Skip to content
Threat Feed

Vendor

Remote Utilities

4 briefs RSS
medium advisory

Detection of Novel RMM Software Usage

This brief details a detection strategy for identifying the introduction of remote monitoring and management (RMM) software in Windows environments by monitoring for newly observed code-signing certificates.

RMM Software rmm command-and-control windows endpoint-detection
1r 1t
medium advisory

Suspicious DNS Queries to Remote Monitoring and Management Domains from Non-Browser Processes

This brief details the detection of DNS queries targeting commonly abused Remote Monitoring and Management (RMM) or remote access software domains, originating from non-browser processes, which is a common tactic for command and control, persistence, and lateral movement by threat actors.

01com +151 windows command-and-control endpoint rmm remote-access
1r 193i
medium advisory

Suspicious Activity: Multiple Remote Management Tool Vendors on Same Host

This brief describes a behavioral detection for Windows hosts where two or more distinct remote monitoring and management (RMM) or remote-access tools from different vendors are observed starting processes within an eight-minute window, indicating potential compromise, shadow IT, or attacker staging of redundant access.

Acronis Cyber Protect Connect +49 command-and-control remote-access-software rmm windows behavioral-detection
1t
medium advisory

Detection of Windows RMM Tool Execution

Detects process creation events indicative of remote management tools, potentially signifying legitimate use or malicious exploitation by threat actors abusing RMM software.

AnyDesk +28 rmm remote-access sysmon
3r 1t