{"id":"T1219.002","name":"Remote Desktop Software","url":"https://attack.mitre.org/techniques/T1219/002","tactics":["command-and-control"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0259","stix_id":"x-mitre-detection-strategy--834e853c-479d-4ddd-a1a3-349b09466b8d","name":"Remote Desktop Software Execution and Beaconing Detection","url":"https://attack.mitre.org/detectionstrategies/DET0259","analytics":[{"id":"AN0714","stix_id":"x-mitre-analytic--fe1e10ae-ddd2-40f0-8e62-3db88c0c8c68","name":"Analytic 0714","description":"Adversary installation or use of RMM software (e.g., TeamViewer, AnyDesk, ScreenConnect) followed by outbound beaconing or remote session establishment","url":"https://attack.mitre.org/detectionstrategies/DET0259#AN0714","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall","channel":"new rule allowing inbound or outbound connections for remote desktop software","data_component":"DC0051","data_component_name":"Firewall Rule Modification","log_source_slug":"wineventlog-microsoft-windows-windows-firewall-with-advanced-security-firewall"}],"mutable_elements":[{"field":"Image","description":"RMM software can vary; defenders should update rules to account for additional binaries (e.g., ConnectWise, Zoho Assist)"},{"field":"DestinationPort","description":"RMM software may use configurable or random high ports outside of standard (e.g., 7070, 5650)"},{"field":"ParentImage","description":"Expected parent process may vary in different enterprise contexts"},{"field":"TimeWindow","description":"Correlation window for install-to-beacon or process-to-network event should match operational environment"}],"live":true,"detection_strategies":["DET0259"],"techniques":["T1219.002"]},{"id":"AN0715","stix_id":"x-mitre-analytic--77769a6d-f3f4-42f1-a9a7-0d1096563115","name":"Analytic 0715","description":"Execution of known or custom VNC/remote desktop daemons or tunneling agents that initiate external communication after launch","url":"https://attack.mitre.org/detectionstrategies/DET0259#AN0715","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"outbound connections to RMM services or to unusual destination ports","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"binary_name","description":"Custom-compiled or renamed VNC servers (e.g., x11vnc, tightvncserver) may require local tuning"},{"field":"OutboundIPRange","description":"Destination IP or ASN may shift depending on geolocation of cloud-hosted RMM backends"}],"live":true,"detection_strategies":["DET0259"],"techniques":["T1219.002"]},{"id":"AN0716","stix_id":"x-mitre-analytic--1d46bf4d-a090-4865-9205-e271d223da42","name":"Analytic 0716","description":"Initiation of remote desktop sessions via AnyDesk, TeamViewer, or Chrome Remote Desktop accompanied by unexpected user logins or system modifications","url":"https://attack.mitre.org/detectionstrategies/DET0259#AN0716","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"launch of remote desktop app or helper binary","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"network sessions initiated by remote desktop apps","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"process_signature","description":"App may be notarized and signed differently depending on distribution method (App Store vs .pkg)"},{"field":"sandbox_exception","description":"If the remote desktop tool circumvents sandbox, it may produce additional telemetry in local TCC logs"}],"live":true,"detection_strategies":["DET0259"],"techniques":["T1219.002"]}],"live":true,"version":"1.0","techniques":["T1219.002"]}],"sigma_rules":[{"id":"065b00ca-5d5c-4557-ac95-64a6d0b64d86","title":"Remote Access Tool - Anydesk Execution From Suspicious Folder","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-05-20","modified":"2025-02-24","description":"An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks.\nThese services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment.\nRemote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1219/T1219.md#atomic-test-2---anydesk-files-detected-test-on-windows","https://thedfirreport.com/2025/02/24/confluence-exploit-leads-to-lockbit-ransomware/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/process_creation/proc_creation_win_remote_access_tools_anydesk_susp_exec.yml","techniques":["T1219.002"],"cves":[]},{"id":"0b9ad457-2554-44c1-82c2-d56a99c42377","title":"Anydesk Temporary Artefact","author":"frack113","status":"test","level":"medium","date":"2022-02-11","modified":"2024-07-20","description":"An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks.\nThese services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment.\nRemote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1219/T1219.md#atomic-test-2---anydesk-files-detected-test-on-windows"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/file/file_event/file_event_win_anydesk_artefact.yml","techniques":["T1219.002"],"cves":[]},{"id":"101a1877-2cf4-474d-abfd-7f6ac4788d1a","title":"Antivirus - APT Malware Signature","author":"Arnim Rupp (Nextron Systems)","status":"experimental","level":"critical","date":"2026-06-15","modified":null,"description":"Detects a highly relevant Antivirus alert that reports APT malware.\nThis event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.\n","references":["https://www.nextron-systems.com/?s=antivirus"],"logsource":{"category":"antivirus"},"tags":["attack.execution","attack.t1203","attack.command-and-control","attack.t1219.002"],"path":"rules/category/antivirus/av_advanced_persistent_threat.yml","techniques":["T1203","T1219.002"],"cves":[]},{"id":"114e7f1c-f137-48c8-8f54-3088c24ce4b9","title":"Remote Access Tool - AnyDesk Silent Installation","author":"Ján Trenčanský","status":"test","level":"high","date":"2021-08-06","modified":"2023-03-05","description":"Detects AnyDesk Remote Desktop silent installation. Which can be used by attackers to gain remote access.","references":["https://twitter.com/TheDFIRReport/status/1423361119926816776?s=20","https://support.anydesk.com/Automatic_Deployment"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/process_creation/proc_creation_win_remote_access_tools_anydesk_silent_install.yml","techniques":["T1219.002"],"cves":[]},{"id":"145322e4-0fd3-486b-81ca-9addc75736d8","title":"Use of UltraVNC Remote Access Software","author":"frack113","status":"test","level":"medium","date":"2022-10-02","modified":null,"description":"An adversary may use legitimate desktop support and remote access software,to establish an interactive command and control channel to target systems within networks","references":["https://github.com/redcanaryco/atomic-red-team/blob/9e5b12c4912c07562aec7500447b11fa3e17e254/atomics/T1219/T1219.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/process_creation/proc_creation_win_ultravnc.yml","techniques":["T1219.002"],"cves":[]},{"id":"162ab1e4-6874-4564-853c-53ec3ab8be01","title":"TeamViewer Remote Session","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2022-01-30","modified":null,"description":"Detects the creation of log files during a TeamViewer remote session","references":["https://www.teamviewer.com/en-us/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/file/file_event/file_event_win_susp_teamviewer_remote_session.yml","techniques":["T1219.002"],"cves":[]},{"id":"22c45af6-f590-4d44-bab3-b5b2d2a2b6d9","title":"Remote Access Tool - Potential MeshAgent Execution - MacOS","author":"Norbert Jaśniewicz (AlphaSOC)","status":"experimental","level":"medium","date":"2025-05-19","modified":null,"description":"Detects potential execution of MeshAgent which is a tool used for remote access.\nHistorical data shows that threat actors rename MeshAgent binary to evade detection.\nMatching command lines with the '--meshServiceName' argument can indicate that the MeshAgent is being used for remote access.\n","references":["https://www.huntress.com/blog/know-thy-enemy-a-novel-november-case-on-persistent-remote-access","https://thecyberexpress.com/ukraine-hit-by-meshagent-malware-campaign/","https://wazuh.com/blog/how-to-detect-meshagent-with-wazuh/","https://www.security.com/threat-intelligence/medusa-ransomware-attacks"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/macos/process_creation/proc_creation_macos_remote_access_tools_meshagent_arguments.yml","techniques":["T1219.002"],"cves":[]},{"id":"238527ad-3c2c-4e4f-a1f6-92fd63adb864","title":"Antivirus - Exploitation Framework Signature","author":"Florian Roth (Nextron Systems), Arnim Rupp","status":"stable","level":"critical","date":"2018-09-09","modified":"2026-06-15","description":"Detects a highly relevant Antivirus alert that reports an exploitation framework.\nThis event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.\n","references":["https://www.nextron-systems.com/?s=antivirus","https://www.virustotal.com/gui/file/925b0b28472d4d79b4bf92050e38cc2b8f722691c713fc28743ac38551bc3797","https://www.virustotal.com/gui/file/8f8daabe1c8ceb5710949283818e16c4aa8059bf2ce345e2f2c90b8692978424","https://www.virustotal.com/gui/file/d9669f7e3eb3a9cdf6a750eeb2ba303b5ae148a43e36546896f1d1801e912466"],"logsource":{"category":"antivirus"},"tags":["attack.execution","attack.t1203","attack.command-and-control","attack.t1219.002"],"path":"rules/category/antivirus/av_exploitation_framework.yml","techniques":["T1203","T1219.002"],"cves":[]},{"id":"2d367498-5112-4ae5-a06a-96e7bc33a211","title":"Suspicious Binary Writes Via AnyDesk","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-09-28","modified":"2025-02-24","description":"Detects AnyDesk writing binary files to disk other than \"gcapi.dll\".\nAccording to RedCanary research it is highly abnormal for AnyDesk to write executable files to disk besides gcapi.dll,\nwhich is a legitimate DLL that is part of the Google Chrome web browser used to interact with the Google Cloud API. (See reference section for more details)\n","references":["https://redcanary.com/blog/misbehaving-rats/","https://thedfirreport.com/2025/02/24/confluence-exploit-leads-to-lockbit-ransomware/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/file/file_event/file_event_win_anydesk_writing_susp_binaries.yml","techniques":["T1219.002"],"cves":[]},{"id":"2fbbe9ff-0afc-470b-bdc0-592198339968","title":"Remote Access Tool - Potential MeshAgent Execution - Windows","author":"Norbert Jaśniewicz (AlphaSOC)","status":"experimental","level":"medium","date":"2025-05-19","modified":null,"description":"Detects potential execution of MeshAgent which is a tool used for remote access.\nHistorical data shows that threat actors rename MeshAgent binary to evade detection.\nMatching command lines with the '--meshServiceName' argument can indicate that the MeshAgent is being used for remote access.\n","references":["https://www.huntress.com/blog/know-thy-enemy-a-novel-november-case-on-persistent-remote-access","https://thecyberexpress.com/ukraine-hit-by-meshagent-malware-campaign/","https://wazuh.com/blog/how-to-detect-meshagent-with-wazuh/","https://www.security.com/threat-intelligence/medusa-ransomware-attacks"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/process_creation/proc_creation_win_remote_access_tools_meshagent_arguments.yml","techniques":["T1219.002"],"cves":[]},{"id":"3ab79e90-9fab-4cdf-a7b2-6522bc742adb","title":"HackTool - RemoteKrbRelay SMB Relay Secrets Dump Module Indicators","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2024-06-27","modified":null,"description":"Detects the creation of file with specific names used by RemoteKrbRelay SMB Relay attack module.","references":["https://github.com/CICADA8-Research/RemoteKrbRelay/blob/19ec76ba7aa50c2722b23359bc4541c0a9b2611c/Exploit/RemoteKrbRelay/Relay/Attacks/RemoteRegistry.cs#L31-L40"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/file/file_event/file_event_win_hktl_krbrelay_remote_ioc.yml","techniques":["T1219.002"],"cves":[]},{"id":"4bb79b62-ef12-4861-981d-2aab43fab642","title":"TacticalRMM Service Installation","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-11-28","modified":null,"description":"Detects a TacticalRMM service installation. Tactical RMM is a remote monitoring & management tool.","references":["https://thedfirreport.com/2022/11/28/emotet-strikes-again-lnk-file-leads-to-domain-wide-ransomware/"],"logsource":{"product":"windows","service":"system"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/builtin/system/service_control_manager/win_system_service_install_tacticalrmm.yml","techniques":["T1219.002"],"cves":[]},{"id":"4d07b1f4-cb00-4470-b9f8-b0191d48ff52","title":"DNS Query To Remote Access Software Domain From Non-Browser App","author":"frack113, Connor Martin","status":"test","level":"medium","date":"2022-07-11","modified":"2024-12-17","description":"An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks.\nThese services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment.\nRemote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1219/T1219.md#atomic-test-4---gotoassist-files-detected-test-on-windows","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1219/T1219.md#atomic-test-3---logmein-files-detected-test-on-windows","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1219/T1219.md#atomic-test-6---ammyy-admin-software-execution","https://redcanary.com/blog/misbehaving-rats/","https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/hunting-for-omi-vulnerability-exploitation-with-azure-sentinel/ba-p/2764093","https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a","https://blog.sekoia.io/scattered-spider-laying-new-eggs/","https://learn.microsoft.com/en-us/windows/client-management/client-tools/quick-assist#disable-quick-assist-within-your-organization"],"logsource":{"product":"windows","category":"dns_query"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/dns_query/dns_query_win_remote_access_software_domains_non_browsers.yml","techniques":["T1219.002"],"cves":[]},{"id":"52753ea4-b3a0-4365-910d-36cff487b789","title":"Hijack Legit RDP Session to Move Laterally","author":"Samir Bousseaden","status":"test","level":"high","date":"2019-02-21","modified":"2021-11-27","description":"Detects the usage of tsclient share to place a backdoor on the RDP source machine's startup folder","references":["Internal Research"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/file/file_event/file_event_win_tsclient_filewrite_startup.yml","techniques":["T1219.002"],"cves":[]},{"id":"57bff678-25d1-4d6c-8211-8ca106d12053","title":"Remote Access Tool - ScreenConnect Execution","author":"frack113","status":"test","level":"medium","date":"2022-02-13","modified":"2023-03-05","description":"An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks.\nThese services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment.\nRemote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1219/T1219.md#atomic-test-5---screenconnect-application-download-and-install-on-windows"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/process_creation/proc_creation_win_remote_access_tools_screenconnect.yml","techniques":["T1219.002"],"cves":[]},{"id":"5d756aee-ad3e-4306-ad95-cb1abec48de2","title":"GoToAssist Temporary Installation Artefact","author":"frack113","status":"test","level":"medium","date":"2022-02-13","modified":null,"description":"An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks.\nThese services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment.\nRemote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1219/T1219.md#atomic-test-4---gotoassist-files-detected-test-on-windows"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/file/file_event/file_event_win_gotoopener_artefact.yml","techniques":["T1219.002"],"cves":[]},{"id":"5fdce3ac-e7f9-4ecd-a3aa-a4d78ebbf0af","title":"Mstsc.EXE Execution With Local RDP File","author":"Nasreddine Bencherchali (Nextron Systems), Christopher Peacock @securepeacock","status":"test","level":"low","date":"2023-04-18","modified":"2023-04-30","description":"Detects potential RDP connection via Mstsc using a local \".rdp\" file","references":["https://www.blackhillsinfosec.com/rogue-rdp-revisiting-initial-access-methods/","https://web.archive.org/web/20230726144748/https://blog.thickmints.dev/mintsights/detecting-rogue-rdp/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/process_creation/proc_creation_win_mstsc_run_local_rdp_file.yml","techniques":["T1219.002"],"cves":[]},{"id":"6e22722b-dfb1-4508-a911-49ac840b40f8","title":"Suspicious Mstsc.EXE Execution With Local RDP File","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-04-18","modified":null,"description":"Detects potential RDP connection via Mstsc using a local \".rdp\" file located in suspicious locations.","references":["https://www.blackhillsinfosec.com/rogue-rdp-revisiting-initial-access-methods/","https://web.archive.org/web/20230726144748/https://blog.thickmints.dev/mintsights/detecting-rogue-rdp/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/process_creation/proc_creation_win_mstsc_run_local_rdp_file_susp_location.yml","techniques":["T1219.002"],"cves":[]},{"id":"6f6afac3-8e7a-4e4b-9588-2608ffe08f82","title":"Potential CSharp Streamer RAT Loading .NET Executable Image","author":"Luca Di Bartolomeo","status":"test","level":"high","date":"2024-06-22","modified":null,"description":"Detects potential CSharp Streamer RAT loading .NET executable image by using the default file name and path associated with the tool.\n","references":["https://thedfirreport.com/2024/06/10/icedid-brings-screenconnect-and-csharp-streamer-to-alphv-ransomware-deployment/#detections","https://cyber.wtf/2023/12/06/the-csharp-streamer-rat/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.command-and-control","attack.t1219.002","detection.emerging-threats"],"path":"rules-emerging-threats/2024/Malware/CSharp-Streamer/image_load_malware_csharp_streamer_dotnet_load.yml","techniques":["T1219.002"],"cves":[]},{"id":"70761fe8-6aa2-4f80-98c1-a57049c08e66","title":"Potential SocGholish Second Stage C2 DNS Query","author":"Dusty Miller","status":"test","level":"high","date":"2023-02-23","modified":null,"description":"Detects a DNS query initiated from a \"wscript\" process for domains matching a specific pattern that was seen being used by SocGholish for its Command and Control traffic","references":["https://www.virustotal.com/gui/file/0e2854753d17b1bb534de8e765d5813c9fb584a745978b3d92bc6ca78e3e7735/relations","https://www.virustotal.com/gui/file/d5661009c461a8b20e1ad22f48609cc84dd90aee9182e026659dde4d46aaf25e/relations","https://www.proofpoint.com/us/blog/threat-insight/part-1-socgholish-very-real-threat-very-fake-update"],"logsource":{"product":"windows","category":"dns_query"},"tags":["attack.command-and-control","attack.t1219.002","detection.emerging-threats"],"path":"rules-emerging-threats/2023/Malware/dns_query_win_malware_socgholish_second_stage_c2.yml","techniques":["T1219.002"],"cves":[]},{"id":"74a2b202-73e0-4693-9a3a-9d36146d0775","title":"Remote Access Tool - MeshAgent Command Execution via MeshCentral","author":"@Kostastsale","status":"test","level":"medium","date":"2024-09-22","modified":null,"description":"Detects the use of MeshAgent to execute commands on the target host, particularly when threat actors might abuse it to execute commands directly.\nMeshAgent can execute commands on the target host by leveraging win-console to obscure their activities and win-dispatcher to run malicious code through IPC with child processes.\n","references":["https://github.com/Ylianst/MeshAgent","https://github.com/Ylianst/MeshAgent/blob/52cf129ca43d64743181fbaf940e0b4ddb542a37/modules/win-dispatcher.js#L173","https://github.com/Ylianst/MeshAgent/blob/52cf129ca43d64743181fbaf940e0b4ddb542a37/modules/win-info.js#L55"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/process_creation/proc_creation_win_remote_access_tools_meshagent_exec.yml","techniques":["T1219.002"],"cves":[]},{"id":"758ff488-18d5-4cbe-8ec4-02b6285a434f","title":"Remote Access Tool - NetSupport Execution","author":"frack113","status":"test","level":"medium","date":"2022-09-25","modified":"2023-03-06","description":"An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks.\nThese services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment.\nRemote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1219/T1219.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/process_creation/proc_creation_win_remote_access_tools_netsupport.yml","techniques":["T1219.002"],"cves":[]},{"id":"778ba9a8-45e4-4b80-8e3e-34a419f0b85e","title":"TeamViewer Domain Query By Non-TeamViewer Application","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2022-01-30","modified":"2023-09-18","description":"Detects DNS queries to a TeamViewer domain only resolved by a TeamViewer client by an image that isn't named TeamViewer (sometimes used by threat actors for obfuscation)","references":["https://www.teamviewer.com/en-us/"],"logsource":{"product":"windows","category":"dns_query"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/dns_query/dns_query_win_teamviewer_domain_query_by_uncommon_app.yml","techniques":["T1219.002"],"cves":[]},{"id":"7b582f1a-b318-4c6a-bf4e-66fe49bf55a5","title":"Remote Access Tool - ScreenConnect Potential Suspicious Remote Command Execution","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), @Kostastsale","status":"test","level":"medium","date":"2022-02-25","modified":"2024-02-28","description":"Detects potentially suspicious child processes launched via the ScreenConnect client service.\n","references":["https://www.mandiant.com/resources/telegram-malware-iranian-espionage","https://docs.connectwise.com/ConnectWise_Control_Documentation/Get_started/Host_client/View_menu/Backstage_mode","https://www.huntress.com/blog/slashandgrab-screen-connect-post-exploitation-in-the-wild-cve-2024-1709-cve-2024-1708","https://www.trendmicro.com/en_us/research/24/b/threat-actor-groups-including-black-basta-are-exploiting-recent-.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/process_creation/proc_creation_win_remote_access_tools_screenconnect_remote_execution_susp.yml","techniques":["T1219.002"],"cves":[]},{"id":"87261fb2-69d0-42fe-b9de-88c6b5f65a43","title":"Atera Agent Installation","author":"Bhabesh Raj","status":"test","level":"high","date":"2021-09-01","modified":"2022-12-25","description":"Detects successful installation of Atera Remote Monitoring & Management (RMM) agent as recently found to be used by Conti operators","references":["https://www.advintel.io/post/secret-backdoor-behind-conti-ransomware-operation-introducing-atera-agent"],"logsource":{"product":"windows","service":"application"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/builtin/application/msiinstaller/win_software_atera_rmm_agent_install.yml","techniques":["T1219.002"],"cves":[]},{"id":"88656cec-6c3b-487c-82c0-f73ebb805503","title":"Remote Access Tool - UltraViewer Execution","author":"frack113","status":"test","level":"medium","date":"2022-09-25","modified":"2024-03-14","description":"An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks.\nThese services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment.\nRemote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1219/T1219.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/process_creation/proc_creation_win_remote_access_tools_ultraviewer.yml","techniques":["T1219.002"],"cves":[]},{"id":"95e60a2b-4705-444b-b7da-ba0ea81a3ee2","title":"Remote Access Tool - Simple Help Execution","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2024-02-23","modified":null,"description":"An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks.\nThese services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment.\nRemote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)\n","references":["https://www.huntress.com/blog/slashandgrab-screen-connect-post-exploitation-in-the-wild-cve-2024-1709-cve-2024-1708"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/process_creation/proc_creation_win_remote_access_tools_simple_help.yml","techniques":["T1219.002"],"cves":[]},{"id":"9711de76-5d4f-4c50-a94f-21e4e8f8384d","title":"Installation of TeamViewer Desktop","author":"frack113","status":"test","level":"medium","date":"2022-01-28","modified":null,"description":"TeamViewer_Desktop.exe is create during install","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1219/T1219.md#atomic-test-1---teamviewer-files-detected-test-on-windows"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/file/file_event/file_event_win_install_teamviewer_desktop.yml","techniques":["T1219.002"],"cves":[]},{"id":"97233998-3838-4581-88c6-f1d19d3993fb","title":"Antivirus - Remote Access Tools Signature","author":"Arnim Rupp (Nextron Systems)","status":"experimental","level":"critical","date":"2026-06-15","modified":null,"description":"Detects a highly relevant Antivirus alert that reports a remote access tool.\nThis event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.\n","references":["https://www.nextron-systems.com/?s=antivirus","https://www.virustotal.com/gui/file/d9669f7e3eb3a9cdf6a750eeb2ba303b5ae148a43e36546896f1d1801e912466"],"logsource":{"category":"antivirus"},"tags":["attack.execution","attack.t1203","attack.command-and-control","attack.t1219.002"],"path":"rules/category/antivirus/av_remote_access_toolkit.yml","techniques":["T1203","T1219.002"],"cves":[]},{"id":"9847f263-4a81-424f-970c-875dab15b79b","title":"Suspicious TSCON Start as SYSTEM","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2018-03-17","modified":"2022-05-27","description":"Detects a tscon.exe start as LOCAL SYSTEM","references":["http://www.korznikov.com/2017/03/0-day-or-feature-privilege-escalation.html","https://medium.com/@networksecurity/rdp-hijacking-how-to-hijack-rds-and-remoteapp-sessions-transparently-to-move-through-an-da2a1e73a5f6","https://www.ired.team/offensive-security/lateral-movement/t1076-rdp-hijacking-for-lateral-movement"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/process_creation/proc_creation_win_tscon_localsystem.yml","techniques":["T1219.002"],"cves":[]},{"id":"aa3168fb-d594-4f93-a92d-7a9ba675b766","title":"Remote Access Tool - Action1 Arbitrary Code Execution and Remote Sessions","author":"@kostastsale","status":"test","level":"medium","date":"2023-04-13","modified":null,"description":"Detects the execution of Action1 in order to execute arbitrary code or establish a remote session.\n\nAction1 is a powerful Remote Monitoring and Management tool that enables users to execute commands, scripts, and binaries.\nThrough the web interface of action1, the administrator must create a new policy or an app to establish remote execution and then points that the agent is installed.\n\nHunting Opportunity 1- Weed Out The Noise\n\nWhen threat actors execute a script, a command, or a binary through these new policies and apps, the names of these become visible in the command line during the execution process. Below is an example of the command line that contains the deployment of a binary through  a policy with name \"test_app_1\":\n\nParentCommandLine: \"C:\\WINDOWS\\Action1\\action1_agent.exe schedule:Deploy_App__test_app_1_1681327673425 runaction:0\"\n\nAfter establishing a baseline, we can split the command to extract the policy name and group all the policy names and inspect the results with a list of frequency occurrences.\n\nHunting Opportunity 2 - Remote Sessions On Out Of Office Hours\n\nIf you have admins within your environment using remote sessions to administer endpoints, you can create a threat-hunting query and modify the time of the initiated sessions looking for abnormal activity.\n","references":["https://twitter.com/Kostastsale/status/1646256901506605063?s=20","https://www.action1.com/documentation/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1219.002","detection.threat-hunting"],"path":"rules-threat-hunting/windows/process_creation/proc_creation_win_remote_access_tools_action1_code_exec_and_remote_sessions.yml","techniques":["T1219.002"],"cves":[]},{"id":"b1377339-fda6-477a-b455-ac0923f9ec2c","title":"Remote Access Tool - AnyDesk Piped Password Via CLI","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-09-28","modified":"2023-03-05","description":"Detects piping the password to an anydesk instance via CMD and the '--set-password' flag.","references":["https://redcanary.com/blog/misbehaving-rats/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/process_creation/proc_creation_win_remote_access_tools_anydesk_piped_password_via_cli.yml","techniques":["T1219.002"],"cves":[]},{"id":"b471f462-eb0d-4832-be35-28d94bdb4780","title":"Remote Access Tool - Renamed MeshAgent Execution - Windows","author":"Norbert Jaśniewicz (AlphaSOC)","status":"experimental","level":"high","date":"2025-05-19","modified":null,"description":"Detects the execution of a renamed instance of the Remote Monitoring and Management (RMM) tool, MeshAgent.\nRMM tools such as MeshAgent are commonly utilized by IT administrators for legitimate remote support and system management.\nHowever, malicious actors may exploit these tools by renaming them to bypass detection mechanisms, enabling unauthorized access and control over compromised systems.\n","references":["https://www.huntress.com/blog/know-thy-enemy-a-novel-november-case-on-persistent-remote-access","https://thecyberexpress.com/ukraine-hit-by-meshagent-malware-campaign/","https://wazuh.com/blog/how-to-detect-meshagent-with-wazuh/","https://www.security.com/threat-intelligence/medusa-ransomware-attacks"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.stealth","attack.t1219.002","attack.t1036.003"],"path":"rules/windows/process_creation/proc_creation_win_remote_access_tools_renamed_meshagent_execution.yml","techniques":["T1219.002","T1036.003"],"cves":[]},{"id":"b52e84a3-029e-4529-b09b-71d19dd27e94","title":"Remote Access Tool - AnyDesk Execution","author":"frack113","status":"test","level":"medium","date":"2022-02-11","modified":"2025-02-24","description":"An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks.\nThese services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment.\nRemote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1219/T1219.md#atomic-test-2---anydesk-files-detected-test-on-windows","https://thedfirreport.com/2025/02/24/confluence-exploit-leads-to-lockbit-ransomware/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/process_creation/proc_creation_win_remote_access_tools_anydesk.yml","techniques":["T1219.002"],"cves":[]},{"id":"b6d98a4f-cef0-4abf-bbf6-24132854a83d","title":"Remote Access Tool - GoToAssist Execution","author":"frack113","status":"test","level":"medium","date":"2022-02-13","modified":"2023-03-05","description":"An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks.\nThese services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment.\nRemote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1219/T1219.md#atomic-test-4---gotoassist-files-detected-test-on-windows"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/process_creation/proc_creation_win_remote_access_tools_gotoopener.yml","techniques":["T1219.002"],"cves":[]},{"id":"bb09dd3e-2b78-4819-8e35-a7c1b874e449","title":"HackTool - Inveigh Execution Artefacts","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"critical","date":"2022-10-24","modified":"2024-06-27","description":"Detects the presence and execution of Inveigh via dropped artefacts","references":["https://github.com/Kevin-Robertson/Inveigh/blob/29d9e3c3a625b3033cdaf4683efaafadcecb9007/Inveigh/Support/Output.cs","https://github.com/Kevin-Robertson/Inveigh/blob/29d9e3c3a625b3033cdaf4683efaafadcecb9007/Inveigh/Support/Control.cs","https://thedfirreport.com/2020/11/23/pysa-mespinoza-ransomware/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/file/file_event/file_event_win_hktl_inveigh_artefacts.yml","techniques":["T1219.002"],"cves":[]},{"id":"bd3b5eaa-439d-4a42-8f35-a49f5c8a2582","title":"Remote Access Tool - Renamed MeshAgent Execution - MacOS","author":"Norbert Jaśniewicz (AlphaSOC)","status":"experimental","level":"high","date":"2025-05-19","modified":null,"description":"Detects the execution of a renamed instance of the Remote Monitoring and Management (RMM) tool, MeshAgent.\nRMM tools such as MeshAgent are commonly utilized by IT administrators for legitimate remote support and system management.\nHowever, malicious actors may exploit these tools by renaming them to bypass detection mechanisms, enabling unauthorized access and control over compromised systems.\n","references":["https://www.huntress.com/blog/know-thy-enemy-a-novel-november-case-on-persistent-remote-access","https://thecyberexpress.com/ukraine-hit-by-meshagent-malware-campaign/","https://wazuh.com/blog/how-to-detect-meshagent-with-wazuh/","https://www.security.com/threat-intelligence/medusa-ransomware-attacks"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.command-and-control","attack.stealth","attack.t1219.002","attack.t1036.003"],"path":"rules/macos/process_creation/proc_creation_macos_remote_access_tools_renamed_meshagent_execution.yml","techniques":["T1219.002","T1036.003"],"cves":[]},{"id":"ce5678bb-b9aa-4fb5-be4b-e57f686256ad","title":"Potential Remote Desktop Connection to Non-Domain Host","author":"James Pemberton","status":"test","level":"medium","date":"2020-05-22","modified":"2021-11-27","description":"Detects logons using NTLM to hosts that are potentially not part of the domain.","references":["n/a"],"logsource":{"product":"windows","service":"ntlm"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/builtin/ntlm/win_susp_ntlm_rdp.yml","techniques":["T1219.002"],"cves":[]},{"id":"d20ee2f4-822c-4827-9e15-41500b1fff10","title":"Potential Amazon SSM Agent Hijacking","author":"Muhammad Faisal","status":"test","level":"medium","date":"2023-08-02","modified":null,"description":"Detects potential Amazon SSM agent hijack attempts as outlined in the Mitiga research report.","references":["https://www.mitiga.io/blog/mitiga-security-advisory-abusing-the-ssm-agent-as-a-remote-access-trojan","https://www.bleepingcomputer.com/news/security/amazons-aws-ssm-agent-can-be-used-as-post-exploitation-rat-malware/","https://www.helpnetsecurity.com/2023/08/02/aws-instances-attackers-access/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.persistence","attack.t1219.002"],"path":"rules/windows/process_creation/proc_creation_win_ssm_agent_abuse.yml","techniques":["T1219.002"],"cves":[]},{"id":"d58ba5c6-0ed7-4b9d-a433-6878379efda9","title":"Remote Access Tool - AnyDesk Incoming Connection","author":"@d4ns4n_ (Wuerth-Phoenix)","status":"experimental","level":"medium","date":"2024-09-02","modified":"2025-02-24","description":"Detects incoming connections to AnyDesk. This could indicate a potential remote attacker trying to connect to a listening instance of AnyDesk and use it as potential command and control channel.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1219/T1219.md#atomic-test-2---anydesk-files-detected-test-on-windows","https://asec.ahnlab.com/en/40263/"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.persistence","attack.command-and-control","attack.t1219.002"],"path":"rules/windows/network_connection/net_connection_win_remote_access_tools_anydesk_incoming_connection.yml","techniques":["T1219.002"],"cves":[]},{"id":"d85873ef-a0f8-4c48-a53a-6b621f11729d","title":"Remote Access Tool - LogMeIn Execution","author":"frack113","status":"test","level":"medium","date":"2022-02-11","modified":"2023-03-05","description":"An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks.\nThese services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment.\nRemote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1219/T1219.md#atomic-test-3---logmein-files-detected-test-on-windows"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/process_creation/proc_creation_win_remote_access_tools_logmein.yml","techniques":["T1219.002"],"cves":[]},{"id":"e043f529-8514-4205-8ab0-7f7d2927b400","title":"DNS Query To AzureWebsites.NET By Non-Browser Process","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2024-06-24","modified":null,"description":"Detects a DNS query by a non browser process on the system to \"azurewebsites.net\". The latter was often used by threat actors as a malware hosting and exfiltration site.\n","references":["https://www.sentinelone.com/labs/wip26-espionage-threat-actors-abuse-cloud-infrastructure-in-targeted-telco-attacks/","https://symantec-enterprise-blogs.security.com/threat-intelligence/harvester-new-apt-attacks-asia","https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/higaisa-or-winnti-apt-41-backdoors-old-and-new/","https://intezer.com/blog/research/how-we-escaped-docker-in-azure-functions/"],"logsource":{"product":"windows","category":"dns_query"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/dns_query/dns_query_win_domain_azurewebsites.yml","techniques":["T1219.002"],"cves":[]},{"id":"e0d1ad53-c7eb-48ec-a87a-72393cc6cedc","title":"Mesh Agent Service Installation","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-11-28","modified":null,"description":"Detects a Mesh Agent service installation. Mesh Agent is used to remotely manage computers","references":["https://thedfirreport.com/2022/11/28/emotet-strikes-again-lnk-file-leads-to-domain-wide-ransomware/"],"logsource":{"product":"windows","service":"system"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/builtin/system/service_control_manager/win_system_service_install_mesh_agent.yml","techniques":["T1219.002"],"cves":[]},{"id":"e20b5b14-ce93-4230-88af-981983ef6e74","title":"QuickAssist Execution","author":"Muhammad Faisal (@faisalusuf)","status":"experimental","level":"low","date":"2024-12-19","modified":null,"description":"Detects the execution of Microsoft Quick Assist tool \"QuickAssist.exe\". This utility can be used by attackers to gain remote access.\n","references":["https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/","https://www.linkedin.com/posts/kevin-beaumont-security_ive-been-assisting-a-few-orgs-hit-with-successful-activity-7268055739116445701-xxjZ/","https://x.com/cyb3rops/status/1862406110365245506","https://learn.microsoft.com/en-us/windows/client-management/client-tools/quick-assist"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/process_creation/proc_creation_win_quickassist_execution.yml","techniques":["T1219.002"],"cves":[]},{"id":"f9b3edc5-3322-4fc7-8aa3-245d646cc4b7","title":"Potential Linux Amazon SSM Agent Hijacking","author":"Muhammad Faisal","status":"test","level":"medium","date":"2023-08-03","modified":null,"description":"Detects potential Amazon SSM agent hijack attempts as outlined in the Mitiga research report.","references":["https://www.mitiga.io/blog/mitiga-security-advisory-abusing-the-ssm-agent-as-a-remote-access-trojan","https://www.bleepingcomputer.com/news/security/amazons-aws-ssm-agent-can-be-used-as-post-exploitation-rat-malware/","https://www.helpnetsecurity.com/2023/08/02/aws-instances-attackers-access/"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.command-and-control","attack.persistence","attack.t1219.002"],"path":"rules/linux/process_creation/proc_creation_lnx_ssm_agent_abuse.yml","techniques":["T1219.002"],"cves":[]},{"id":"fec96f39-988b-4586-b746-b93d59fd1922","title":"ScreenConnect Temporary Installation Artefact","author":"frack113","status":"test","level":"medium","date":"2022-02-13","modified":null,"description":"An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks.\nThese services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment.\nRemote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1219/T1219.md#atomic-test-5---screenconnect-application-download-and-install-on-windows"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.command-and-control","attack.t1219.002"],"path":"rules/windows/file/file_event/file_event_win_remote_access_tools_screenconnect_artefact.yml","techniques":["T1219.002"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}