<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>T1219.002 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/t1219.002/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 03 Sep 2026 13:36:42 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/t1219.002/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Detection of Non-Browser DNS Queries to Remote Access Software Domains</title><link>https://feed.craftedsignal.io/briefs/2026-09-dns-query-remote-access/</link><pubDate>Thu, 03 Sep 2026 13:36:42 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-dns-query-remote-access/</guid><description>Adversaries frequently leverage legitimate remote access and support software to establish command and control channels; detecting these tools via DNS queries from non-browser processes provides visibility into potential unauthorized remote access.</description><content:encoded><![CDATA[<p>Adversaries often use legitimate desktop support and remote access tools to establish interactive command and control (C2) channels. These tools are frequently whitelisted by application control policies due to their role in technical support operations. By monitoring DNS queries directed at these specific domains from processes other than authorized web browsers, defenders can identify suspicious execution of Remote Monitoring and Management (RMM) or remote access utilities. This telemetry is critical for identifying unauthorized persistence and lateral movement attempts by threat groups, such as Scattered Spider, which have been observed utilizing various RMM solutions to maintain access.</p>
<h2 id="impact">Impact</h2>
<p>Successful deployment of unauthorized remote access software allows attackers to perform interactive operations, exfiltrate sensitive data, and bypass traditional security controls that trust signed support tools. This activity is a common precursor to ransomware deployment and large-scale data breaches in enterprise environments.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Deploy the provided Sigma rule to detect DNS queries to RMM domains from non-browser applications.</p>
<ul>
<li>Baseline your organization's authorized remote access tools and tune the rule to allowlist sanctioned versions.</li>
<li>Integrate these findings into your incident response process to verify if the initiated connection was requested by an authorized administrator.</li>
<li>Review and monitor internal outbound DNS traffic for these specific domains.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>command-and-control</category><category>t1219.002</category></item></channel></rss>