kevmap

TechniquesT1219 › T1219.002

T1219.002 Remote Desktop Software

command and control — Linux, macOS, Windows · attack.mitre.org · JSON

1
MITRE detection strategy
3
analytics
46
Sigma rules tagged attack.t1219.002
0
KEV CVEs mapped here
<p>An adversary may use legitimate desktop support software to establish an interactive command and control channel to target systems within networks. Desktop support software provides a graphical interface for remotely controlling another computer, transmitting the display output, keyboard input, and mouse control between devices using various protocols. Desktop support software, such as VNC, Team Viewer, AnyDesk, ScreenConnect, LogMein, AmmyyAdmin, and other remote monitoring and management (RMM) tools, are commonly used as legitimate technical support software and may be allowed by application control within a target environment.</p><p>Remote access modules/features may also exist as part of otherwise existing software such as Zoom or Google Chrome’s Remote Desktop.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1219.002

Author: Florian Roth (Nextron Systems) · 2022-05-20 (modified 2025-02-24) · logsource: product=windows category=process_creation · 065b00ca-5d5c-4557-ac95-64a6d0b64d86
An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
Techniques: T1219.002
Author: frack113 · 2022-02-11 (modified 2024-07-20) · logsource: product=windows category=file_event · 0b9ad457-2554-44c1-82c2-d56a99c42377
An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
Techniques: T1219.002
Author: Arnim Rupp (Nextron Systems) · 2026-06-15 · logsource: category=antivirus · 101a1877-2cf4-474d-abfd-7f6ac4788d1a
Detects a highly relevant Antivirus alert that reports APT malware. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
Techniques: T1203T1219.002
Author: Ján Trenčanský · 2021-08-06 (modified 2023-03-05) · logsource: product=windows category=process_creation · 114e7f1c-f137-48c8-8f54-3088c24ce4b9
Detects AnyDesk Remote Desktop silent installation. Which can be used by attackers to gain remote access.
Techniques: T1219.002
Author: frack113 · 2022-10-02 · logsource: product=windows category=process_creation · 145322e4-0fd3-486b-81ca-9addc75736d8
An adversary may use legitimate desktop support and remote access software,to establish an interactive command and control channel to target systems within networks
Techniques: T1219.002
Author: Florian Roth (Nextron Systems) · 2022-01-30 · logsource: product=windows category=file_event · 162ab1e4-6874-4564-853c-53ec3ab8be01
Detects the creation of log files during a TeamViewer remote session
Techniques: T1219.002
Author: Norbert Jaśniewicz (AlphaSOC) · 2025-05-19 · logsource: product=macos category=process_creation · 22c45af6-f590-4d44-bab3-b5b2d2a2b6d9
Detects potential execution of MeshAgent which is a tool used for remote access. Historical data shows that threat actors rename MeshAgent binary to evade detection. Matching command lines with the '--meshServiceName' argument can indicate that the MeshAgent is being used for remote access.
Techniques: T1219.002
Author: Florian Roth (Nextron Systems), Arnim Rupp · 2018-09-09 (modified 2026-06-15) · logsource: category=antivirus · 238527ad-3c2c-4e4f-a1f6-92fd63adb864
Detects a highly relevant Antivirus alert that reports an exploitation framework. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
Techniques: T1203T1219.002
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-09-28 (modified 2025-02-24) · logsource: product=windows category=file_event · 2d367498-5112-4ae5-a06a-96e7bc33a211
Detects AnyDesk writing binary files to disk other than "gcapi.dll". According to RedCanary research it is highly abnormal for AnyDesk to write executable files to disk besides gcapi.dll, which is a legitimate DLL that is part of the Google Chrome web browser used to interact with the Google Cloud API. (See reference section for more details)
Techniques: T1219.002
Author: Norbert Jaśniewicz (AlphaSOC) · 2025-05-19 · logsource: product=windows category=process_creation · 2fbbe9ff-0afc-470b-bdc0-592198339968
Detects potential execution of MeshAgent which is a tool used for remote access. Historical data shows that threat actors rename MeshAgent binary to evade detection. Matching command lines with the '--meshServiceName' argument can indicate that the MeshAgent is being used for remote access.
Techniques: T1219.002
Author: Nasreddine Bencherchali (Nextron Systems) · 2024-06-27 · logsource: product=windows category=file_event · 3ab79e90-9fab-4cdf-a7b2-6522bc742adb
Detects the creation of file with specific names used by RemoteKrbRelay SMB Relay attack module.
Techniques: T1219.002
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-11-28 · logsource: product=windows service=system · 4bb79b62-ef12-4861-981d-2aab43fab642
Detects a TacticalRMM service installation. Tactical RMM is a remote monitoring & management tool.
Techniques: T1219.002
Author: frack113, Connor Martin · 2022-07-11 (modified 2024-12-17) · logsource: product=windows category=dns_query · 4d07b1f4-cb00-4470-b9f8-b0191d48ff52
An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
Techniques: T1219.002
Author: Samir Bousseaden · 2019-02-21 (modified 2021-11-27) · logsource: product=windows category=file_event · 52753ea4-b3a0-4365-910d-36cff487b789
Detects the usage of tsclient share to place a backdoor on the RDP source machine's startup folder
Techniques: T1219.002
Author: frack113 · 2022-02-13 (modified 2023-03-05) · logsource: product=windows category=process_creation · 57bff678-25d1-4d6c-8211-8ca106d12053
An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
Techniques: T1219.002
Author: frack113 · 2022-02-13 · logsource: product=windows category=file_event · 5d756aee-ad3e-4306-ad95-cb1abec48de2
An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
Techniques: T1219.002
Author: Nasreddine Bencherchali (Nextron Systems), Christopher Peacock @securepeacock · 2023-04-18 (modified 2023-04-30) · logsource: product=windows category=process_creation · 5fdce3ac-e7f9-4ecd-a3aa-a4d78ebbf0af
Detects potential RDP connection via Mstsc using a local ".rdp" file
Techniques: T1219.002
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-04-18 · logsource: product=windows category=process_creation · 6e22722b-dfb1-4508-a911-49ac840b40f8
Detects potential RDP connection via Mstsc using a local ".rdp" file located in suspicious locations.
Techniques: T1219.002
Author: Luca Di Bartolomeo · 2024-06-22 · logsource: product=windows category=image_load · 6f6afac3-8e7a-4e4b-9588-2608ffe08f82
Detects potential CSharp Streamer RAT loading .NET executable image by using the default file name and path associated with the tool.
Techniques: T1219.002
Author: Dusty Miller · 2023-02-23 · logsource: product=windows category=dns_query · 70761fe8-6aa2-4f80-98c1-a57049c08e66
Detects a DNS query initiated from a "wscript" process for domains matching a specific pattern that was seen being used by SocGholish for its Command and Control traffic
Techniques: T1219.002
Author: @Kostastsale · 2024-09-22 · logsource: product=windows category=process_creation · 74a2b202-73e0-4693-9a3a-9d36146d0775
Detects the use of MeshAgent to execute commands on the target host, particularly when threat actors might abuse it to execute commands directly. MeshAgent can execute commands on the target host by leveraging win-console to obscure their activities and win-dispatcher to run malicious code through IPC with child processes.
Techniques: T1219.002
Author: frack113 · 2022-09-25 (modified 2023-03-06) · logsource: product=windows category=process_creation · 758ff488-18d5-4cbe-8ec4-02b6285a434f
An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
Techniques: T1219.002
Author: Florian Roth (Nextron Systems) · 2022-01-30 (modified 2023-09-18) · logsource: product=windows category=dns_query · 778ba9a8-45e4-4b80-8e3e-34a419f0b85e
Detects DNS queries to a TeamViewer domain only resolved by a TeamViewer client by an image that isn't named TeamViewer (sometimes used by threat actors for obfuscation)
Techniques: T1219.002
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), @Kostastsale · 2022-02-25 (modified 2024-02-28) · logsource: product=windows category=process_creation · 7b582f1a-b318-4c6a-bf4e-66fe49bf55a5
Detects potentially suspicious child processes launched via the ScreenConnect client service.
Techniques: T1219.002
Author: Bhabesh Raj · 2021-09-01 (modified 2022-12-25) · logsource: product=windows service=application · 87261fb2-69d0-42fe-b9de-88c6b5f65a43
Detects successful installation of Atera Remote Monitoring & Management (RMM) agent as recently found to be used by Conti operators
Techniques: T1219.002
Author: frack113 · 2022-09-25 (modified 2024-03-14) · logsource: product=windows category=process_creation · 88656cec-6c3b-487c-82c0-f73ebb805503
An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
Techniques: T1219.002
Author: Nasreddine Bencherchali (Nextron Systems) · 2024-02-23 · logsource: product=windows category=process_creation · 95e60a2b-4705-444b-b7da-ba0ea81a3ee2
An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
Techniques: T1219.002
Author: frack113 · 2022-01-28 · logsource: product=windows category=file_event · 9711de76-5d4f-4c50-a94f-21e4e8f8384d
TeamViewer_Desktop.exe is create during install
Techniques: T1219.002
Author: Arnim Rupp (Nextron Systems) · 2026-06-15 · logsource: category=antivirus · 97233998-3838-4581-88c6-f1d19d3993fb
Detects a highly relevant Antivirus alert that reports a remote access tool. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
Techniques: T1203T1219.002
Author: Florian Roth (Nextron Systems) · 2018-03-17 (modified 2022-05-27) · logsource: product=windows category=process_creation · 9847f263-4a81-424f-970c-875dab15b79b
Detects a tscon.exe start as LOCAL SYSTEM
Techniques: T1219.002
Author: @kostastsale · 2023-04-13 · logsource: product=windows category=process_creation · aa3168fb-d594-4f93-a92d-7a9ba675b766
Detects the execution of Action1 in order to execute arbitrary code or establish a remote session. Action1 is a powerful Remote Monitoring and Management tool that enables users to execute commands, scripts, and binaries. Through the web interface of action1, the administrator must create a new policy or an app to establish remote execution and then points that the agent is installed. Hunting Opportunity 1- Weed Out The Noise When threat actors execute a script, a command, or a binary through these new policies and apps, the names of these become visible in the command line during the execution process. Below is an example of the command line that contains the deployment of a binary through a policy with name "test_app_1": ParentCommandLine: "C:\WINDOWS\Action1\action1_agent.exe schedule:Deploy_App__test_app_1_1681327673425 runaction:0" After establishing a baseline, we can split the command to extract the policy name and group all the policy names and inspect the results with a list of frequency occurrences. Hunting Opportunity 2 - Remote Sessions On Out Of Office Hours If you have admins within your environment using remote sessions to administer endpoints, you can create a threat-hunting query and modify the time of the initiated sessions looking for abnormal activity.
Techniques: T1219.002
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-09-28 (modified 2023-03-05) · logsource: product=windows category=process_creation · b1377339-fda6-477a-b455-ac0923f9ec2c
Detects piping the password to an anydesk instance via CMD and the '--set-password' flag.
Techniques: T1219.002
Author: Norbert Jaśniewicz (AlphaSOC) · 2025-05-19 · logsource: product=windows category=process_creation · b471f462-eb0d-4832-be35-28d94bdb4780
Detects the execution of a renamed instance of the Remote Monitoring and Management (RMM) tool, MeshAgent. RMM tools such as MeshAgent are commonly utilized by IT administrators for legitimate remote support and system management. However, malicious actors may exploit these tools by renaming them to bypass detection mechanisms, enabling unauthorized access and control over compromised systems.
Techniques: T1219.002T1036.003
Author: frack113 · 2022-02-11 (modified 2025-02-24) · logsource: product=windows category=process_creation · b52e84a3-029e-4529-b09b-71d19dd27e94
An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
Techniques: T1219.002
Author: frack113 · 2022-02-13 (modified 2023-03-05) · logsource: product=windows category=process_creation · b6d98a4f-cef0-4abf-bbf6-24132854a83d
An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
Techniques: T1219.002
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-10-24 (modified 2024-06-27) · logsource: product=windows category=file_event · bb09dd3e-2b78-4819-8e35-a7c1b874e449
Detects the presence and execution of Inveigh via dropped artefacts
Techniques: T1219.002
Author: Norbert Jaśniewicz (AlphaSOC) · 2025-05-19 · logsource: product=macos category=process_creation · bd3b5eaa-439d-4a42-8f35-a49f5c8a2582
Detects the execution of a renamed instance of the Remote Monitoring and Management (RMM) tool, MeshAgent. RMM tools such as MeshAgent are commonly utilized by IT administrators for legitimate remote support and system management. However, malicious actors may exploit these tools by renaming them to bypass detection mechanisms, enabling unauthorized access and control over compromised systems.
Techniques: T1219.002T1036.003
Author: James Pemberton · 2020-05-22 (modified 2021-11-27) · logsource: product=windows service=ntlm · ce5678bb-b9aa-4fb5-be4b-e57f686256ad
Detects logons using NTLM to hosts that are potentially not part of the domain.
Techniques: T1219.002
Author: Muhammad Faisal · 2023-08-02 · logsource: product=windows category=process_creation · d20ee2f4-822c-4827-9e15-41500b1fff10
Detects potential Amazon SSM agent hijack attempts as outlined in the Mitiga research report.
Techniques: T1219.002
Author: @d4ns4n_ (Wuerth-Phoenix) · 2024-09-02 (modified 2025-02-24) · logsource: product=windows category=network_connection · d58ba5c6-0ed7-4b9d-a433-6878379efda9
Detects incoming connections to AnyDesk. This could indicate a potential remote attacker trying to connect to a listening instance of AnyDesk and use it as potential command and control channel.
Techniques: T1219.002
Author: frack113 · 2022-02-11 (modified 2023-03-05) · logsource: product=windows category=process_creation · d85873ef-a0f8-4c48-a53a-6b621f11729d
An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
Techniques: T1219.002
Author: Nasreddine Bencherchali (Nextron Systems) · 2024-06-24 · logsource: product=windows category=dns_query · e043f529-8514-4205-8ab0-7f7d2927b400
Detects a DNS query by a non browser process on the system to "azurewebsites.net". The latter was often used by threat actors as a malware hosting and exfiltration site.
Techniques: T1219.002
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-11-28 · logsource: product=windows service=system · e0d1ad53-c7eb-48ec-a87a-72393cc6cedc
Detects a Mesh Agent service installation. Mesh Agent is used to remotely manage computers
Techniques: T1219.002
QuickAssist Execution lowexperimental
Author: Muhammad Faisal (@faisalusuf) · 2024-12-19 · logsource: product=windows category=process_creation · e20b5b14-ce93-4230-88af-981983ef6e74
Detects the execution of Microsoft Quick Assist tool "QuickAssist.exe". This utility can be used by attackers to gain remote access.
Techniques: T1219.002
Author: Muhammad Faisal · 2023-08-03 · logsource: product=linux category=process_creation · f9b3edc5-3322-4fc7-8aa3-245d646cc4b7
Detects potential Amazon SSM agent hijack attempts as outlined in the Mitiga research report.
Techniques: T1219.002
Author: frack113 · 2022-02-13 · logsource: product=windows category=file_event · fec96f39-988b-4586-b746-b93d59fd1922
An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
Techniques: T1219.002

Rules tagged at the parent level (attack.t1219) 6

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Author: Nasreddine Bencherchali (Nextron Systems) · 2023-09-28 (modified 2025-10-29) · logsource: product=windows category=process_creation · 2cf29f11-e356-4f61-98c0-1bdb9393d6da
Detects renamed Visual Studio Code tunnel execution. Attackers can abuse this functionality to establish a C2 channel
Techniques: T1071.001T1219
Author: Ahmed Nosir (@egycondor) · 2025-05-29 · logsource: product=windows category=process_creation · 2db93a3f-3249-4f73-9e68-0e77a0f8ae7e
Detects TacticalRMM agent installations where the --api, --auth, and related flags are used on the command line. These parameters configure the agent to connect to a specific RMM server with authentication, client ID, and site ID. This technique could indicate a threat actor attempting to register the agent with an attacker-controlled RMM infrastructure silently.
Techniques: T1219T1105
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-08-29 · logsource: product=windows category=process_creation · 4bc90587-e6ca-4b41-be0b-ed4d04e4ed0c
Detects the suspicious use of the Velociraptor DFIR tool to execute other tools or download additional payloads, as seen in a campaign where it was abused for remote access and to stage further attacks.
Techniques: T1219
Author: @kostastsale · 2026-02-19 · logsource: product=windows category=process_creation · 7f3a9c2d-4e8b-4a7f-9d3e-5c6f8a9b2e1d
Detects the OpenEDR ssh-shellhost.exe spawning a command shell (cmd.exe) or PowerShell with PTY (pseudo-terminal) capabilities. This may indicate remote command execution through OpenEDR's remote management features, which could be legitimate administrative activity or potential abuse of the remote access tool. Threat actors may leverage OpenEDR's remote shell capabilities to execute commands on compromised systems, facilitating lateral movement or other command-and-control operations.
Author: Nasreddine Bencherchali (Nextron Systems), citron_ninja · 2023-10-25 (modified 2025-10-29) · logsource: product=windows category=process_creation · 90d6bd71-dffb-4989-8d86-a827fedd6624
Detects Visual Studio Code tunnel execution. Attackers can abuse this functionality to establish a C2 channel
Techniques: T1071.001T1219
Author: @kostastsale · 2026-02-19 · logsource: product=windows category=file_event · 9e4b7d3a-6f2c-4e9a-8d1b-3c5e7a9f2b4d
Detects the creation of potentially suspicious files by OpenEDR's ITSMService process. The ITSMService is responsible for remote management operations and can create files on the system through the Process Explorer or file management features. While legitimate for IT operations, creation of executable or script files could indicate unauthorized file uploads, data staging, or malicious file deployment.
Techniques: T1105T1570T1219