{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/remote-monitoring-management/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["command-and-control","persistence","remote-monitoring-management"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eAdversaries frequently employ legitimate remote access software (RATs) such as AnyDesk, GoToMyPC, LogMeIn, and TeamViewer to maintain unauthorized access to compromised endpoints. By leveraging these tools, attackers can bypass traditional perimeter controls, as the traffic often blends with legitimate administrative activity. The deployment of these utilities usually occurs after initial access is achieved, serving as a secondary persistent backdoor or a mechanism for interactive operator control.\u003c/p\u003e\n\u003cp\u003eThis detection focuses on identifying the filesystem-level arrival of these tools, specifically monitoring for executables, installers, and scripts identified via a managed lookup table of known remote access utilities. Because these tools are often utilized by legitimate administrators, the detection requires careful tuning via exception lists to avoid noise. The presence of these files is a high-fidelity indicator that requires immediate investigation to determine if the deployment was authorized by internal IT or performed by an unauthorized third party.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial access is gained through phishing, exploitation of a public-facing application, or compromised credentials.\u003c/li\u003e\n\u003cli\u003eThe attacker performs initial reconnaissance to identify system architecture and installed security software.\u003c/li\u003e\n\u003cli\u003eThe attacker downloads or drops the remote access utility installer (e.g., .exe, .msi, or .pkg) to a temporary directory.\u003c/li\u003e\n\u003cli\u003eThe installer is executed to register the remote access service, creating persistent registry keys or startup entries.\u003c/li\u003e\n\u003cli\u003eThe remote access agent initiates an outbound connection to the vendor's command-and-control infrastructure.\u003c/li\u003e\n\u003cli\u003eThe attacker uses the persistent remote access session to conduct lateral movement and harvest credentials.\u003c/li\u003e\n\u003cli\u003eFinal objectives, such as data exfiltration or ransomware deployment, are executed via the established remote session.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful deployment of unauthorized remote access software grants an attacker persistent, interactive control over the affected system. This facilitates long-term presence, bypass of network segmentation, and the ability to exfiltrate sensitive data or deploy further payloads, often resulting in widespread environment compromise and significant operational disruption.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eDeploy file-creation monitoring (Sysmon Event ID 11 or equivalent EDR telemetry) focusing on paths associated with user-writeable directories.\u003c/li\u003e\n\u003cli\u003eMaintain a centralized, organizational list of authorized remote access utilities to act as an allowlist against the \u003ccode\u003eremote_access_software\u003c/code\u003e lookup.\u003c/li\u003e\n\u003cli\u003eAudit the current \u003ccode\u003eremote_access_software_usage_exceptions\u003c/code\u003e list to ensure all legitimate administrative tools are properly excluded.\u003c/li\u003e\n\u003cli\u003eUse the provided Splunk analytic to monitor for unauthorized arrivals of new binaries from the identified remote utility categories.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-05T12:09:45Z","date_published":"2026-10-05T12:09:45Z","id":"https://feed.craftedsignal.io/briefs/2026-10-remote-access-software/","summary":"This detection monitors for the creation of files associated with known remote access utilities, which adversaries frequently deploy to establish C2 channels and persistent access.","title":"Detection of Unauthorized Remote Access Software Usage","url":"https://feed.craftedsignal.io/briefs/2026-10-remote-access-software/"}],"language":"en","title":"CraftedSignal Threat Feed - Remote-Monitoring-Management","version":"https://jsonfeed.org/version/1.1"}