Skip to content
Threat Feed

Vendor

Philandro Software GmbH

4 briefs RSS
medium advisory

First Time Seen Remote Monitoring and Management Tool Detection

Adversaries are leveraging legitimate Remote Monitoring and Management (RMM) and remote access tools on Windows endpoints for command-and-control, persistence, and execution, with detection focusing on the first observed instance of these tools on a host.

AA +132 command-and-control persistence execution rmm remote-access windows
1r 3t 5i
high advisory

Process Created with an Elevated Token via Token Theft

This rule detects the creation of a process running as SYSTEM while impersonating the token context of a Windows core binary, which adversaries may leverage to escalate privileges and bypass access controls through token theft.

privilege-escalation token-theft windows
2r 1t
high advisory

Privilege Elevation via Parent Process PID Spoofing

This rule detects parent process spoofing used to create an elevated child process, specifically targeting privilege escalation to SYSTEM, where adversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or to elevate privileges on Windows systems.

Elastic Endpoint +2 privilege-escalation windows ppid-spoofing
2r 1t
medium advisory

First Time Seen Remote Monitoring and Management Tool Execution

Detects the execution of previously unseen remote monitoring and management (RMM) tools or remote access software on compromised Windows endpoints, often leveraged for command-and-control, persistence, and execution of malicious commands.

Elastic Defend +101 remote-access rmm command-and-control persistence
3r