This is a non-exhaustive list of executables associated with a top RMM list, correlated against observations for unique executables.

Wildcard (*) patterns are used to generalize random values (and to sanitize).

download as json

original source

Windows

Ninja RMM

executablecode_signature.subject_name
C:\Program Files*\*\NinjaRMMAgentPatcher.exeNinjaRMM, LLC
C:\Program Files*\NinjaRMMAgent\NinjaRMMAgentPatcher.exeNinjaRMM, LLC
C:\ProgramData\NinjaRMMAgent\ninjarmm-cli.exe
C:\Program Files*\*\NinjaRMMAgent.exeNinjaRMM, LLC
C:\Program Files*\NinjaRMMAgent\NinjaRMMAgent.exeNinjaRMM, LLC

Atera

executablecode_signature.subject_name
C:\Program Files*\ATERA Networks\AteraAgent\AteraAgent.exe
C:\Program Files*\ATERA Networks\AteraAgent\Packages\AgentPackageNetworkDiscoveryWG\AgentPackageNetworkDiscoveryWG.exe
C:\Program Files*\ATERA Networks\AteraAgent\Packages\AgentPackageAgentInformation\AgentPackageAgentInformation.exe
C:\Program Files*\ATERA Networks\AteraAgent\Packages\AgentPackageSTRemote\AgentPackageSTRemote.exeAtera Networks Ltd
C:\Program Files*\ATERA Networks\AteraAgent\Packages\AgentPackageFileExplorer\AgentPackageFileExplorer.exe
C:\Program Files*\ATERA Networks\AteraAgent\Packages\AgentPackageMonitoring\AgentPackageMonitoring.exe
C:\Program Files*\ATERA Networks\AteraAgent\Packages\AgentPackageRuntimeInstaller\AgentPackageRuntimeInstaller.exe

GoToMeeting

executablecode_signature.subject_name
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\GoToAssist Remote Support Applet\*.tmp\GoToAssistService.exeLogMeIn, Inc.
C:\Users\*\AppData\Local\GoToAssist Remote Support Applet\*.tmp\GoToAssistProcessChecker.exeLogMeIn, Inc.
C:\Program Files*\LogMeIn\GoToAssist Corporate\*\G2AC_HostLauncher.exe
C:\Program Files*\GoToMeeting\*\G2MInstaller.exe
C:\Users\*\AppData\Local\GoToMeeting\*\g2mcomm.exe
C:\Users\*\AppData\Local\GoToMeeting\*\g2mlauncher.exe
C:\Program Files*\GoToAssist Remote Support Customer\*\g2ax_host_service.exe
C:\Program Files*\GoToAssist Remote Support Customer\*\g2ax_comm_customer.exe
C:\Users\*\AppData\Local\GoTo Resolve Applet\*.tmp\GoToResolveService.exe
C:\Program Files*\GoToAssist Remote Support Unattended\*\GoToAssistTools64.exeLogMeIn, Inc.
C:\Program Files*\GoToAssist Remote Support Unattended\*\GoToAssistUnattended.exe
C:\Users\*\AppData\Local\goto-updater\pending\GoToSetup-*.exe
C:\Program Files*\GoToMeeting\*\g2mlauncher.exe
C:\Users\*\AppData\Local\GoToAssist Remote Support Applet\*.tmp\GoToAssistCrashHandler.exeLogMeIn, Inc.
C:\Users\*\AppData\Local\GoToMeeting\*\g2mupdate.exeLogMeIn, Inc.

Manage Engine

executablecode_signature.subject_name
C:\ManageEngine\DesktopCentralMSP_Server\jre\bin\java.exe
C:\ManageEngine\ADManager Plus\jre\bin\java.exe
C:\Program Files*\ManageEngine\PMP\tools\archiver\windows\x86-64\7za.exe
C:\ManageEngine\elasticsearch\jre\bin\java.exe
C:\Program Files*\ManageEngine\PMP\jre\bin\java.exe
C:\Program Files*\ManageEngine\ServiceDesk\DesktopCentral_Server\bin\7za.exe
C:\Program Files*\ManageEngine\ServiceDesk\DesktopCentral_Server\bin\wrapper.exe
C:\ManageEngine\OpManager\jre\bin\java.exeOracle America, Inc.
C:\ManageEngine\EventLog Analyzer\jre\bin\java.exe
C:\ManageEngine\ADAudit Plus\pgsql\bin\postgres.exe
C:\ManageEngine\OpManager\Probe\OpManagerProbe\pgsql\bin\postgres.exe

Microsoft Intune

executablecode_signature.subject_name
C:\Program Files*\Microsoft Intune Management Extension\ClientHealthEval.exe
C:\Program Files*\WindowsApps\Microsoft.*\IntuneManagementExtensionBridge\IntuneManagementExtensionBridge.exe
C:\Program Files*\WindowsApps\Microsoft.*\BridgeLauncher\BridgeLauncher.exe
C:\Program Files*\Microsoft Intune Management Extension\Microsoft.Management.Services.IntuneWindowsAgent.exe
C:\Program Files*\Microsoft Intune Management Extension\Microsoft.Management.Clients.CopyAgentCatalog.exe
C:\Program Files*\Microsoft Intune Management Extension\SensorLogonTask.exe
C:\Program Files*\Microsoft Intune Management Extension\AgentExecutor.exe

N-Central

executablecode_signature.subject_name
C:\Users\*\AppData\Local\MSP Anywhere for N-central\Viewer\Tmp\SWI_MSP_RC_ViewerUpdate-*.exe

Desktop Central

executablecode_signature.subject_name
C:\Program Files*\DesktopCentral_Agent\bin\dcagentservice.exe
C:\Program Files*\DesktopCentral_Agent\bin\DCFAService64.exe
C:\Program Files*\DesktopCentral_Agent\bin\dcagentregister.exe
C:\Program Files*\DesktopCentral_Server\pgsql\bin\postgres.exe
C:\Program Files*\DesktopCentral_Server\bin\wrapper.exe
C:\ManageEngine\DesktopCentral_Server\bin\wrapper.exe
C:\Program Files*\DesktopCentral_Server\bin\UEMS.exe
C:\Program Files*\DesktopCentral_Server\nginx\dcnginx.exe
C:\Program Files*\ManageEngine\ServiceDesk\DesktopCentral_Server\jre\bin\java.exe
C:\Program Files*\DesktopCentral_Agent\bin\EMSAddonInstaller.exe
C:\ManageEngine\DesktopCentral_Server\jre\bin\java.exeAzul Systems, Inc.
C:\Program Files*\DesktopCentral_Server\apache\bin\dcserverhttpd.exe
C:\Program Files*\DesktopCentral_Server\bin\7za.exe
C:\Program Files*\DesktopCentral_Server\jre\bin\java.exe
C:\Program Files*\DesktopCentral_Server\bin\dcnotificationserver.exe
C:\Program Files*\DesktopCentral_Agent\dcconfig.exe
C:\Program Files*\DesktopCentral_Agent\patches\*-gimp-*-setup.exe
C:\ManageEngine\AssetExplorer\DesktopCentral_Server\bin\wrapper.exe
C:\Program Files*\ManageEngine\ServiceDesk\DesktopCentral_Server\lib\native\64bit\wrapper.dllTanuki Software Ltd.
C:\Program Files*\ManageEngine\ServiceDesk\DesktopCentral_Server\jre\bin\awt.dllAzul Systems, Inc.
C:\Program Files*\ManageEngine\ServiceDesk\DesktopCentral_Server\jre\bin\sunec.dllAzul Systems, Inc.
C:\Program Files*\ManageEngine\ServiceDesk\DesktopCentral_Server\jre\bin\freetype.dllAzul Systems, Inc.
C:\Program Files*\ManageEngine\ServiceDesk\DesktopCentral_Server\jre\bin\fontmanager.dllAzul Systems, Inc.
C:\Program Files*\ManageEngine\ServiceDesk\DesktopCentral_Server\lib\native\64bit\SyMNative.dllZOHO Corporation Private Limited
C:\Program Files*\ManageEngine\ServiceDesk\DesktopCentral_Server\lib\native\64bit\OSDSyMNative.dllZOHO Corporation Private Limited

Action1

executablecode_signature.subject_name
C:\Windows\Action1\action1_remote.exe
C:\Windows\Action1\action1_agent.exeAction1 Corporation

ConnectWise

executablecode_signature.subject_name
C:\Users\*\AppData\Roaming\ConnectWise\cache\*\controls\cef\ConnectWise.exeConnectwise, LLC
C:\Users\*\AppData\Roaming\ConnectWise\cache\*\controls\cef\ConnectWise.exeConnectWise, LLC
C:\Program Files*\ConnectWise\*\ConnectWiseManage.exeConnectWise, LLC
C:\Program Files*\ScreenConnect\Bin\ScreenConnect.Service.exeConnectwise, LLC
C:\Program Files*\ScreenConnect\Bin\ScreenConnect.Client.exeConnectwise, LLC
C:\Windows\LTSvc\LTSVC.exeConnectwise, LLC
C:\Users\*\Downloads\ConnectWiseControl.Client.exeConnectwise, LLC

MacOS

Ninja RMM

executablecode_signature.subject_name
/Applications/NinjaRMMAgent/programfiles/ninjarmm-macagentDeveloper ID Application: NinjaRMM LLC (EBNT3ZX97E)

GoToMeeting

executablecode_signature.subject_name
/Applications/GoToMeeting.app/Contents/MacOS/GoToMeeting
/Applications/GoToMeeting.app/Contents/Helpers/G2MUpdate
/Users/*/Library/Application Support/LogMeInInc/GoToMeeting/G2MUpdate

Microsoft Intune

executablecode_signature.subject_name
/Library/Intune/Microsoft Intune Agent.app/Contents/MacOS/IntuneMdmDaemon

N-Central

executablecode_signature.subject_name
/Applications/MSP Anywhere Agent N-central.app/Contents/Resources/MSP Anywhere Service Configurator.app/Contents/MacOS/MSP Anywhere Service ConfiguratorDeveloper ID Application: N-able Technologies Inc. (YT3GCGK3Z7)
/Applications/MSP Anywhere Agent N-central.app/Contents/Resources/MSP Anywhere HelperDeveloper ID Application: N-able Technologies Inc. (YT3GCGK3Z7)

Jamf

executablecode_signature.subject_name
/usr/local/jamf/bin/jamfDeveloper ID Application: JAMF Software (483DWKW443)
/Library/Application Support/JAMF/Jamf.app/Contents/MacOS/JamfDaemon.app/Contents/MacOS/JamfDaemonDeveloper ID Application: JAMF Software (483DWKW443)
/Library/Application Support/JAMF/Jamf.app/Contents/MacOS/JamfManagementService.app/Contents/MacOS/JamfManagementServiceDeveloper ID Application: JAMF Software (483DWKW443)
/Library/Application Support/JAMF/Jamf.app/Contents/MacOS/JamfManagementService.app/Contents/MacOS/jamf_trampolineDeveloper ID Application: JAMF Software (483DWKW443)
/Library/Application Support/JAMF/tmp/jamfDeveloper ID Application: JAMF Software (483DWKW443)