<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Remote-Monitoring-Management - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/remote-monitoring-management/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 05 Oct 2026 12:09:45 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/remote-monitoring-management/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Detection of Unauthorized Remote Access Software Usage</title><link>https://feed.craftedsignal.io/briefs/2026-10-remote-access-software/</link><pubDate>Mon, 05 Oct 2026 12:09:45 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-remote-access-software/</guid><description>This detection monitors for the creation of files associated with known remote access utilities, which adversaries frequently deploy to establish C2 channels and persistent access.</description><content:encoded><![CDATA[<p>Adversaries frequently employ legitimate remote access software (RATs) such as AnyDesk, GoToMyPC, LogMeIn, and TeamViewer to maintain unauthorized access to compromised endpoints. By leveraging these tools, attackers can bypass traditional perimeter controls, as the traffic often blends with legitimate administrative activity. The deployment of these utilities usually occurs after initial access is achieved, serving as a secondary persistent backdoor or a mechanism for interactive operator control.</p>
<p>This detection focuses on identifying the filesystem-level arrival of these tools, specifically monitoring for executables, installers, and scripts identified via a managed lookup table of known remote access utilities. Because these tools are often utilized by legitimate administrators, the detection requires careful tuning via exception lists to avoid noise. The presence of these files is a high-fidelity indicator that requires immediate investigation to determine if the deployment was authorized by internal IT or performed by an unauthorized third party.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Initial access is gained through phishing, exploitation of a public-facing application, or compromised credentials.</li>
<li>The attacker performs initial reconnaissance to identify system architecture and installed security software.</li>
<li>The attacker downloads or drops the remote access utility installer (e.g., .exe, .msi, or .pkg) to a temporary directory.</li>
<li>The installer is executed to register the remote access service, creating persistent registry keys or startup entries.</li>
<li>The remote access agent initiates an outbound connection to the vendor's command-and-control infrastructure.</li>
<li>The attacker uses the persistent remote access session to conduct lateral movement and harvest credentials.</li>
<li>Final objectives, such as data exfiltration or ransomware deployment, are executed via the established remote session.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful deployment of unauthorized remote access software grants an attacker persistent, interactive control over the affected system. This facilitates long-term presence, bypass of network segmentation, and the ability to exfiltrate sensitive data or deploy further payloads, often resulting in widespread environment compromise and significant operational disruption.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Deploy file-creation monitoring (Sysmon Event ID 11 or equivalent EDR telemetry) focusing on paths associated with user-writeable directories.</li>
<li>Maintain a centralized, organizational list of authorized remote access utilities to act as an allowlist against the <code>remote_access_software</code> lookup.</li>
<li>Audit the current <code>remote_access_software_usage_exceptions</code> list to ensure all legitimate administrative tools are properly excluded.</li>
<li>Use the provided Splunk analytic to monitor for unauthorized arrivals of new binaries from the identified remote utility categories.</li>
</ol>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>command-and-control</category><category>persistence</category><category>remote-monitoring-management</category></item></channel></rss>