Project case study
CIS Mini RMM.
An independent build that connects endpoint administration with application and infrastructure engineering. This page records the technical work in more detail.
Independent technical project
CIS Mini RMM
A private endpoint-management project used to develop and demonstrate skills across Windows services, APIs, databases, networking, and secure updates.
Enroll
One-time, high-entropy tokens are hashed at rest and expire when redeemed. Devices receive their own ID and secret.
Report
A Windows service phones home with heartbeats and version information through a restricted nginx gateway.
Recover
A separate Auditor watches the Agent and can restart it with retry and backoff behavior.
Update
Maintenance tooling checks signed release artifacts before replacing the installed Agent.
Platform architecture
A small distributed system.
The diagram shows the reported working components, not a public demo environment.
Security by design
Trust is a workflow.
Key decisions in the build include single-use enrollment, device identities, a dedicated agent gateway, outbound endpoint communication, and RSA-signed software releases. Self-update has been tested end to end with the new version reported back by the API.
Device lifecycle and remote control
The planned lifecycle covers pending, approved, active, suspended, rejected, decommissioned, and archived states. Tokenless bootstrap keeps unknown devices quarantined until approval. Browser-based remote desktop and per-user remote-control authorization remain design work.
Remote terminal execution is currently in the SYSTEM context; interactive-user execution is being examined.
Release engineering
Update the endpoint with evidence.
The release flow is designed to verify both package integrity and publisher authenticity before installation.
A self-update test replaced an installed Agent and the API subsequently reported the new version.
Back to the résumé
