Cross-source coverage

T1219.002 / ATT&CK

Remote Access Tools: Remote Desktop Software

53 rules across 2 sources.

From MITRE ATT&CK 19.2

An adversary may use legitimate desktop support software to establish an interactive command and control channel to target systems within networks. Desktop support software provides a graphical interface for remotely controlling another computer, transmitting the display output, keyboard input, and mouse control between devices using various protocols. Desktop support software, such as VNC, Team Viewer, AnyDesk, ScreenConnect, LogMein, AmmyyAdmin, and other remote monitoring and management (RMM) tools, are commonly used as legitimate technical support software and may be allowed by application control within a target environment.

Remote access modules/features may also exist as part of otherwise existing software such as Zoom or Google Chrome’s Remote Desktop.

Platforms
Linux · macOS · Windows
Telemetry
WinEventLog:SysmonWinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewallauditd:SYSCALLNSM:Flowmacos:unifiedlog

How MITRE says to detect it DET0259

Remote Desktop Software Execution and Beaconing Detection

Windows Analytic 0714

Adversary installation or use of RMM software (e.g., TeamViewer, AnyDesk, ScreenConnect) followed by outbound beaconing or remote session establishment

  • WinEventLog:Sysmon EventCode=11
  • WinEventLog:Sysmon EventCode=3, 22
  • WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall new rule allowing inbound or outbound connections for remote desktop software

Linux Analytic 0715

Execution of known or custom VNC/remote desktop daemons or tunneling agents that initiate external communication after launch

  • auditd:SYSCALL execve
  • NSM:Flow outbound connections to RMM services or to unusual destination ports

macOS Analytic 0716

Initiation of remote desktop sessions via AnyDesk, TeamViewer, or Chrome Remote Desktop accompanied by unexpected user logins or system modifications

  • macos:unifiedlog launch of remote desktop app or helper binary
  • macos:unifiedlog network sessions initiated by remote desktop apps

SigmaHQ/sigma

46 rules
Detection Severity Format
Antivirus - APT Malware Signature Critical Sigma
Antivirus - Exploitation Framework Signature Critical Sigma
Antivirus - Remote Access Tools Signature Critical Sigma
HackTool - Inveigh Execution Artefacts Critical Sigma
Atera Agent Installation High Sigma
HackTool - RemoteKrbRelay SMB Relay Secrets Dump Module Indicators High Sigma
Hijack Legit RDP Session to Move Laterally High Sigma
Potential CSharp Streamer RAT Loading .NET Executable Image High Sigma
Potential SocGholish Second Stage C2 DNS Query High Sigma
Remote Access Tool - Anydesk Execution From Suspicious Folder High Sigma

+ 36 more from SigmaHQ/sigma → showing the 10 highest-severity

elastic/detection-rules

7 rules
Detection Severity Format
Newly Observed ScreenConnect Host Server High Elastic TOML
First Time Seen DNS Query to RMM Domain Medium Elastic TOML
First Time Seen Remote Monitoring and Management Tool Medium Elastic TOML
First Time Seen RMM Signer Across the Environment Medium Elastic TOML
Multiple Remote Management Tool Vendors on Same Host Medium Elastic TOML
Remote Management Access Launch After MSI Install Medium Elastic TOML
Suspicious Shell Execution via Velociraptor Medium Elastic TOML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.