Cross-source coverage
T1219 / ATT&CK
Remote Access Tools
534 rules · 529 families across 10 sources.
13 deprecated hidden · include
Showing atomic-IOC rules · back to the default
From MITRE ATT&CK 19.2
An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.
Remote access tools may be installed and used post-compromise as an alternate communications channel for redundant access or to establish an interactive remote desktop session with the target system. It may also be used as a malware component to establish a reverse connection or back-connect to a service or adversary-controlled system.
Installation of many remote access tools may also include persistence (e.g., the software's installation routine creates a Windows Service). Remote access modules/features may also exist as part of otherwise existing software (e.g., Google Chrome’s Remote Desktop).
- Tactics
- Command and Control
- Platforms
- Linux · macOS · Windows
- Telemetry
-
WinEventLog:SysmonWinEventLog:Systemauditd:SYSCALLauditd:PATHmacos:unifiedlogmacos:osquery
How MITRE says to detect it DET0496
Behavior-Chain Detection for Remote Access Tools (Tool-Agnostic)
Windows Analytic 1366
Chain of remote access tool behavior: (1) initial execution of remote-control/assist agent or GUI under user context; (2) persistence via service or autorun; (3) long-lived outbound connection/tunnel to external infrastructure; (4) interactive control signals such as shell or file-manager child processes spawned by the RAT parent.
WinEventLog:SysmonEventCode=1WinEventLog:SystemEventCode=7045WinEventLog:SysmonEventCode=12WinEventLog:SysmonEventCode=13, 14WinEventLog:SysmonEventCode=11WinEventLog:SysmonEventCode=3, 22
Linux Analytic 1367
Sequence of RAT agent execution, systemd persistence, and long-lived external egress; optional interactive shells spawned from the agent.
auditd:SYSCALLexecve: Agent/headless flags (listen/connect/reverse/tunnel) or remote-control binaries spawning shellsauditd:PATHWRITE: Drop of binaries/scripts in ~/.local, /tmp, or /opt tool dirsWinEventLog:SysmonEventCode=3, 22
macOS Analytic 1368
Electron/GUI or headless RAT execution followed by LaunchAgent/Daemon persistence and persistent external connections; interactive children (osascript/sh/curl) spawned by parent.
macos:unifiedlogProcess exec of remote-control apps or binaries with headless/connect flagsmacos:osqueryCREATE/MODIFY: Creation of LaunchAgents/Daemons plists in user/system locationsmacos:osqueryCONNECT: Long-lived connections from remote-control parents to external IPs/domains
Sub-techniques with coverage
Counted in the 534 above — a rule tagged a sub-technique covers this technique too.
Emerging Threats Open
269 rules · 264 families| Detection | Severity | Format |
|---|---|---|
| ET MALWARE iMonitor EAM CnC Agent Request (AGENTALARM) | Critical | Suricata |
| ET MALWARE iMonitor EAM CnC Agent Request (AGENTCONN) | Critical | Suricata |
| ET MALWARE iMonitor EAM CnC Agent Request (AGENTINFOM) | Critical | Suricata |
| ET MALWARE iMonitor EAM CnC Agent Request (*FILEAGENTD*) | Critical | Suricata |
| ET MALWARE iMonitor EAM CnC Agent Request (*FILEHEADER*) | Critical | Suricata |
| ET MALWARE iMonitor EAM CnC Server Response (DEVNLOADCLIENT) | Critical | Suricata |
| ET MALWARE iMonitor EAM CnC Server Response (RDPBEEND) | Critical | Suricata |
| ET MALWARE iMonitor EAM CnC Server Response (*TRANSFBEGIN*) | Critical | Suricata |
| ET MALWARE iMonitor EAM CnC Server Response (*TRANSFDATA*) | Critical | Suricata |
| ET MALWARE Malicious SimpleHelp RMM Domain in DNS Lookup (funsunmexicobizz .top) | High | Suricata |
+ 259 more from Emerging Threats Open → showing the 10 highest-severity
Azure/Azure-Sentinel
164 rules| Detection | Severity | Format |
|---|---|---|
| Hunt for RMM tool execution following Teams messages | Undefined | KQL |
| Remote Management and Monitoring tool - AeroAdmin - Create Process | Undefined | KQL |
| Remote Management and Monitoring tool - AeroAdmin - File Signature | Undefined | KQL |
| Remote Management and Monitoring tool - AeroAdmin - Network Connection | Undefined | KQL |
| Remote Management and Monitoring tool - All Tools - Network Connection | Undefined | KQL |
| Remote Management and Monitoring tool - Ammyy - Create Process | Undefined | KQL |
| Remote Management and Monitoring tool - Ammyy - File Signature | Undefined | KQL |
| Remote Management and Monitoring tool - Ammyy - Network Connection | Undefined | KQL |
| Remote Management and Monitoring tool - AnyDesk - Create Process | Undefined | KQL |
| Remote Management and Monitoring tool - AnyDesk - File Signature | Undefined | KQL |
+ 154 more from Azure/Azure-Sentinel → showing the 10 highest-severity
SigmaHQ/sigma
52 rules| Detection | Severity | Format |
|---|---|---|
| Antivirus - APT Malware Signature | Critical | Sigma |
| Antivirus - Exploitation Framework Signature | Critical | Sigma |
| Antivirus - Remote Access Tools Signature | Critical | Sigma |
| HackTool - Inveigh Execution Artefacts | Critical | Sigma |
| Atera Agent Installation | High | Sigma |
| HackTool - RemoteKrbRelay SMB Relay Secrets Dump Module Indicators | High | Sigma |
| Hijack Legit RDP Session to Move Laterally | High | Sigma |
| Potential CSharp Streamer RAT Loading .NET Executable Image | High | Sigma |
| Potential SocGholish Second Stage C2 DNS Query | High | Sigma |
| Remote Access Tool - Anydesk Execution From Suspicious Folder | High | Sigma |
+ 42 more from SigmaHQ/sigma → showing the 10 highest-severity
elastic/detection-rules
19 rules| Detection | Severity | Format |
|---|---|---|
| NetSupport Manager Execution from an Unusual Path | High | Elastic TOML |
| Newly Observed ScreenConnect Host Server | High | Elastic TOML |
| Potential REMCOS Trojan Execution | High | Elastic TOML |
| VNC (Virtual Network Computing) from the Internet | High | Elastic TOML |
| Attempt to Establish VScode Remote Tunnel | Medium | Elastic TOML |
| First Time Seen DNS Query to RMM Domain | Medium | Elastic TOML |
| First Time Seen Remote Monitoring and Management Tool | Medium | Elastic TOML |
| First Time Seen RMM Signer Across the Environment | Medium | Elastic TOML |
| Multiple Remote Management Tool Vendors on Same Host | Medium | Elastic TOML |
| Potential Traffic Tunneling using QEMU | Medium | Elastic TOML |
+ 9 more from elastic/detection-rules → showing the 10 highest-severity
splunk/security_content
15 rules| Detection | Severity | Format |
|---|---|---|
| Cisco Secure Firewall - Communication Over Suspicious Ports | Undefined | SPL |
| Cisco Secure Firewall - Remote Access Software Usage Traffic | Undefined | SPL |
| Detect Remote Access Software Usage DNS | Undefined | SPL |
| Detect Remote Access Software Usage File | Undefined | SPL |
| Detect Remote Access Software Usage FileInfo | Undefined | SPL |
| Detect Remote Access Software Usage Process | Undefined | SPL |
| Detect Remote Access Software Usage Registry | Undefined | SPL |
| Detect Remote Access Software Usage Traffic | Undefined | SPL |
| Detect Remote Access Software Usage URL | Undefined | SPL |
| HTTP RMM User Agent | Undefined | SPL |
+ 5 more from splunk/security_content → showing the 10 highest-severity
Bert-JanP/Hunting-Queries-Detection-Rules
5 rules| Detection | Severity | Format |
|---|---|---|
| Detect when AnyDesk makes a remote connection | Undefined | KQL |
| *Known RAT/RMM process patterns* | Undefined | KQL |
| MITRE ATT&CK Mapping | Undefined | KQL |
| RMM Tools with connections | Undefined | KQL |
| TTP Detection Rule: NetSupport running from unexpected directory (FIN7) | Undefined | KQL |
elastic/protections-artifacts
5 rules| Detection | Severity | Format |
|---|---|---|
| NetSupport Execution form unusual Path | Undefined | Elastic TOML |
| Potential PlugX Registry Modification | Undefined | Elastic TOML |
| Suspicious DNS Lookup by Remote Utilities RMM | Undefined | Elastic TOML |
| Suspicious NetSupport Execution | Undefined | Elastic TOML |
| Velociraptor Suspicious Shell Execution | Undefined | Elastic TOML |
chronicle/detection-rules
2 rules| Detection | Severity | Format |
|---|---|---|
| gcti_remote_access_tools | High | YARA-L |
| win_pua_detection_of_uncommon_rmm | Medium | YARA-L |
socfortress/Wazuh-Rules
2 rules| Detection | Severity | Format |
|---|---|---|
| Sysmon - Event 1: Process creation · PowerShell Download of RAT Tool (T1219) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Remote Access Tool Execution (T1219) | High | Wazuh XML |
panther-labs/panther-analysis
1 rule| Detection | Severity | Format |
|---|---|---|
| Crowdstrike Remote Access Tool Execution | Informational | Panther Python |