Remote Management and Monitoring tool - MSP360_CloudBerry - Create Process


Description

Remote Monitoring and Management (RMM) programs are IT to manage remote endpoints. Attackers have begun to abuse these programs to persist or provide C2 channels. https://github.com/jischell-msft/RemoteManagementMonitoringTools

Query · kql

let Time_start = now(-5d);
let Time_end = now();
//
DeviceProcessEvents 
| where Timestamp between (Time_start..Time_end)
| where ProcessVersionInfoCompanyName has_any (
        'CloudBerry',
        'MSP360'
    )
    and ProcessVersionInfoProductName has_any (
        'RMM',
        'Remote',
        'Connect',
        'Cloud.Ra',
        'RM Service'
    )
| summarize FirstSeen=min(Timestamp), LastSeen=max(Timestamp), 
    Report=make_set(ReportId), Count=count() by DeviceId, DeviceName
Raw source Remote Management and Monitoring tool - MSP360_CloudBerry - Create Process · KQL
Esc
Published by Azure/Azure-Sentinel ↗, licensed under MIT ↗. Reproduced here unmodified.
id: 2ed71614-0c21-4a41-962a-386234d5d000
name: Remote Management and Monitoring tool - MSP360_CloudBerry - Create Process
description: |
    Remote Monitoring and Management (RMM) programs are IT to manage remote endpoints. Attackers have begun to abuse these programs to persist or provide C2 channels.
    https://github.com/jischell-msft/RemoteManagementMonitoringTools
requiredDataConnectors:
- connectorId: MicrosoftThreatProtection
  dataTypes:
  - DeviceProcessEvents
tactics: CommandAndControl
relevantTechniques: T1219
query: |
  let Time_start = now(-5d);
  let Time_end = now();
  //
  DeviceProcessEvents 
  | where Timestamp between (Time_start..Time_end)
  | where ProcessVersionInfoCompanyName has_any (
          'CloudBerry',
          'MSP360'
      )
      and ProcessVersionInfoProductName has_any (
          'RMM',
          'Remote',
          'Connect',
          'Cloud.Ra',
          'RM Service'
      )
  | summarize FirstSeen=min(Timestamp), LastSeen=max(Timestamp), 
      Report=make_set(ReportId), Count=count() by DeviceId, DeviceName

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.