Project case study

CIS Mini RMM.

An independent build that connects endpoint administration with application and infrastructure engineering. This page records the technical work in more detail.

Independent technical project

CIS Mini RMM

A private endpoint-management project used to develop and demonstrate skills across Windows services, APIs, databases, networking, and secure updates.

Product engineeringEndpoint operationsSecurity architecture
01/ 04
01

Enroll

One-time, high-entropy tokens are hashed at rest and expire when redeemed. Devices receive their own ID and secret.

02

Report

A Windows service phones home with heartbeats and version information through a restricted nginx gateway.

03

Recover

A separate Auditor watches the Agent and can restart it with retry and backoff behavior.

04

Update

Maintenance tooling checks signed release artifacts before replacing the installed Agent.

Platform architecture

A small distributed system.

The diagram shows the reported working components, not a public demo environment.

ENDPOINT
◈ AgentWindows service · heartbeats · actions
⌁ AuditorWatchdog · recovery · maintenance
EDGE
◉ CloudflarePublic entry
⇄ nginx gatewayAgent routes only
CONTROL PLANE
⌘ ASP.NET CoreDevice and organization API
▤ PostgreSQLRecords · migrations · releases
OPERATOR
▦ Web interfaceHealth · devices · versions

Security by design

Trust is a workflow.

Key decisions in the build include single-use enrollment, device identities, a dedicated agent gateway, outbound endpoint communication, and RSA-signed software releases. Self-update has been tested end to end with the new version reported back by the API.

One-time tokenSigned releaseRoute isolationOutbound agent
DESIGNED / IN PROGRESS

Device lifecycle and remote control

The planned lifecycle covers pending, approved, active, suspended, rejected, decommissioned, and archived states. Tokenless bootstrap keeps unknown devices quarantined until approval. Browser-based remote desktop and per-user remote-control authorization remain design work.

Remote terminal execution is currently in the SYSTEM context; interactive-user execution is being examined.

Release engineering

Update the endpoint with evidence.

The release flow is designed to verify both package integrity and publisher authenticity before installation.

01 / BUILDAgent packageCompile and archive
02 / RECORDManifest + hashVersion and metadata
03 / SIGNRSA signaturePublisher verification
04 / STAGERelease catalogueDownload location and notes
05 / VERIFYMaintenance appReject invalid releases

A self-update test replaced an installed Agent and the API subsequently reported the new version.

Back to the résumé

See this project alongside my professional work.

Selected projects ↗