup; Stealth/Hidden agent only available to vetted customers per vendor docs
- Supported platforms
Windows
macOS
Capabilities
Executables & installation paths
- Filename
- tmagentsvc.exe
- OriginalFileName
- tmagentsvc.exe
- Description
- Teramind Agent Windows service binary (registered under service name tsvchst); embedded URL https://www.teramind.co/d/update-shim.exe
- Filename
- Teramind.Setup.Updater.exe
- OriginalFileName
- Teramind.Setup.Updater.exe
- Description
- Teramind agent updater shim; renamed to update-shim.exe at runtime; .NET assembly signed by Teramind Inc.
- Filename
- Teramind.Setup.UI.exe
- OriginalFileName
- Teramind.Setup.UI.exe
- Description
- Teramind installer UI helper (signed by Teramind Inc.)
- Filename
- Teramind.Setup.UIARM.exe
- OriginalFileName
- Teramind.Setup.UIARM.exe
- Description
- Teramind installer UI helper for ARM64 Windows (signed by Teramind Inc.)
- Filename
- Teramind.Remover.Executable
- OriginalFileName
- Teramind.Remover.Executable
- Description
- Teramind agent removal utility (signed by Teramind Inc.)
- Filename
- teramind-remover.exe
- Description
- Teramind agent removal utility variant served from teramind.co
- Filename
- Teramind.Setup.Remover.exe
- Description
- Teramind agent removal utility variant served from teramind.co
- Filename
- dwm.exe
- Description
- Default rename target for the Teramind Hidden Agent core executable; configurable via TMAGENTEXE installer parameter — collides intentionally with the legitimate Desktop Window Manager process name
- Filename
- clm.exe
- Description
- Default rename target for the Teramind clipboard-monitor process; configurable via TMCLIPMONEXE installer parameter
- Filename
- update-shim.exe
- Description
- Runtime name of Teramind.Setup.Updater.exe; downloaded from https://www.teramind.co/d/update-shim.exe
Installation paths
FORENSIC EVIDENCE
Disk artifacts
- File
- C:\ProgramData\{4CEC2908-5CE4-48F0-A717-8FC833D8017A}\*
- Description
- Teramind Hidden / Stealth agent root install directory; named with a fixed product GUID. Vendor docs explicitly call this the verification path for confirming hidden-agent installation. Override via TMROOTDIR installer parameter.
- OS
- Windows
- File
- C:\ProgramData\{4CEC2908-5CE4-48F0-A717-8FC833D8017A}\config
- Description
- Teramind Hidden agent configuration directory
- OS
- Windows
- File
- C:\ProgramData\{4CEC2908-5CE4-48F0-A717-8FC833D8017A}\updates\rundll32.exe.config
- Description
- Teramind agent update staging artifact (.NET app.config sidecar) — directly observed as a Teramind-domain downloaded file in VirusTotal infrastructure data; the rundll32.exe filename is the renamed updater binary, not the legitimate Microsoft rundll32.
- OS
- Windows
- File
- C:\ProgramData\Teramind Agent\*
- Description
- Teramind Revealed agent root install directory (typical install layout)
- OS
- Windows
- File
- C:\ProgramData\Teramind Agent\config
- Description
- Teramind Revealed agent configuration directory
- OS
- Windows
- File
- C:\ProgramData\Teramind Agent\<version>\{6D99445F-F40F-45CB-B433-06302DAE6C70}\tmagentsvc.exe
- Description
- Teramind agent Windows service binary; vendor-documented exact image path (version directory varies by release, e.g. 24.12.0). Invoked with --service / -service.
- OS
- Windows
- File
- C:\ProgramData\Package Cache\.unverified\agent
- Description
- WiX bundle cache copy of the Teramind agent MSI; observed across multiple Teramind MSI submissions in VirusTotal infrastructure data.
- OS
- Windows
- File
- teramind_agent_*_bundle_noredist_setup.msi
- Description
- Teramind agent installer MSI; vendor enforces a fixed filename pattern and refuses to run if renamed. Observed signed variants include teramind_agent_v25.34.2799_bundle_noredist_setup.msi, teramind_agent_v25.31.2935_bundle_noredist_setup.msi, teramind_agent_v24.13.19_bundle_noredist_setup.msi, teramind_agent_v26.8.183_bundle_noredist_setup.msi.
- OS
- Windows
- File
- teramind_agent_*_x64.msi
- Description
- Teramind agent installer MSI (x64 variant) — observed naming pattern teramind_agent_x64.msi, teramind_agent_v5.0.0_x64.msi, teramind_agent_x64_s-i(__<hash>).msi where the trailing parenthesised value is the per-tenant install identifier.
- OS
- Windows
- File
- teramind_agent_*_ARM64.msi
- Description
- Teramind agent installer MSI (ARM64) — observed signed variants include teramind_agent_v26.8.183_ARM64.msi, teramind_agent_v26.8.183_ARM64_popup.msi, teramind_agent_v26.8.183_bundle_drivers_ARM64.msi.
- OS
- Windows
- File
- tmagent-i(__<hash>).pkg
- Description
- Teramind macOS agent PKG installer; vendor enforces a fixed filename pattern. Per-tenant identifier embedded as -i(__<hash>); renamed installers are rejected.
- OS
- MacOS
- File
- teramind_agent_*_hidden-do(<domain>).pkg
- Description
- Teramind macOS hidden-agent PKG installer with the deployment-domain installer parameter -do(<tenant>) baked into the filename, e.g. teramind_agent_v1.235.4632_hidden-do(acme.com).pkg
- OS
- MacOS
- File
- /usr/local/teramind/agent/bin/tmsysd
- Description
- Teramind macOS agent daemon binary
- OS
- MacOS
- File
- /usr/local/teramind/agent/etc/
- Description
- Teramind macOS agent configuration directory
- OS
- MacOS
- File
- /Applications/Teramind Agent.app
- Description
- Teramind Revealed macOS agent app bundle
- OS
- MacOS
- File
- /Applications/tmagent.app
- Description
- Teramind Hidden macOS agent app bundle
- OS
- MacOS
- File
- tmui
- Description
- Teramind Revealed-agent macOS UI component
- OS
- MacOS
- File
- Teramind.Setup.Updater.exe
- Description
- Teramind agent updater shim binary (.NET, signed by Teramind Inc.); contacts https://www.teramind.co/d/check?v=<version>&s=1&arch=<arch> on launch and downloads update-shim.exe from https://www.teramind.co/d/update-shim.exe
- OS
- Windows
- File
- tmdiag.zip
- Description
- Teramind diagnostic-bundle archive served from teramind.co; collected by the agent for vendor support
- OS
- Windows
FORENSIC EVIDENCE
Event log artifacts
- EventID
- 7045
- ProviderName
- Service Control Manager
- LogFile
- System.evtx
- ServiceName
- tsvchst
- ImagePath
- "C:\\ProgramData\\Teramind Agent\\<version>\\{6D99445F-F40F-45CB-B433-06302DAE6C70}\\tmagentsvc.exe" --service
- Description
- Service installation event for the Teramind Agent. The service name is tsvchst (vendor-documented), but the on-disk image is tmagentsvc.exe under the Teramind ProgramData install root. Stealth installs may use the GUID-named ProgramData path C:\ProgramData\{4CEC2908-5CE4-48F0-A717-8FC833D8017A}\ instead.
- EventID
- 4697
- ProviderName
- Microsoft-Windows-Security-Auditing
- LogFile
- Security.evtx
- ServiceName
- tsvchst
- CommandLine
- "C:\\ProgramData\\Teramind Agent\\<version>\\{6D99445F-F40F-45CB-B433-06302DAE6C70}\\tmagentsvc.exe" --service
- Description
- Service installation event (security auditing variant) for tsvchst / tmagentsvc.exe.
- EventID
- 4688
- ProviderName
- Microsoft-Windows-Security-Auditing
- LogFile
- Security.evtx
- CommandLine
- msiexec.exe /i teramind_agent_*_bundle_noredist_setup.msi
- Description
- Process creation observed at install time — msiexec invoking a Teramind agent MSI by its fixed filename pattern. The vendor's installer enforces that the MSI must not be renamed.
FORENSIC EVIDENCE
Registry artifacts
- Path
- HKLM\SYSTEM\CurrentControlSet\Services\tsvchst
- Description
- Teramind agent Windows service registration (service name = tsvchst)
- Path
- HKLM\SYSTEM\CurrentControlSet\Services\tsvchst\ImagePath
- Description
- ImagePath = "C:\ProgramData\Teramind Agent\<version>\{6D99445F-F40F-45CB-B433-06302DAE6C70}\tmagentsvc.exe" --service (or equivalent path under the GUID-named hidden-agent root)
- Path
- HKLM\SYSTEM\CurrentControlSet\Services\tsvchst\Start
- Description
- Start = 2 (Automatic) — service launches at boot
FORENSIC EVIDENCE
Network artifacts
- Description
- Teramind cloud tenant base domain — wildcard *.teramind.co covers per-tenant subdomains (e.g. acme.teramind.co) used for the agent control channel and the customer web console. Backed by Cloudflare (104.20.25.93, 172.66.155.133). The Teramind agent installer also enforces the deployment-domain via the -do(<domain>) parameter, baking the tenant subdomain into the installer filename.
- Domains
- *.teramind.co
- teramind.co
- www.teramind.co
- Ports
- 443
- Description
- Teramind cloud realtime / WebSocket endpoint — async video upload, live screen, and offline video upload traffic over wss://. Vendor-documented hostname.
- Domains
- rt.teramind.co
- Ports
- 443
- Description
- Teramind agent update / version check endpoint — directly observed as the in-the-wild URL contacted by Teramind.Setup.Updater.exe on launch (https://www.teramind.co/d/check?v=<version>&s=1&arch=<arch>) and as the download URL for the updater shim (https://www.teramind.co/d/update-shim.exe).
- Domains
- www.teramind.co
- Ports
- 443
- Description
- Teramind Sentry telemetry endpoint embedded in signed Teramind binaries; used for crash / error reporting back to Teramind.
- Domains
- sentry.dev.teramind.co
- Ports
- 443
- Description
- Teramind Master Server proprietary TLS protocol (on-premise deployments only). Used for agent ↔ Master Server control plane.
- Domains
- <on-prem-master-server-host>
- Ports
- 10000
- Description
- Teramind App Server traffic in multi-node on-premise deployments. Vendor-documented TCP port range.
- Domains
- <on-prem-app-server-host>
- Ports
- 10000
- 10001
- 10500
- 11000
- Description
- Teramind agent audio recording transport. Vendor-documented UDP, random port from a wide range; tenants commonly punch the entire 1000-65535 range in firewalls.
- Domains
- *.teramind.co
- Ports
- 1000-65535
- Description
- Teramind agent deployment / update fetch over plaintext HTTP. Vendor-documented as port 80 for agent deployment / update transport.
- Domains
- www.teramind.co
- Ports
- 80
FORENSIC EVIDENCE
Other artifacts
- Type
- Service Name
- Value
- tsvchst
- Type
- macOS Daemon
- Value
- tmsysd
- Type
- URL
- Value
- https://www.teramind.co/d/update-shim.exe
- Type
- Code Signing CN
- Value
- Teramind Inc.
- Type
- Code Signing Issuer
- Value
- DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
- Type
- Product GUID
- Value
- {4CEC2908-5CE4-48F0-A717-8FC833D8017A}
- Type
- Product GUID
- Value
- {6D99445F-F40F-45CB-B433-06302DAE6C70}
- Type
- SHA256
- Value
- e3ad70a1c8c540612dce4e90c3c619afafb429e297b5a1c9e1bbd4df985c4d24
- Type
- SHA256
- Value
- 998b69af0d3af49021d331d2e46a1734f38e28f03fb4dd3425e023ecc0c0a066
- Type
- SHA256
- Value
- 74e67c6671f6f987f4065e45ddd0cd7785be2330e2e0d273225a2b80bec405b1
- Type
- Snort/Suricata SID
- Value
- ET INFO Teramind RMM Domain (teramind .co) in DNS Lookup (Proofpoint Emerging Threats Open)
- Type
- Snort/Suricata SID
- Value
- ET INFO Observed Teramind RMM Domain (teramind .co) in TLS SNI (Proofpoint Emerging Threats Open)
Detections
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/teramind_files_sigma.yml
- Description
- Detects potential files activity of Teramind RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/teramind_network_sigma.yml
- Description
- Detects potential network activity of Teramind RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/teramind_processes_sigma.yml
- Description
- Detects potential processes activity of Teramind RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/teramind_registry_sigma.yml
- Description
- Detects potential registry activity of Teramind RMM tool
References
- https://www.teramind.co/
- https://kb.teramind.co/en/articles/8791027-which-location-folder-directory-is-teramind-agent-installed-on
- https://kb.teramind.co/en/articles/8791087-how-to-download-and-install-the-teramind-agent
- https://kb.teramind.co/en/articles/8791095-how-to-verify-if-the-agent-is-installed-uninstalled-running
- https://kb.teramind.co/en/articles/9182438-windows-agent-24-13-1482-2024-04-10
- https://kb.teramind.co/en/articles/8791054-how-to-check-if-teramind-ip-addresses-hosts-and-ports-are-reachable
- https://kb.teramind.co/en/articles/8791053-i-am-having-issues-with-the-firewall-and-proxy
- https://www.virustotal.com/gui/file/e3ad70a1c8c540612dce4e90c3c619afafb429e297b5a1c9e1bbd4df985c4d24
- https://www.virustotal.com/gui/file/998b69af0d3af49021d331d2e46a1734f38e28f03fb4dd3425e023ecc0c0a066
- https://www.virustotal.com/gui/file/74e67c6671f6f987f4065e45ddd0cd7785be2330e2e0d273225a2b80bec405b1
- https://www.virustotal.com/gui/domain/teramind.co
- https://rules.emergingthreats.net/
Acknowledgements
- Person
- Michael Haag
- Handle
- @M_haggis
- Person
- Proofpoint Emerging Threats Open
- Handle
- @ET_Labs