{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/dwsnet/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["RMM Software"],"_cs_severities":["medium"],"_cs_tags":["rmm","command-and-control","windows","endpoint-detection"],"_cs_type":"advisory","_cs_vendors":["Action1","Aeroadmin","AmidaWare","Ammyy","AnyDesk Software","AOMEI","Atera Networks","AWERAY","BeamYourScreen","Bomgar","BreakingSecurity","ConnectWise","Devolutions","DOMOTZ","DUC FABULOUS","DWSNET","Electronic Team","Famatech","FleetDeck","GlavSoft","GoTo Technologies","Hefei Pingbo Network Technology","IDrive","Impero Solutions","Instant Housecall","ISL Online","JumpCloud","Level Software","LogMeIn","LUNIXAR","MMSOFT Design","N-ABLE","Nanosystems","NetSupport","NinjaOne","Parallels International","philandro Software","Pro Softnet","RealVNC","REMOTE UTILITIES","Rocket Software","Rsupport","Servably","ShowMyPC","SimpleHelp","Splashtop","Superops","Tailscale","TeamViewer","Techinline","uvnc","ZOHO"],"content_html":"\u003cp\u003eThreat actors frequently abuse legitimate Remote Monitoring and Management (RMM) tools to gain unauthorized remote access, maintain persistence, and deploy secondary malware. By utilizing signed, legitimate administrative software, attackers often evade signature-based security controls and blend in with authorized IT management activity.\u003c/p\u003e\n\u003cp\u003eThe provided detection logic identifies the first-time execution of processes associated with a curated list of RMM vendor code-signing certificates across an Elastic Defend-monitored Windows fleet. Because many of these vendors also produce non-remote-access software, the appearance of a new signer does not inherently indicate malicious activity. Defenders must investigate the parent process context, network activity, and child process execution to distinguish between authorized administrative deployments and the initial staging phase of a compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful abuse of RMM tools can provide an attacker with interactive control over a victim machine, enabling data exfiltration, lateral movement, and the deployment of ransomware. Because RMM software is designed for high-privilege access and visibility, compromise of these tools can result in widespread enterprise impact, potentially affecting an entire network if the RMM infrastructure is leveraged for domain-wide administrative operations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDetection engineering teams should implement the following actions to monitor for unauthorized RMM usage:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule (or equivalent EDR query) to identify the first execution of binaries signed by known RMM vendor certificates.\u003c/li\u003e\n\u003cli\u003eEstablish a baseline of authorized RMM software currently used within the environment to filter out legitimate administrative tools from alerts.\u003c/li\u003e\n\u003cli\u003eEnable process-creation logging and cross-reference process execution with known change management and software rollout schedules.\u003c/li\u003e\n\u003cli\u003eAudit network egress traffic originating from RMM binary processes to identify connections to unauthorized or anomalous command-and-control infrastructure.\u003c/li\u003e\n\u003cli\u003eReview child process activity for administrative tools; focus on unauthorized use of shells (cmd.exe, powershell.exe) or discovery utilities (net.exe, nltest.exe) spawned by RMM agents.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T01:56:30Z","date_published":"2026-08-05T01:56:30Z","id":"https://feed.craftedsignal.io/briefs/2026-08-rmm-signer-detection/","summary":"This brief details a detection strategy for identifying the introduction of remote monitoring and management (RMM) software in Windows environments by monitoring for newly observed code-signing certificates.","title":"Detection of Novel RMM Software Usage","url":"https://feed.craftedsignal.io/briefs/2026-08-rmm-signer-detection/"}],"language":"en","title":"CraftedSignal Threat Feed - DWSNET","version":"https://jsonfeed.org/version/1.1"}