Skip to content
Threat Feed
medium advisory

Detection of Unauthorized Remote Access Software Persistence

This detection monitors for the configuration of known remote access utilities within Windows registry persistence locations to identify potential adversary activity aimed at maintaining long-term control.

Adversaries and unauthorized users frequently leverage legitimate remote access software (RAS) to maintain persistent, remote control over compromised systems within an enterprise environment. By modifying Windows registry keys associated with automatic startup, such as "Run" keys or Service "ImagePath" values, actors ensure these utilities execute upon system reboot or user login.

This analytic identifies the unauthorized configuration of such software - including tools like AnyDesk, GoToMyPC, LogMeIn, and TeamViewer - by monitoring Sysmon Event ID 13 registry modifications. Defenders should maintain a robust allowlist of approved enterprise remote administration tools, as these utilities are dual-use and commonly employed by both IT administrators and malicious actors for persistence (MITRE ATT&CK T1219). This approach allows SOC teams to filter out expected administrative behavior while focusing investigations on unauthorized or unexpected remote access software deployments.

Impact

Successful deployment of unauthorized remote access software allows attackers to bypass traditional network perimeter defenses, exfiltrate sensitive data, and execute further stages of an attack chain. This technique is frequently associated with ransomware operators and secondary infection chains, such as those observed in Gozi, Emotet, and Bumblebee campaigns. Failure to monitor for these persistence mechanisms increases the risk of long-term undetected access and eventual catastrophic business impact from ransomware or data theft.

Recommendation

  • Enable Sysmon Event ID 13 logging to capture registry modification events across all endpoints.
  • Implement the suggested registry-monitoring Sigma rule to trigger alerts when remote access utilities are added to Windows startup paths.
  • Utilize the "remote_access_software_usage_exceptions" lookup mechanism to maintain an enterprise-wide allowlist of authorized administrative tools, reducing noise for the security operations center.
  • Prioritize investigations where a remote access utility is detected on high-value targets (e.g., domain controllers, build servers, or sensitive workstations) as these often represent deliberate persistence efforts by an adversary.

Immediate actions

Deploy registry-monitoring detection rule.

Detection Engineering 72h

Mitigations

Establish and maintain a centralized allowlist for remote administrative tools.

medium_term IT Operations

Detection coverage 1

Detect Remote Access Software Persistence via Registry

medium

Detects when known remote access software is configured to persist by adding an entry to Windows Run keys or creating/modifying system services.

sigma tactics: persistence techniques: T1219 sources: registry_set, windows

Detection queries are available on the platform. Get full rules →