{"id":"T1021","name":"Remote Services","url":"https://attack.mitre.org/techniques/T1021","tactics":["lateral-movement"],"platforms":["Linux","macOS","Windows","IaaS","ESXi"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0269","stix_id":"x-mitre-detection-strategy--d33ffd4e-6328-4b10-84c0-7ad4a241b02d","name":"Behavioral Detection Strategy for Remote Service Logins and Post-Access Activity","url":"https://attack.mitre.org/detectionstrategies/DET0269","analytics":[{"id":"AN0750","stix_id":"x-mitre-analytic--34c5e959-876b-4851-8ebf-bfaf97e9e609","name":"Analytic 0750","description":"Logon via RDP or WMI by a user account followed by uncommon command execution, file manipulation, or lateral network connections.","url":"https://attack.mitre.org/detectionstrategies/DET0269#AN0750","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4624, 4648","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Correlation window between remote login and post-access activity"},{"field":"LogonUser","description":"Limit to service accounts or privileged users for higher fidelity"},{"field":"RemoteHostList","description":"Allowlisting known admin jumpboxes or deployment tools"}],"live":true,"detection_strategies":["DET0269"],"techniques":["T1021"]},{"id":"AN0751","stix_id":"x-mitre-analytic--a366262a-ba79-4b74-be16-0b139d546651","name":"Analytic 0751","description":"SSH session from new source IP followed by interactive shell or privilege escalation (e.g., sudo, su) and outbound lateral connection.","url":"https://attack.mitre.org/detectionstrategies/DET0269#AN0751","platforms":["Linux"],"log_source_references":[{"name":"linux:syslog","channel":"sshd: Accepted password/publickey","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"linux-syslog"},{"name":"auditd:SYSCALL","channel":"execve, USER_CMD","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"SourceIP","description":"Limit to new/unexpected SSH source IPs"},{"field":"CommandList","description":"Flag suspicious post-SSH command patterns"}],"live":true,"detection_strategies":["DET0269"],"techniques":["T1021"]},{"id":"AN0752","stix_id":"x-mitre-analytic--e26778ca-0fd9-4a1b-9d1d-d8ba561b065a","name":"Analytic 0752","description":"Remote login via ARD or SSH followed by screensharingd process activity or modification of TCC-protected files.","url":"https://attack.mitre.org/detectionstrategies/DET0269#AN0752","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"eventMessage CONTAINS 'screensharingd' or 'AuthorizationRefCreate'","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"process_events","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"RemoteService","description":"Differentiate ARD vs SSH access patterns"},{"field":"TargetedPath","description":"Tunable list of sensitive directories or TCC targets"}],"live":true,"detection_strategies":["DET0269"],"techniques":["T1021"]},{"id":"AN0753","stix_id":"x-mitre-analytic--dfabf07a-8179-43f5-abf6-699202c10343","name":"Analytic 0753","description":"Use of cloud-based bastion or VM console session followed by commands that initiate outbound SSH or RDP sessions from the cloud instance to other environments.","url":"https://attack.mitre.org/detectionstrategies/DET0269#AN0753","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"AWS ConsoleLogin, StartSession","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"aws-cloudtrail"},{"name":"AWS:VPCFlowLogs","channel":"Outbound connections to port 22, 3389","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"aws-vpcflowlogs"}],"mutable_elements":[{"field":"SourceAssetTag","description":"Limit detection to cloud admin/bastion hosts"},{"field":"TargetPortList","description":"Define critical remote service ports to flag"}],"live":true,"detection_strategies":["DET0269"],"techniques":["T1021"]},{"id":"AN0754","stix_id":"x-mitre-analytic--8a534291-3b75-45ba-9f7b-b952251a3f03","name":"Analytic 0754","description":"vSphere API logins (vimService) or SSH to ESXi host followed by unauthorized shell commands or lateral remote logins from the ESXi host.","url":"https://attack.mitre.org/detectionstrategies/DET0269#AN0754","platforms":["ESXi"],"log_source_references":[{"name":"esxi:vmkernel","channel":"vim.fault.*, DCUI login, SSH shell","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"esxi-vmkernel"},{"name":"esxi:shell","channel":"Command execution trace","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"esxi-shell"}],"mutable_elements":[{"field":"SessionType","description":"Filter by DCUI, SSH, vSphere API"},{"field":"CommandPattern","description":"Watch for remote access tool invocations (e.g., netcat, ssh)"}],"live":true,"detection_strategies":["DET0269"],"techniques":["T1021"]}],"live":true,"version":"1.0","techniques":["T1021"]}],"sigma_rules":[{"id":"22777c9e-873a-4b49-855f-6072ab861a52","title":"OpenCanary - SMB File Open Request","author":"Security Onion Solutions","status":"test","level":"high","date":"2024-03-08","modified":null,"description":"Detects instances where an SMB service on an OpenCanary node has had a file open request.","references":["https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration","https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52"],"logsource":{"product":"opencanary","category":"application"},"tags":["attack.lateral-movement","attack.collection","attack.t1021","attack.t1005"],"path":"rules/application/opencanary/opencanary_smb_file_open.yml","techniques":["T1021","T1005"],"cves":[]},{"id":"6991bc2b-ae2e-447f-bc55-3a1ba04c14e5","title":"OpenCanary - FTP Login Attempt","author":"Security Onion Solutions","status":"test","level":"high","date":"2024-03-08","modified":null,"description":"Detects instances where an FTP service on an OpenCanary node has had a login attempt.","references":["https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration","https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52"],"logsource":{"product":"opencanary","category":"application"},"tags":["attack.initial-access","attack.exfiltration","attack.lateral-movement","attack.t1190","attack.t1021"],"path":"rules/application/opencanary/opencanary_ftp_login_attempt.yml","techniques":["T1190","T1021"],"cves":[]},{"id":"730fc21b-eaff-474b-ad23-90fd265d4988","title":"Psexec Execution","author":"omkar72","status":"test","level":"medium","date":"2020-10-30","modified":"2023-02-28","description":"Detects user accept agreement execution in psexec commandline","references":["https://www.fireeye.com/blog/threat-research/2020/10/kegtap-and-singlemalt-with-a-ransomware-chaser.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.lateral-movement","attack.t1569","attack.t1021"],"path":"rules/windows/process_creation/proc_creation_win_sysinternals_psexec_execution.yml","techniques":["T1569","T1021"],"cves":[]},{"id":"7638e5fe-600c-4289-a968-f49dd537ec7d","title":"HackTool - NetExec Execution","author":"Chirag Damani","status":"experimental","level":"high","date":"2026-03-29","modified":null,"description":"Detects execution of the hacktool NetExec.\nNetExec (formerly CrackMapExec) is a widely used post-exploitation tool designed for Active Directory penetration testing and network enumeration\nIn enterprise environments, the use of NetExec is considered suspicious or potentially malicious because it enables attackers to enumerate hosts, exploit network services, and move laterally across systems.\nThreat actors and red teams commonly use NetExec to identify vulnerable systems, harvest credentials, and execute commands remotely.\n","references":["https://thedfirreport.com/2025/12/17/cats-got-your-files-lynx-ransomware/","https://github.com/Pennyw0rth/NetExec","https://www.netexec.wiki/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1018","attack.lateral-movement","attack.t1021"],"path":"rules/windows/process_creation/proc_creation_win_hktl_netexec.yml","techniques":["T1018","T1021"],"cves":[]},{"id":"8a3038e8-9c9d-46f8-b184-66234a160f6f","title":"Potential Remote Desktop Tunneling","author":"Tim Rauch, Elastic (idea)","status":"test","level":"medium","date":"2022-09-27","modified":null,"description":"Detects potential use of an SSH utility to establish RDP over a reverse SSH Tunnel. This can be used by attackers to enable routing of network packets that would otherwise not reach their intended destination.","references":["https://www.elastic.co/guide/en/security/current/potential-remote-desktop-tunneling-detected.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.lateral-movement","attack.t1021"],"path":"rules/windows/process_creation/proc_creation_win_susp_remote_desktop_tunneling.yml","techniques":["T1021"],"cves":[]},{"id":"9bd04a79-dabe-4f1f-a5ff-92430265c96b","title":"Privilege Escalation via Named Pipe Impersonation","author":"Tim Rauch, Elastic (idea)","status":"test","level":"high","date":"2022-09-27","modified":"2022-12-30","description":"Detects a remote file copy attempt to a hidden network share. This may indicate lateral movement or data staging activity.","references":["https://www.elastic.co/guide/en/security/current/privilege-escalation-via-named-pipe-impersonation.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.lateral-movement","attack.t1021"],"path":"rules/windows/process_creation/proc_creation_win_susp_priv_escalation_via_named_pipe.yml","techniques":["T1021"],"cves":[]},{"id":"9db5446c-b44a-4291-8b89-fcab5609c3b3","title":"OpenCanary - VNC Connection Attempt","author":"Security Onion Solutions","status":"test","level":"high","date":"2024-03-08","modified":null,"description":"Detects instances where a VNC service on an OpenCanary node has had a connection attempt.","references":["https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration","https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52"],"logsource":{"product":"opencanary","category":"application"},"tags":["attack.lateral-movement","attack.t1021"],"path":"rules/application/opencanary/opencanary_vnc_connection_attempt.yml","techniques":["T1021"],"cves":[]},{"id":"cd55f721-5623-4663-bd9b-5229cab5237d","title":"OpenCanary - SSH New Connection Attempt","author":"Security Onion Solutions","status":"test","level":"high","date":"2024-03-08","modified":null,"description":"Detects instances where an SSH service on an OpenCanary node has had a connection attempt.","references":["https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration","https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52"],"logsource":{"product":"opencanary","category":"application"},"tags":["attack.privilege-escalation","attack.initial-access","attack.lateral-movement","attack.persistence","attack.stealth","attack.t1133","attack.t1021","attack.t1078"],"path":"rules/application/opencanary/opencanary_ssh_new_connection.yml","techniques":["T1133","T1021","T1078"],"cves":[]},{"id":"e9856028-fd4e-46e6-b3d1-10f7ceb95078","title":"OpenCanary - SNMP OID Request","author":"Security Onion Solutions","status":"test","level":"high","date":"2024-03-08","modified":null,"description":"Detects instances where an SNMP service on an OpenCanary node has had an OID request.","references":["https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration","https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52"],"logsource":{"product":"opencanary","category":"application"},"tags":["attack.discovery","attack.lateral-movement","attack.t1016","attack.t1021"],"path":"rules/application/opencanary/opencanary_snmp_cmd.yml","techniques":["T1016","T1021"],"cves":[]},{"id":"fda34293-718e-4b36-b018-38caab0d1209","title":"New RDP Connection Initiated From Domain Controller","author":"Josh Nickels","status":"test","level":"high","date":"2024-05-10","modified":null,"description":"Detects an RDP connection originating from a domain controller.","references":["Internal Research"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.lateral-movement","attack.t1021"],"path":"rules-placeholder/windows/network_connection/net_connection_win_susp_rdp_from_domain_controller.yml","techniques":["T1021"],"cves":[]},{"id":"ff7139bc-fdb1-4437-92f2-6afefe8884cb","title":"OpenCanary - SSH Login Attempt","author":"Security Onion Solutions","status":"test","level":"high","date":"2024-03-08","modified":null,"description":"Detects instances where an SSH service on an OpenCanary node has had a login attempt.","references":["https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration","https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52"],"logsource":{"product":"opencanary","category":"application"},"tags":["attack.privilege-escalation","attack.initial-access","attack.lateral-movement","attack.persistence","attack.stealth","attack.t1133","attack.t1021","attack.t1078"],"path":"rules/application/opencanary/opencanary_ssh_login_attempt.yml","techniques":["T1133","T1021","T1078"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2025-54309","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2024-55591","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-28252","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2020-1472","state":"mapped","mapping_types":["primary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}