Detection of Unauthorized Remote Access Software Usage
This detection monitors for the creation of files associated with known remote access utilities, which adversaries frequently deploy to establish C2 channels and persistent access.
Adversaries frequently employ legitimate remote access software (RATs) such as AnyDesk, GoToMyPC, LogMeIn, and TeamViewer to maintain unauthorized access to compromised endpoints. By leveraging these tools, attackers can bypass traditional perimeter controls, as the traffic often blends with legitimate administrative activity. The deployment of these utilities usually occurs after initial access is achieved, serving as a secondary persistent backdoor or a mechanism for interactive operator control.
This detection focuses on identifying the filesystem-level arrival of these tools, specifically monitoring for executables, installers, and scripts identified via a managed lookup table of known remote access utilities. Because these tools are often utilized by legitimate administrators, the detection requires careful tuning via exception lists to avoid noise. The presence of these files is a high-fidelity indicator that requires immediate investigation to determine if the deployment was authorized by internal IT or performed by an unauthorized third party.
Attack Chain
- Initial access is gained through phishing, exploitation of a public-facing application, or compromised credentials.
- The attacker performs initial reconnaissance to identify system architecture and installed security software.
- The attacker downloads or drops the remote access utility installer (e.g., .exe, .msi, or .pkg) to a temporary directory.
- The installer is executed to register the remote access service, creating persistent registry keys or startup entries.
- The remote access agent initiates an outbound connection to the vendor's command-and-control infrastructure.
- The attacker uses the persistent remote access session to conduct lateral movement and harvest credentials.
- Final objectives, such as data exfiltration or ransomware deployment, are executed via the established remote session.
Impact
Successful deployment of unauthorized remote access software grants an attacker persistent, interactive control over the affected system. This facilitates long-term presence, bypass of network segmentation, and the ability to exfiltrate sensitive data or deploy further payloads, often resulting in widespread environment compromise and significant operational disruption.
Recommendation
- Deploy file-creation monitoring (Sysmon Event ID 11 or equivalent EDR telemetry) focusing on paths associated with user-writeable directories.
- Maintain a centralized, organizational list of authorized remote access utilities to act as an allowlist against the
remote_access_softwarelookup. - Audit the current
remote_access_software_usage_exceptionslist to ensure all legitimate administrative tools are properly excluded. - Use the provided Splunk analytic to monitor for unauthorized arrivals of new binaries from the identified remote utility categories.
Immediate actions
Review and update the remote_access_software lookup table to include current approved utilities.
Threat Hunt
Search for unknown binaries in temp directories with file names matching known remote access tools.
Data: Sysmon Event ID 11
Mitigations
Implement strict application control or allowlisting for remote access software.
T1219
Detection coverage 1
Detect Remote Access Software Installation
mediumDetects the creation of files on disk identified as belonging to known remote access software utilities.
Detection queries are available on the platform. Get full rules →