Techniques › T1219.002 › AN0714
AN0714 Analytic 0714
Windows · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Adversary installation or use of RMM software (e.g., TeamViewer, AnyDesk, ScreenConnect) followed by outbound beaconing or remote session establishment</p>
- Detects
- T1219.002 Remote Desktop Software
- Part of
- DET0259 Remote Desktop Software Execution and Beaconing Detection
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| WinEventLog:Sysmon | EventCode=11 | DC0039 File Creation |
| WinEventLog:Sysmon | EventCode=3, 22 | DC0082 Network Connection Creation |
| WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall | new rule allowing inbound or outbound connections for remote desktop software | DC0051 Firewall Rule Modification |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
Image | RMM software can vary; defenders should update rules to account for additional binaries (e.g., ConnectWise, Zoho Assist) |
DestinationPort | RMM software may use configurable or random high ports outside of standard (e.g., 7070, 5650) |
ParentImage | Expected parent process may vary in different enterprise contexts |
TimeWindow | Correlation window for install-to-beacon or process-to-network event should match operational environment |