RAT
Veyon
Veyon (Virtual Eye On Networks) is a free and open-source remote monitoring and classroom management software designed for educational environments and remote support scenarios. It enables monitoring and controlling computers across multiple platforms, allowing administrators and teachers to view and control computer labs, interact with students, and provide remote technical support.
Tool overview
- Category
- RAT
- Research authors
- Daniel Koifman (KoifSec)
- Created
- 2025-11-12
- Last modified
- 2025-11-12
- Privileges
- User
- Free / availability
- Yes
- Verification required
- No
- Supported platforms
Linux
Windows
Capabilities
Executables & installation paths
- Filename
- Not recorded
- OriginalFileName
- Not recorded
- Description
- Not recorded
- Product
- Not recorded
Installation paths
C:\Program Files\Veyon\*
C:\Program Files (x86)\Veyon\*
veyon-wcli.exe
veyon-worker.exe
veyon-server.exe
veyon-service.exe
veyon-master.exe
Code signing
- signer name
- Tobias Junghans
- certificate thumbprint
- 8F892D81447CDC2964F118C7DC45CA9759C222E9
- tbs sha256
- A505895C8E2222B5DE687B0BDAB5C3BF49E247C85E4FDF8779C028D31F00A376
- tbs sha1
- Not recorded
- signer name
- Tobias Junghans
- certificate thumbprint
- EBB8477300D089B339FECB224835A0A0B87EFEA0
- tbs sha256
- 8EF0D8B0EA4B35008C88AA54CA6787E2F4140361D0B193CDB5481EB49B32355D
- tbs sha1
- Not recorded
search names
veyon-server.exe
veyon-service.exe
veyon-wcli.exe
veyon-worker.exe
company names
signer names
Tobias Junghans
File hashes
- authenticode
- file name
- veyon-service.exe
- sha256
- 85D48AC33F718DBBA7295A6FA3C8A05BD6B39B402566709BDA6FE3E94986899B
- sha1
- 1F4C1A5FDCE602D67F41F55D30E4ED015B9B10E5
- file name
- veyon-server.exe
- sha256
- 7EF0076A6B0FDBE0EBB0266D59EC916424DB9F236F5B4D78AF79DB14532A47B5
- sha1
- 5367689376BDF0F7E9BA4418BE06F0DE0BB91328
- file name
- veyon-service.exe
- sha256
- 9C8311F37078C8EB6D132FFC89094E2E352A53F0E36B73019696134819DC775D
- sha1
- 64A8685F7DCE2AC2597F95133F930D0AA618187A
- file name
- veyon-worker.exe
- sha256
- BBF57D6E6FDC601E1F31A8221F0FD7845DBB32689DCB670654A0FB421F2C5195
- sha1
- F2D58832DBB0E38B544045AC8DD2FDE078BA3CF0
- file name
- veyon-server.exe
- sha256
- D530C5CE3875986E46F3985915C6DAFB149C9FE7362DE7548B8E53A904167F1F
- sha1
- 0FB7B3A7F9A53CDE64E09F7897B12974B637F2F6
- file name
- veyon-wcli.exe
- sha256
- DE0EC89B5BE9D22B6A28EFC4BA4C9D102E9A8430007D6DE91E2A24F0F6EBEA42
- sha1
- A2B2A1CD78B2975357906E0D65BB638423C0FAF2
- page
- Not recorded
FORENSIC EVIDENCE
Disk artifacts
- File
- C:\Windows\Temp\VeyonServer.log
- Description
- VeyonServer log file
- OS
- Windows
- File
- C:\Windows\Temp\VeyonService.log
- Description
- VeyonService log file
- OS
- Windows
- File
- C:\Users\*\AppData\Local\VeyonCLI.log
- Description
- Veyon command-line interface utility log
- OS
- Windows
FORENSIC EVIDENCE
Event log artifacts
- EventID
- 7045
- ProviderName
- Service Control Manager
- LogFile
- System.evtx
- ServiceName
- Veyon Service
- ImagePath
- "C:\\Program Files\\Veyon\\veyon-service.exe"
- Description
- Service installation event for Veyon Service
FORENSIC EVIDENCE
Registry artifacts
- Path
- HKLM\SOFTWARE\Veyon Solutions
- Description
- Main Veyon configuration registry key containing all service and application settings
- Path
- HKLM\SYSTEM\CurrentControlSet\Services\VeyonService
- Description
- Veyon service registration and configuration
Detections
- Splunk
- https://raw.githubusercontent.com/Koifman/Deathcon25/refs/heads/main/rmm_rodeo/veyon/spl.spl
- Description
- Detects Veyon RMM activity through registry modifications (EventCode 13), process creation (EventCode 1), and service installation (EventCode 4697)