Remote Management and Monitoring tool - ZohoAssist - Network Connection


Description

Remote Monitoring and Management (RMM) programs are IT to manage remote endpoints. Attackers have begun to abuse these programs to persist or provide C2 channels. https://github.com/jischell-msft/RemoteManagementMonitoringTools

Query · kql

let Time_start = now(-5d);
let Time_end = now();
//
DeviceNetworkEvents
| where Timestamp between (Time_start..Time_end)
| where RemoteUrl has_any (
        'assist.zoho.com',			
        'assist.zoho.eu',			
        'assist.zoho.com.au',		
        'assist.zoho.in',			
        'assist.zoho.jp', 			
        'assist.zoho.uk',			
        'assistlab.zoho.com',		
        'downloads.zohocdn.com',	
        'download-accl.zoho.in',	
        'zohoassist.com',			
        'zohopublic.com',			
        'zohopublic.eu',			
        'meeting.zoho.com',			
        'meeting.zoho.eu', 			
        'static.zohocdn.com',		
        'zohodl.com.cn',			
        'zohowebstatic.com',		
        'zohostatic.in'		
    )
    and InitiatingProcessVersionInfoCompanyName has 'Zoho'
    and InitiatingProcessVersionInfoProductName has 'Zoho Assist'
| summarize FirstSeen=min(Timestamp), LastSeen=max(Timestamp), 
    Report=make_set(ReportId), Count=count() by DeviceId, DeviceName,
    RemoteUrl
Raw source Remote Management and Monitoring tool - ZohoAssist - Network Connection · KQL
Esc
Published by Azure/Azure-Sentinel ↗, licensed under MIT ↗. Reproduced here unmodified.
id: b915897c-1fe7-47f4-9e06-2ae74da8203e
name: Remote Management and Monitoring tool - ZohoAssist - Network Connection
description: |
    Remote Monitoring and Management (RMM) programs are IT to manage remote endpoints. Attackers have begun to abuse these programs to persist or provide C2 channels.
    https://github.com/jischell-msft/RemoteManagementMonitoringTools
requiredDataConnectors:
- connectorId: MicrosoftThreatProtection
  dataTypes:
  - DeviceNetworkEvents
tactics: CommandAndControl
relevantTechniques: T1219
query: |
  let Time_start = now(-5d);
  let Time_end = now();
  //
  DeviceNetworkEvents
  | where Timestamp between (Time_start..Time_end)
  | where RemoteUrl has_any (
          'assist.zoho.com',			
          'assist.zoho.eu',			
          'assist.zoho.com.au',		
          'assist.zoho.in',			
          'assist.zoho.jp', 			
          'assist.zoho.uk',			
          'assistlab.zoho.com',		
          'downloads.zohocdn.com',	
          'download-accl.zoho.in',	
          'zohoassist.com',			
          'zohopublic.com',			
          'zohopublic.eu',			
          'meeting.zoho.com',			
          'meeting.zoho.eu', 			
          'static.zohocdn.com',		
          'zohodl.com.cn',			
          'zohowebstatic.com',		
          'zohostatic.in'		
      )
      and InitiatingProcessVersionInfoCompanyName has 'Zoho'
      and InitiatingProcessVersionInfoProductName has 'Zoho Assist'
  | summarize FirstSeen=min(Timestamp), LastSeen=max(Timestamp), 
      Report=make_set(ReportId), Count=count() by DeviceId, DeviceName,
      RemoteUrl 

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.