Remote Access Tool - Ammy Admin Agent Execution
Detects the execution of the Ammy Admin RMM agent for remote management.
Detection logic
selection
Image|endswith: \rundll32.exe
CommandLine|contains: AMMYY\aa_nts.dll",runCondition
selectionRaw YAML
title: Remote Access Tool - Ammy Admin Agent Execution
id: 7da7809e-f3d5-47a3-9d5d-fc9d019caf14
status: test
description: Detects the execution of the Ammy Admin RMM agent for remote management.
references:
- https://www.ammyy.com/en/admin_features.html
author: '@kostastsale'
date: 2024-08-05
tags:
- attack.execution
- attack.persistence
- detection.threat-hunting
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith: '\rundll32.exe'
CommandLine|contains: 'AMMYY\aa_nts.dll",run'
condition: selection
falsepositives:
- Legitimate use of Ammy Admin RMM agent for remote management by admins.
level: mediumFalse positives
- Legitimate use of Ammy Admin RMM agent for remote management by admins.
References
Similar rules
Remote Access Tool - Cmd.EXE Execution via AnyViewer
mediumwindows · Same logsource category (process_creation)
Scheduled Task Creation From Potential Suspicious Parent Location
mediumwindows · Same logsource category (process_creation)
Abuse of Service Permissions to Hide Services Via Set-Service
highwindows · Same logsource category (process_creation)
APT27 - Emissary Panda Activity
criticalwindows · Same logsource category (process_creation)