Product
low
advisory
Detection of RMM Software Deployment via Internet-Originated MSI Files
1 TTPThis detection identifies the download and execution of Windows Installer (MSI) packages from the internet that result in the installation of remote monitoring and management (RMM) software used for persistent system access.
Acronis Cyber Protect Connect +43
defense-evasion
command-and-control
windows
rmm
1t
medium
advisory
First Time Seen Remote Monitoring and Management Tool Detection
1 rule 3 TTPs 5 IOCsAdversaries are leveraging legitimate Remote Monitoring and Management (RMM) and remote access tools on Windows endpoints for command-and-control, persistence, and execution, with detection focusing on the first observed instance of these tools on a host.
AA +132
command-and-control
persistence
execution
rmm
remote-access
windows
1r
3t
5i
high
advisory
Komari Agent Abused as SYSTEM-Level Backdoor
2 rules 4 TTPs 2 IOCsThreat actors are abusing the Komari monitoring agent, a project hosted on GitHub, as a SYSTEM-level backdoor following initial access through compromised VPN credentials and lateral movement via Impacket.
Defender +2
komari
backdoor
nssm
github
rat
reverse shell
2r
4t
2i