Cross-source coverage

T1219 / ATT&CK

Remote Access Tools

291 rules · 290 families across 10 sources.

256 atomic-IOC hidden · include

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.

Remote access tools may be installed and used post-compromise as an alternate communications channel for redundant access or to establish an interactive remote desktop session with the target system. It may also be used as a malware component to establish a reverse connection or back-connect to a service or adversary-controlled system.

Installation of many remote access tools may also include persistence (e.g., the software's installation routine creates a Windows Service). Remote access modules/features may also exist as part of otherwise existing software (e.g., Google Chrome’s Remote Desktop).

Platforms
Linux · macOS · Windows
Telemetry
WinEventLog:SysmonWinEventLog:Systemauditd:SYSCALLauditd:PATHmacos:unifiedlogmacos:osquery

How MITRE says to detect it DET0496

Behavior-Chain Detection for Remote Access Tools (Tool-Agnostic)

Windows Analytic 1366

Chain of remote access tool behavior: (1) initial execution of remote-control/assist agent or GUI under user context; (2) persistence via service or autorun; (3) long-lived outbound connection/tunnel to external infrastructure; (4) interactive control signals such as shell or file-manager child processes spawned by the RAT parent.

  • WinEventLog:Sysmon EventCode=1
  • WinEventLog:System EventCode=7045
  • WinEventLog:Sysmon EventCode=12
  • WinEventLog:Sysmon EventCode=13, 14
  • WinEventLog:Sysmon EventCode=11
  • WinEventLog:Sysmon EventCode=3, 22

Linux Analytic 1367

Sequence of RAT agent execution, systemd persistence, and long-lived external egress; optional interactive shells spawned from the agent.

  • auditd:SYSCALL execve: Agent/headless flags (listen/connect/reverse/tunnel) or remote-control binaries spawning shells
  • auditd:PATH WRITE: Drop of binaries/scripts in ~/.local, /tmp, or /opt tool dirs
  • WinEventLog:Sysmon EventCode=3, 22

macOS Analytic 1368

Electron/GUI or headless RAT execution followed by LaunchAgent/Daemon persistence and persistent external connections; interactive children (osascript/sh/curl) spawned by parent.

  • macos:unifiedlog Process exec of remote-control apps or binaries with headless/connect flags
  • macos:osquery CREATE/MODIFY: Creation of LaunchAgents/Daemons plists in user/system locations
  • macos:osquery CONNECT: Long-lived connections from remote-control parents to external IPs/domains

Sub-techniques with coverage

Counted in the 291 above — a rule tagged a sub-technique covers this technique too.


Azure/Azure-Sentinel

160 rules
Detection Severity Format
Hunt for RMM tool execution following Teams messages Undefined KQL
Remote Management and Monitoring tool - AeroAdmin - Create Process Undefined KQL
Remote Management and Monitoring tool - AeroAdmin - File Signature Undefined KQL
Remote Management and Monitoring tool - All Tools - Network Connection Undefined KQL
Remote Management and Monitoring tool - Ammyy - Create Process Undefined KQL
Remote Management and Monitoring tool - Ammyy - File Signature Undefined KQL
Remote Management and Monitoring tool - Ammyy - Network Connection Undefined KQL
Remote Management and Monitoring tool - AnyDesk - Create Process Undefined KQL
Remote Management and Monitoring tool - AnyDesk - File Signature Undefined KQL
Remote Management and Monitoring tool - AnyDesk - Network Connection Undefined KQL

+ 150 more from Azure/Azure-Sentinel → showing the 10 highest-severity

SigmaHQ/sigma

52 rules
Detection Severity Format
Antivirus - APT Malware Signature Critical Sigma
Antivirus - Exploitation Framework Signature Critical Sigma
Antivirus - Remote Access Tools Signature Critical Sigma
HackTool - Inveigh Execution Artefacts Critical Sigma
Atera Agent Installation High Sigma
HackTool - RemoteKrbRelay SMB Relay Secrets Dump Module Indicators High Sigma
Hijack Legit RDP Session to Move Laterally High Sigma
Potential CSharp Streamer RAT Loading .NET Executable Image High Sigma
Potential SocGholish Second Stage C2 DNS Query High Sigma
Remote Access Tool - Anydesk Execution From Suspicious Folder High Sigma

+ 42 more from SigmaHQ/sigma → showing the 10 highest-severity

Emerging Threats Open

28 rules · 27 families
Detection Severity Format
ET MALWARE iMonitor EAM CnC Agent Request (AGENTALARM) Critical Suricata
ET MALWARE iMonitor EAM CnC Agent Request (AGENTCONN) Critical Suricata
ET MALWARE iMonitor EAM CnC Agent Request (AGENTINFOM) Critical Suricata
ET MALWARE iMonitor EAM CnC Agent Request (*FILEAGENTD*) Critical Suricata
ET MALWARE iMonitor EAM CnC Agent Request (*FILEHEADER*) Critical Suricata
ET MALWARE iMonitor EAM CnC Server Response (DEVNLOADCLIENT) Critical Suricata
ET MALWARE iMonitor EAM CnC Server Response (RDPBEEND) Critical Suricata
ET MALWARE iMonitor EAM CnC Server Response (*TRANSFBEGIN*) Critical Suricata
ET MALWARE iMonitor EAM CnC Server Response (*TRANSFDATA*) Critical Suricata
ET INFO Dameware Mini Remote Control Session Initiation Sequence M2 Informational Suricata

+ 18 more from Emerging Threats Open → showing the 10 highest-severity

elastic/detection-rules

19 rules
Detection Severity Format
NetSupport Manager Execution from an Unusual Path High Elastic TOML
Newly Observed ScreenConnect Host Server High Elastic TOML
Potential REMCOS Trojan Execution High Elastic TOML
VNC (Virtual Network Computing) from the Internet High Elastic TOML
Attempt to Establish VScode Remote Tunnel Medium Elastic TOML
First Time Seen DNS Query to RMM Domain Medium Elastic TOML
First Time Seen Remote Monitoring and Management Tool Medium Elastic TOML
First Time Seen RMM Signer Across the Environment Medium Elastic TOML
Multiple Remote Management Tool Vendors on Same Host Medium Elastic TOML
Potential Traffic Tunneling using QEMU Medium Elastic TOML

+ 9 more from elastic/detection-rules → showing the 10 highest-severity

splunk/security_content

15 rules
Detection Severity Format
Cisco Secure Firewall - Communication Over Suspicious Ports Undefined SPL
Cisco Secure Firewall - Remote Access Software Usage Traffic Undefined SPL
Detect Remote Access Software Usage DNS Undefined SPL
Detect Remote Access Software Usage File Undefined SPL
Detect Remote Access Software Usage FileInfo Undefined SPL
Detect Remote Access Software Usage Process Undefined SPL
Detect Remote Access Software Usage Registry Undefined SPL
Detect Remote Access Software Usage Traffic Undefined SPL
Detect Remote Access Software Usage URL Undefined SPL
HTTP RMM User Agent Undefined SPL

+ 5 more from splunk/security_content → showing the 10 highest-severity

Bert-JanP/Hunting-Queries-Detection-Rules

5 rules
Detection Severity Format
Detect when AnyDesk makes a remote connection Undefined KQL
*Known RAT/RMM process patterns* Undefined KQL
MITRE ATT&CK Mapping Undefined KQL
RMM Tools with connections Undefined KQL
TTP Detection Rule: NetSupport running from unexpected directory (FIN7) Undefined KQL

elastic/protections-artifacts

5 rules
Detection Severity Format
NetSupport Execution form unusual Path Undefined Elastic TOML
Potential PlugX Registry Modification Undefined Elastic TOML
Suspicious DNS Lookup by Remote Utilities RMM Undefined Elastic TOML
Suspicious NetSupport Execution Undefined Elastic TOML
Velociraptor Suspicious Shell Execution Undefined Elastic TOML

chronicle/detection-rules

4 rules
Detection Severity Format
gcti_remote_access_tools High YARA-L
win_pua_detection_of_uncommon_rmm Medium YARA-L
antivirus_exploitation_framework_detection Undefined YARA-L
guildma_malware_detector_sysmon_behavior Undefined YARA-L

socfortress/Wazuh-Rules

2 rules
Detection Severity Format
Sysmon - Event 1: Process creation · PowerShell Download of RAT Tool (T1219) High Wazuh XML
Sysmon - Event 1: Process creation · Remote Access Tool Execution (T1219) High Wazuh XML

panther-labs/panther-analysis

1 rule
Detection Severity Format
Crowdstrike Remote Access Tool Execution Informational Panther Python

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.