Vendor
medium
advisory
Suspicious DNS Queries to Remote Monitoring and Management Domains from Non-Browser Processes
1 rule 193 IOCsThis brief details the detection of DNS queries targeting commonly abused Remote Monitoring and Management (RMM) or remote access software domains, originating from non-browser processes, which is a common tactic for command and control, persistence, and lateral movement by threat actors.
01com +151
windows
command-and-control
endpoint
rmm
remote-access
1r
193i
medium
advisory
Remote Management Access Launch After MSI Install
2 rulesDetects a suspicious sequence of an MSI installer execution immediately followed by the execution of commonly abused Remote Management Software, potentially indicating unauthorized remote access.
ScreenConnect +3
remote-access
command-and-control
rmm
msi
2r
medium
advisory
Suspicious DNS Queries to RMM Domains from Non-Browser Processes
2 rulesDetection of DNS queries to remote monitoring and management (RMM) domains from non-browser processes indicating potential misuse of legitimate remote access tools for command and control.
Elastic Endpoint +1
command-and-control
remote-access
windows
2r