MITRE ATT&CK technique
Remote Access Tools detection rulesT1219
Remote Access Tools (T1219) is a MITRE ATT&CK technique in the Command and Control tactic. This page lists the 52 community-maintained Sigma detection rules in the library mapped to T1219 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, macos, linux.
Tactic
Antivirus - APT Malware Signature
criticalDetects a highly relevant Antivirus alert that reports APT malware. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
antivirus
Antivirus - Exploitation Framework Signature
criticalDetects a highly relevant Antivirus alert that reports an exploitation framework. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
antivirus
Antivirus - Remote Access Tools Signature
criticalDetects a highly relevant Antivirus alert that reports a remote access tool. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
antivirus
HackTool - Inveigh Execution Artefacts
criticalDetects the presence and execution of Inveigh via dropped artefacts
windows · file_event
Atera Agent Installation
highDetects successful installation of Atera Remote Monitoring & Management (RMM) agent as recently found to be used by Conti operators
windows
HackTool - RemoteKrbRelay SMB Relay Secrets Dump Module Indicators
highDetects the creation of file with specific names used by RemoteKrbRelay SMB Relay attack module.
windows · file_event
Hijack Legit RDP Session to Move Laterally
highDetects the usage of tsclient share to place a backdoor on the RDP source machine's startup folder
windows · file_event
Potential CSharp Streamer RAT Loading .NET Executable Image
highDetects potential CSharp Streamer RAT loading .NET executable image by using the default file name and path associated with the tool.
windows · image_load
Potential SocGholish Second Stage C2 DNS Query
highDetects a DNS query initiated from a "wscript" process for domains matching a specific pattern that was seen being used by SocGholish for its Command and Control traffic
windows · dns_query
Remote Access Tool - Anydesk Execution From Suspicious Folder
highAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · process_creation
Remote Access Tool - AnyDesk Silent Installation
highDetects AnyDesk Remote Desktop silent installation. Which can be used by attackers to gain remote access.
windows · process_creation
Remote Access Tool - Renamed MeshAgent Execution - MacOS
highDetects the execution of a renamed instance of the Remote Monitoring and Management (RMM) tool, MeshAgent. RMM tools such as MeshAgent are commonly utilized by IT administrators for legitimate remote support and system management. However, malicious actors may exploit these tools by renaming them to bypass detection mechanisms, enabling unauthorized access and control over compromised systems.
macos · process_creation
Remote Access Tool - Renamed MeshAgent Execution - Windows
highDetects the execution of a renamed instance of the Remote Monitoring and Management (RMM) tool, MeshAgent. RMM tools such as MeshAgent are commonly utilized by IT administrators for legitimate remote support and system management. However, malicious actors may exploit these tools by renaming them to bypass detection mechanisms, enabling unauthorized access and control over compromised systems.
windows · process_creation
Renamed Visual Studio Code Tunnel Execution
highDetects renamed Visual Studio Code tunnel execution. Attackers can abuse this functionality to establish a C2 channel
windows · process_creation
Suspicious Binary Writes Via AnyDesk
highDetects AnyDesk writing binary files to disk other than "gcapi.dll". According to RedCanary research it is highly abnormal for AnyDesk to write executable files to disk besides gcapi.dll, which is a legitimate DLL that is part of the Google Chrome web browser used to interact with the Google Cloud API. (See reference section for more details)
windows · file_event
Suspicious Mstsc.EXE Execution With Local RDP File
highDetects potential RDP connection via Mstsc using a local ".rdp" file located in suspicious locations.
windows · process_creation
Suspicious TSCON Start as SYSTEM
highDetects a tscon.exe start as LOCAL SYSTEM
windows · process_creation
Suspicious Velociraptor Child Process
highDetects the suspicious use of the Velociraptor DFIR tool to execute other tools or download additional payloads, as seen in a campaign where it was abused for remote access and to stage further attacks.
windows · process_creation
Anydesk Temporary Artefact
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · file_event
DNS Query To AzureWebsites.NET By Non-Browser Process
mediumDetects a DNS query by a non browser process on the system to "azurewebsites.net". The latter was often used by threat actors as a malware hosting and exfiltration site.
windows · dns_query
DNS Query To Remote Access Software Domain From Non-Browser App
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · dns_query
GoToAssist Temporary Installation Artefact
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · file_event
Installation of TeamViewer Desktop
mediumTeamViewer_Desktop.exe is create during install
windows · file_event
Mesh Agent Service Installation
mediumDetects a Mesh Agent service installation. Mesh Agent is used to remotely manage computers
windows
OpenEDR Spawning Command Shell
mediumDetects the OpenEDR ssh-shellhost.exe spawning a command shell (cmd.exe) or PowerShell with PTY (pseudo-terminal) capabilities. This may indicate remote command execution through OpenEDR's remote management features, which could be legitimate administrative activity or potential abuse of the remote access tool. Threat actors may leverage OpenEDR's remote shell capabilities to execute commands on compromised systems, facilitating lateral movement or other command-and-control operations.
windows · process_creation
Potential Amazon SSM Agent Hijacking
mediumDetects potential Amazon SSM agent hijack attempts as outlined in the Mitiga research report.
windows · process_creation
Potential Linux Amazon SSM Agent Hijacking
mediumDetects potential Amazon SSM agent hijack attempts as outlined in the Mitiga research report.
linux · process_creation
Potential Remote Desktop Connection to Non-Domain Host
mediumDetects logons using NTLM to hosts that are potentially not part of the domain.
windows
Potentially Suspicious File Creation by OpenEDR's ITSMService
mediumDetects the creation of potentially suspicious files by OpenEDR's ITSMService process. The ITSMService is responsible for remote management operations and can create files on the system through the Process Explorer or file management features. While legitimate for IT operations, creation of executable or script files could indicate unauthorized file uploads, data staging, or malicious file deployment.
windows · file_event
Remote Access Tool - Action1 Arbitrary Code Execution and Remote Sessions
mediumDetects the execution of Action1 in order to execute arbitrary code or establish a remote session. Action1 is a powerful Remote Monitoring and Management tool that enables users to execute commands, scripts, and binaries. Through the web interface of action1, the administrator must create a new policy or an app to establish remote execution and then points that the agent is installed. Hunting Opportunity 1- Weed Out The Noise When threat actors execute a script, a command, or a binary through these new policies and apps, the names of these become visible in the command line during the execution process. Below is an example of the command line that contains the deployment of a binary through a policy with name "test_app_1": ParentCommandLine: "C:\WINDOWS\Action1\action1_agent.exe schedule:Deploy_App__test_app_1_1681327673425 runaction:0" After establishing a baseline, we can split the command to extract the policy name and group all the policy names and inspect the results with a list of frequency occurrences. Hunting Opportunity 2 - Remote Sessions On Out Of Office Hours If you have admins within your environment using remote sessions to administer endpoints, you can create a threat-hunting query and modify the time of the initiated sessions looking for abnormal activity.
windows · process_creation
Remote Access Tool - AnyDesk Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · process_creation
Remote Access Tool - AnyDesk Incoming Connection
mediumDetects incoming connections to AnyDesk. This could indicate a potential remote attacker trying to connect to a listening instance of AnyDesk and use it as potential command and control channel.
windows · network_connection
Remote Access Tool - AnyDesk Piped Password Via CLI
mediumDetects piping the password to an anydesk instance via CMD and the '--set-password' flag.
windows · process_creation
Remote Access Tool - GoToAssist Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · process_creation
Remote Access Tool - LogMeIn Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · process_creation
Remote Access Tool - MeshAgent Command Execution via MeshCentral
mediumDetects the use of MeshAgent to execute commands on the target host, particularly when threat actors might abuse it to execute commands directly. MeshAgent can execute commands on the target host by leveraging win-console to obscure their activities and win-dispatcher to run malicious code through IPC with child processes.
windows · process_creation
Remote Access Tool - NetSupport Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · process_creation
Remote Access Tool - Potential MeshAgent Execution - MacOS
mediumDetects potential execution of MeshAgent which is a tool used for remote access. Historical data shows that threat actors rename MeshAgent binary to evade detection. Matching command lines with the '--meshServiceName' argument can indicate that the MeshAgent is being used for remote access.
macos · process_creation
Remote Access Tool - Potential MeshAgent Execution - Windows
mediumDetects potential execution of MeshAgent which is a tool used for remote access. Historical data shows that threat actors rename MeshAgent binary to evade detection. Matching command lines with the '--meshServiceName' argument can indicate that the MeshAgent is being used for remote access.
windows · process_creation
Remote Access Tool - ScreenConnect Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · process_creation
Remote Access Tool - ScreenConnect Potential Suspicious Remote Command Execution
mediumDetects potentially suspicious child processes launched via the ScreenConnect client service.
windows · process_creation
Remote Access Tool - Simple Help Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · process_creation
Remote Access Tool - TacticalRMM Agent Registration to Potentially Attacker-Controlled Server
mediumDetects TacticalRMM agent installations where the --api, --auth, and related flags are used on the command line. These parameters configure the agent to connect to a specific RMM server with authentication, client ID, and site ID. This technique could indicate a threat actor attempting to register the agent with an attacker-controlled RMM infrastructure silently.
windows · process_creation
Remote Access Tool - UltraViewer Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · process_creation
ScreenConnect Temporary Installation Artefact
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · file_event
TacticalRMM Service Installation
mediumDetects a TacticalRMM service installation. Tactical RMM is a remote monitoring & management tool.
windows
TeamViewer Domain Query By Non-TeamViewer Application
mediumDetects DNS queries to a TeamViewer domain only resolved by a TeamViewer client by an image that isn't named TeamViewer (sometimes used by threat actors for obfuscation)
windows · dns_query
TeamViewer Remote Session
mediumDetects the creation of log files during a TeamViewer remote session
windows · file_event
Use of UltraVNC Remote Access Software
mediumAn adversary may use legitimate desktop support and remote access software,to establish an interactive command and control channel to target systems within networks
windows · process_creation
Visual Studio Code Tunnel Execution
mediumDetects Visual Studio Code tunnel execution. Attackers can abuse this functionality to establish a C2 channel
windows · process_creation
Mstsc.EXE Execution With Local RDP File
lowDetects potential RDP connection via Mstsc using a local ".rdp" file
windows · process_creation
QuickAssist Execution
lowDetects the execution of Microsoft Quick Assist tool "QuickAssist.exe". This utility can be used by attackers to gain remote access.
windows · process_creation