Cross-source coverage
T1219.002 / ATT&CK
Remote Access Tools: Remote Desktop Software
53 rules across 2 sources.
From MITRE ATT&CK 19.2
An adversary may use legitimate desktop support software to establish an interactive command and control channel to target systems within networks. Desktop support software provides a graphical interface for remotely controlling another computer, transmitting the display output, keyboard input, and mouse control between devices using various protocols. Desktop support software, such as VNC, Team Viewer, AnyDesk, ScreenConnect, LogMein, AmmyyAdmin, and other remote monitoring and management (RMM) tools, are commonly used as legitimate technical support software and may be allowed by application control within a target environment.
Remote access modules/features may also exist as part of otherwise existing software such as Zoom or Google Chrome’s Remote Desktop.
- Tactics
- Command and Control
- Platforms
- Linux · macOS · Windows
- Telemetry
-
WinEventLog:SysmonWinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewallauditd:SYSCALLNSM:Flowmacos:unifiedlog
How MITRE says to detect it DET0259
Remote Desktop Software Execution and Beaconing Detection
Windows Analytic 0714
Adversary installation or use of RMM software (e.g., TeamViewer, AnyDesk, ScreenConnect) followed by outbound beaconing or remote session establishment
WinEventLog:SysmonEventCode=11WinEventLog:SysmonEventCode=3, 22WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewallnew rule allowing inbound or outbound connections for remote desktop software
Linux Analytic 0715
Execution of known or custom VNC/remote desktop daemons or tunneling agents that initiate external communication after launch
auditd:SYSCALLexecveNSM:Flowoutbound connections to RMM services or to unusual destination ports
macOS Analytic 0716
Initiation of remote desktop sessions via AnyDesk, TeamViewer, or Chrome Remote Desktop accompanied by unexpected user logins or system modifications
macos:unifiedloglaunch of remote desktop app or helper binarymacos:unifiedlognetwork sessions initiated by remote desktop apps
SigmaHQ/sigma
46 rules| Detection | Severity | Format |
|---|---|---|
| Antivirus - APT Malware Signature | Critical | Sigma |
| Antivirus - Exploitation Framework Signature | Critical | Sigma |
| Antivirus - Remote Access Tools Signature | Critical | Sigma |
| HackTool - Inveigh Execution Artefacts | Critical | Sigma |
| Atera Agent Installation | High | Sigma |
| HackTool - RemoteKrbRelay SMB Relay Secrets Dump Module Indicators | High | Sigma |
| Hijack Legit RDP Session to Move Laterally | High | Sigma |
| Potential CSharp Streamer RAT Loading .NET Executable Image | High | Sigma |
| Potential SocGholish Second Stage C2 DNS Query | High | Sigma |
| Remote Access Tool - Anydesk Execution From Suspicious Folder | High | Sigma |
+ 36 more from SigmaHQ/sigma → showing the 10 highest-severity
elastic/detection-rules
7 rules| Detection | Severity | Format |
|---|---|---|
| Newly Observed ScreenConnect Host Server | High | Elastic TOML |
| First Time Seen DNS Query to RMM Domain | Medium | Elastic TOML |
| First Time Seen Remote Monitoring and Management Tool | Medium | Elastic TOML |
| First Time Seen RMM Signer Across the Environment | Medium | Elastic TOML |
| Multiple Remote Management Tool Vendors on Same Host | Medium | Elastic TOML |
| Remote Management Access Launch After MSI Install | Medium | Elastic TOML |
| Suspicious Shell Execution via Velociraptor | Medium | Elastic TOML |