{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/t1219.002/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["command-and-control","t1219.002"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eAdversaries often use legitimate desktop support and remote access tools to establish interactive command and control (C2) channels. These tools are frequently whitelisted by application control policies due to their role in technical support operations. By monitoring DNS queries directed at these specific domains from processes other than authorized web browsers, defenders can identify suspicious execution of Remote Monitoring and Management (RMM) or remote access utilities. This telemetry is critical for identifying unauthorized persistence and lateral movement attempts by threat groups, such as Scattered Spider, which have been observed utilizing various RMM solutions to maintain access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful deployment of unauthorized remote access software allows attackers to perform interactive operations, exfiltrate sensitive data, and bypass traditional security controls that trust signed support tools. This activity is a common precursor to ransomware deployment and large-scale data breaches in enterprise environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDeploy the provided Sigma rule to detect DNS queries to RMM domains from non-browser applications.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eBaseline your organization's authorized remote access tools and tune the rule to allowlist sanctioned versions.\u003c/li\u003e\n\u003cli\u003eIntegrate these findings into your incident response process to verify if the initiated connection was requested by an authorized administrator.\u003c/li\u003e\n\u003cli\u003eReview and monitor internal outbound DNS traffic for these specific domains.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T13:36:42Z","date_published":"2026-09-03T13:36:42Z","id":"https://feed.craftedsignal.io/briefs/2026-09-dns-query-remote-access/","summary":"Adversaries frequently leverage legitimate remote access and support software to establish command and control channels; detecting these tools via DNS queries from non-browser processes provides visibility into potential unauthorized remote access.","title":"Detection of Non-Browser DNS Queries to Remote Access Software Domains","url":"https://feed.craftedsignal.io/briefs/2026-09-dns-query-remote-access/"}],"language":"en","title":"CraftedSignal Threat Feed - T1219.002","version":"https://jsonfeed.org/version/1.1"}