DEV Community

Cover image for We built a free connection manager that opens SSH, RDP, WinRM and a Mac's High Performance screen in one window
Gia Bursulaia
Gia Bursulaia

Posted on Fully Autonomous

We built a free connection manager that opens SSH, RDP, WinRM and a Mac's High Performance screen in one window

A typical working day for the people we build for looks like this: PuTTY or a terminal for Linux boxes, mstsc for Windows servers, Screen Sharing for the Macs, WinSCP for files, a password manager in another window, and a text file of jump-host commands copied from every morning.

The tools that put all of this in one place are good, but they are either Windows-only or they charge per user: MobaXterm is $69 per user, Termius is $10 per user per month, SecureCRT is $119. For a small team that adds up quickly, and none of them could open a Mac the way macOS itself does.

So we built BURSU Connection Manager (BURSUcm). It is free, it runs on Windows, macOS and Linux, and it has Android and iPhone/iPad apps that open the same catalogue. This post covers what it does and a few of the less obvious problems we had to solve along the way.

BURSUcm home dashboard

One tree, every protocol

Every connection lives in one tree of nested folders, such as Servers \ Production or Network, and opens in a tab:

  • SSH with a full interactive terminal (ANSI colours, htop, mc) and an SFTP panel docked beside it
  • RDP in an embedded tab, rendered by our own engine with H.264 graphics, remote audio and multi-monitor support
  • WinRM: PowerShell or cmd.exe on a Windows server, with no RDP session and no SSH server needed on the Windows side
  • AppleRD: a Mac's screen over Apple Remote Desktop (more on this below)
  • VNC with TLS/VeNCrypt, plus Telnet, Serial (COM), FTP/FTPS and embedded web pages

Split view puts two sessions in one tab, broadcast input types into every open session at once, and command snippets with {placeholder} prompts are synced and shared with the team.

The part we're proudest of: a Mac's screen at native quality

Most connection managers open a Mac through plain VNC. It works, but it is slow and blurry, and there is no sound.

macOS 14 on Apple silicon has a High Performance mode for Screen Sharing: H.264 or HEVC video, the Mac's system audio, and a virtual display sized to your window. Until now only Apple's own client used it. In BURSUcm an AppleRD connection takes that path, and the video is decoded on your GPU. You can choose a private virtual display, where the Mac's own screen goes dark, or mirror the real screen. HEVC 4:4:4 keeps coloured text sharp. As far as we know, no other connection manager does this.

A Mac over AppleRD in BURSUcm

A few details that took longer than expected:

  • The Mac's identity is checked before your password goes out. Its host key is remembered on first contact and verified on every later connection, the same way SSH works. If the key changes, the password is never sent.
  • Sleeping Macs wake up first. A Wake-on-LAN packet goes out before the session starts. A Mac asleep on Wi-Fi ignores broadcast frames, so the packet is addressed to the machine itself as well as to the whole network. A "Get MAC" button reads the hardware address for you, over SSH if the machine is behind a router.
  • Intel Macs got faster too. The conventional route now asks the Mac for compressed screen updates instead of raw pixels, which roughly doubled the drawing speed over Wi-Fi.

Windows servers without RDP: WinRM in a terminal tab

Opening a full RDP desktop just to restart a service gets old fast. A WinRM connection opens PowerShell (over PowerShell Remoting) or cmd.exe (over WinRS) in a normal terminal tab:

  • output streams while a command runs, and Ctrl+C stops the pipeline
  • Read-Host and -Confirm prompts wait for your answer, as in a local console
  • errors arrive as errors, with the line they happened on
  • with HTTPS, the server's certificate is trusted once and then pinned like an SSH host key

SSH features for every day

  • ProxyJump chains through bastions, for both the terminal and SFTP
  • Tunnels for each connection: local -L, remote -R and dynamic -D (SOCKS5)
  • tmux: attach to a named session, so a dropped connection picks up exactly where it left off
  • Automatic reconnect: a frozen server is noticed within seconds, the tab turns red and reconnects on its own, and forwarded ports are released so the new session can bind them again
  • Keys from the OpenSSH agent, or stored in the vault, encrypted under the master password

Credentials and teams

Passwords, SSH keys and TOTP codes live in a separate encrypted vault (AES-256-GCM with a master password, or DPAPI on Windows), and folders can inherit a default credential.

You choose where the catalogue lives:

  • Local SQLite: no account at all
  • Your own PostgreSQL server, shared by the whole team
  • BURSUcloud: optional sync across desktop and mobile. The desktop and mobile apps send only ciphertext, and your master password stays on the device.

For teams there are permissions per folder (Read, Edit, Reveal password) and desktop-only users who don't need a portal account.

An AI assistant you can switch off

The assistant sees the same terminal you do. It can explain output, investigate a failure and run routine commands. It does nothing until you add your own key (OpenAI, Gemini, Claude, DeepSeek) or point it at a local model through Ollama, LM Studio or llama.cpp.

Read-only commands may run on their own, but anything that changes the system waits for your approval. Passwords, keys and tokens are redacted before any text leaves your machine. If you don't want AI at all, one checkbox removes the feature.

Install

# Windows
winget install bursucm
Enter fullscreen mode Exit fullscreen mode
# Debian / Ubuntu: signed APT repository, see bursucm.com/download
sudo apt install bursucm
Enter fullscreen mode Exit fullscreen mode

macOS builds are signed and notarised by Apple, Windows builds are Authenticode-signed, and the Linux packages come from signed APT, DNF and Pacman repositories. The mobile apps are on Google Play and the App Store.

Moving in is one import window: your connections come over from PuTTY, WinSCP (saved passwords included), mRemoteNG, Remote Desktop Manager, Royal TS, OpenSSH config files and .rdp files.

👉 Download: bursucm.com

We'd love your feedback

BURSUcm is built by a small team, and we'd really like to hear from people who manage mixed fleets:

  • What does your current setup do that this one doesn't?
  • If you have Macs on Apple silicon, does the High Performance mode work on your network?
  • What would make you switch from MobaXterm, Termius or Royal TS?

We answer every comment.

Top comments (0)