Vendor
low
advisory
Detection of RMM Software Deployment via Internet-Originated MSI Files
1 TTPThis detection identifies the download and execution of Windows Installer (MSI) packages from the internet that result in the installation of remote monitoring and management (RMM) software used for persistent system access.
Acronis Cyber Protect Connect +43
defense-evasion
command-and-control
windows
rmm
1t
high
advisory
CSRF Vulnerability in Komari Management Interface
1 rule 2 TTPsThe Komari management interface lacks CSRF protections and secure cookie attributes, allowing an attacker to perform unauthorized administrative actions including arbitrary code execution.
komari
web-application-security
csrf
session-management
1r
2t
medium
advisory
Suspicious Activity: Multiple Remote Management Tool Vendors on Same Host
1 TTPThis brief describes a behavioral detection for Windows hosts where two or more distinct remote monitoring and management (RMM) or remote-access tools from different vendors are observed starting processes within an eight-minute window, indicating potential compromise, shadow IT, or attacker staging of redundant access.
Acronis Cyber Protect Connect +49
command-and-control
remote-access-software
rmm
windows
behavioral-detection
1t