{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/t1219/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["command-and-control","remote-access","network-security","T1219"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eAdversaries frequently employ legitimate remote access and monitoring tools (RATs/RMMs) to maintain persistence, conduct command-and-control (C2) communication, and facilitate unauthorized data exfiltration. This threat involves the use of dual-use software - such as AnyDesk, GoToMyPC, LogMeIn, and TeamViewer - which are often indistinguishable from standard administrative traffic unless specific domain indicators are monitored. This analytic focuses on identifying network connections to domains associated with these utilities by mapping web proxy or firewall traffic to the Common Information Model (CIM) Web data model. Defensive teams must differentiate between authorized enterprise IT management activities and malicious actor usage. Success in this detection relies on maintaining a robust allowlist lookup to manage known-good business use cases, as these tools are commonly integrated into modern enterprise workflows.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial access: Adversary gains entry to a target system via phishing, exploit, or credential theft.\u003c/li\u003e\n\u003cli\u003eStaging: Attacker downloads a legitimate remote access installer or portable executable onto the compromised host.\u003c/li\u003e\n\u003cli\u003eExecution: The remote access binary is launched, establishing a connection to its vendor-hosted C2 cloud infrastructure.\u003c/li\u003e\n\u003cli\u003eC2 Established: The host registers with the attacker-controlled panel, providing a unique ID for remote interaction.\u003c/li\u003e\n\u003cli\u003ePersistence: The actor configures the software to run automatically upon system startup to maintain long-term access.\u003c/li\u003e\n\u003cli\u003eAction on Objective: The attacker uses the remote interface to browse files, exfiltrate sensitive data, or deploy additional malware like ransomware.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for complete remote control of compromised systems, enabling attackers to bypass traditional perimeter security, exfiltrate intellectual property, and deploy destructive payloads like ransomware. This technique is observed across multiple sectors and is a standard component in the toolsets of major ransomware operations and organized cybercriminal groups.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the implementation of network-based monitoring for known remote access software domains to identify unauthorized usage.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eProcess network logs (Firewall/Proxy) and map them to the Web data model using the Splunk CIM to ensure compatibility with detection logic.\u003c/li\u003e\n\u003cli\u003eImplement a lookup-based allowlist (remote_access_software_usage_exception.csv) to manage legitimate enterprise use of these tools and reduce false positives.\u003c/li\u003e\n\u003cli\u003eInvestigate any detected connections from unexpected source IPs or user accounts using the provided drilldown searches.\u003c/li\u003e\n\u003cli\u003eIntegrate Asset and Identity (A\u0026amp;I) lookups to automatically suppress alerts for known IT administration endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-05T12:35:37Z","date_published":"2026-10-05T12:35:37Z","id":"https://feed.craftedsignal.io/briefs/2026-10-remote-access-software-usage/","summary":"This detection analytic identifies unauthorized usage of remote access utilities by monitoring web traffic for connections to known domains associated with tools such as AnyDesk, GoToMyPC, LogMeIn, and TeamViewer.","title":"Detection of Unauthorized Remote Access Software via Web Traffic","url":"https://feed.craftedsignal.io/briefs/2026-10-remote-access-software-usage/"}],"language":"en","title":"CraftedSignal Threat Feed - T1219","version":"https://jsonfeed.org/version/1.1"}