Product
medium
advisory
Multiple Remote Management Tool Vendors on Same Host
2 rulesThis rule identifies Windows hosts where two or more distinct remote monitoring and management (RMM) or remote-access tool vendors are observed starting processes within the same eight-minute window, potentially indicating compromise, shadow IT, or attacker staging of redundant access.
AeroAdmin +60
remote-access-tool
command-and-control
rmm
windows
2r
medium
advisory
Detection of Windows RMM Tool Execution
3 rules 1 TTPDetects process creation events indicative of remote management tools, potentially signifying legitimate use or malicious exploitation by threat actors abusing RMM software.
AnyDesk +28
rmm
remote-access
sysmon
3r
1t