EXPLORE
← Back to Explore
T1219

Remote Access Tools

An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line int...

LinuxmacOSWindows
33
Detections
3
Sources
13
Threat Actors

BY SOURCE

15elastic12splunk_escu6sigma

PROCEDURES (24)

Exfiltrat3 detections

Auto-extracted: 3 detections for exfiltrat

Network Connection Monitoring3 detections

Auto-extracted: 3 detections for network connection monitoring

Tunnel2 detections

Auto-extracted: 2 detections for tunnel

Dns2 detections

Auto-extracted: 2 detections for dns

General Monitoring2 detections

Auto-extracted: 2 detections for general monitoring

Service Monitoring2 detections

Auto-extracted: 2 detections for service monitoring

Download2 detections

Auto-extracted: 2 detections for download

C21 detections

Auto-extracted: 1 detections for c2

Lateral1 detections

Auto-extracted: 1 detections for lateral

Registry1 detections

Auto-extracted: 1 detections for registry

Tunnel1 detections

Auto-extracted: 1 detections for tunnel

Service1 detections

Auto-extracted: 1 detections for service

Process Creation Monitoring1 detections

Auto-extracted: 1 detections for process creation monitoring

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

Powershell1 detections

Auto-extracted: 1 detections for powershell

Module Load Monitoring1 detections

Auto-extracted: 1 detections for module load monitoring

Tunnel1 detections

Auto-extracted: 1 detections for tunnel

Registry1 detections

Auto-extracted: 1 detections for registry

Lateral1 detections

Auto-extracted: 1 detections for lateral

Persist1 detections

Auto-extracted: 1 detections for persist

Persist1 detections

Auto-extracted: 1 detections for persist

Exfiltrat1 detections

Auto-extracted: 1 detections for exfiltrat

Persist1 detections

Auto-extracted: 1 detections for persist

C21 detections

Auto-extracted: 1 detections for c2

DETECTIONS (33)

Attempt to Establish VScode Remote Tunnel
elasticmedium
Cisco Secure Firewall - Communication Over Suspicious Ports
splunk_escu
Cisco Secure Firewall - Remote Access Software Usage Traffic
splunk_escu
Detect Remote Access Software Usage DNS
splunk_escu
Detect Remote Access Software Usage File
splunk_escu
Detect Remote Access Software Usage FileInfo
splunk_escu
Detect Remote Access Software Usage Process
splunk_escu
Detect Remote Access Software Usage Registry
splunk_escu
Detect Remote Access Software Usage Traffic
splunk_escu
Detect Remote Access Software Usage URL
splunk_escu
First Time Seen DNS Query to RMM Domain
elasticmedium
First Time Seen Remote Monitoring and Management Tool
elasticmedium
HTTP RMM User Agent
splunk_escu
Multiple Remote Management Tool Vendors on Same Host
elasticmedium
NetSupport Manager Execution from an Unusual Path
elastichigh
Newly Observed ScreenConnect Host Server
elastichigh
OpenEDR Spawning Command Shell
sigmamedium
Potential REMCOS Trojan Execution
elastichigh
Potential Traffic Tunneling using QEMU
elasticmedium
Potentially Suspicious File Creation by OpenEDR's ITSMService
sigmamedium
Remote Access Tool - TacticalRMM Agent Registration to Potentially Attacker-Controlled Server
sigmamedium
Remote File Copy via TeamViewer
elasticmedium
Remote GitHub Actions Runner Registration
elasticmedium
Remote Management Access Launch After MSI Install
elasticmedium
Renamed Visual Studio Code Tunnel Execution
sigmahigh
Suspicious ScreenConnect Client Child Process
elasticmedium
Suspicious Shell Execution via Velociraptor
elasticmedium
Suspicious Velociraptor Child Process
sigmahigh
Visual Studio Code Tunnel Execution
sigmamedium
VNC (Virtual Network Computing) from the Internet
elastichigh
VNC (Virtual Network Computing) to the Internet
elasticmedium
Windows Remote Access Software BRC4 Loaded Dll
splunk_escu
Windows Remote Access Software RMS Registry
splunk_escu