Remote Access Tools T1219
Tactic: Command & Control
An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.
Events covered
19 catalog events are tagged with this technique by at least one rule.
Authoring guide
These 111 rules share fields, values, and exclusions.
Fields filtered most (77 distinct)
These fields appear most often in rule filters.
Top indicator values (1197 distinct)
These values appear most often in rule predicates.
Exclusions (175 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 52 rules
- Antivirus - APT Malware Signature
- Antivirus - Exploitation Framework Signature
- Antivirus - Remote Access Tools Signature
- Anydesk Temporary Artefact
- Atera Agent Installation
- DNS Query To AzureWebsites.NET By Non-Browser Process
- DNS Query To Remote Access Software Domain From Non-Browser App
- GoToAssist Temporary Installation Artefact
- HackTool - Inveigh Execution Artefacts
- HackTool - RemoteKrbRelay SMB Relay Secrets Dump Module Indicators
- Hijack Legit RDP Session to Move Laterally
- Installation of TeamViewer Desktop
- Mesh Agent Service Installation
- Mstsc.EXE Execution With Local RDP File
- OpenEDR Spawning Command Shell
- Potential Amazon SSM Agent Hijacking
- Potential CSharp Streamer RAT Loading .NET Executable Image
- Potential Linux Amazon SSM Agent Hijacking
- Potential Remote Desktop Connection to Non-Domain Host
- Potential SocGholish Second Stage C2 DNS Query
- Potentially Suspicious File Creation by OpenEDR's ITSMService
- QuickAssist Execution
- Remote Access Tool - Action1 Arbitrary Code Execution and Remote Sessions
- Remote Access Tool - AnyDesk Execution
- Remote Access Tool - Anydesk Execution From Suspicious Folder
- Remote Access Tool - AnyDesk Incoming Connection
- Remote Access Tool - AnyDesk Piped Password Via CLI
- Remote Access Tool - AnyDesk Silent Installation
- Remote Access Tool - GoToAssist Execution
- Remote Access Tool - LogMeIn Execution
- Remote Access Tool - MeshAgent Command Execution via MeshCentral
- Remote Access Tool - NetSupport Execution
- Remote Access Tool - Potential MeshAgent Execution - MacOS
- Remote Access Tool - Potential MeshAgent Execution - Windows
- Remote Access Tool - Renamed MeshAgent Execution - MacOS
- Remote Access Tool - Renamed MeshAgent Execution - Windows
- Remote Access Tool - ScreenConnect Execution
- Remote Access Tool - ScreenConnect Potential Suspicious Remote Command Execution
- Remote Access Tool - Simple Help Execution
- Remote Access Tool - TacticalRMM Agent Registration to Potentially Attacker-Controlled Server
- Remote Access Tool - UltraViewer Execution
- Renamed Visual Studio Code Tunnel Execution
- ScreenConnect Temporary Installation Artefact
- Suspicious Binary Writes Via AnyDesk
- Suspicious Mstsc.EXE Execution With Local RDP File
- Suspicious TSCON Start as SYSTEM
- Suspicious Velociraptor Child Process
- TacticalRMM Service Installation
- TeamViewer Domain Query By Non-TeamViewer Application
- TeamViewer Remote Session
- Use of UltraVNC Remote Access Software
- Visual Studio Code Tunnel Execution
Elastic 24 rules
- Attempt to Establish VScode Remote Tunnel
- First Time Seen DNS Query to RMM Domain
- First Time Seen Remote Monitoring and Management Tool
- First Time Seen RMM Signer Across the Environment
- Multiple Remote Management Tool Vendors on Same Host
- NetSupport Execution form unusual Path
- NetSupport Manager Execution from an Unusual Path
- Newly Observed ScreenConnect Host Server
- Potential PlugX Registry Modification
- Potential REMCOS Trojan Execution
- Potential Traffic Tunneling using QEMU
- Potential Tunneling via Tailscaled
- Quick Assist Full Control Sharing Mode Enabled
- Remote File Copy via TeamViewer
- Remote GitHub Actions Runner Registration
- Remote Management Access Launch After MSI Install
- Shell Execution via Elastic Endpoint
- Suspicious DNS Lookup by Remote Utilities RMM
- Suspicious NetSupport Execution
- Suspicious ScreenConnect Client Child Process
- Suspicious Shell Execution via Velociraptor
- Velociraptor Suspicious Shell Execution
- VNC (Virtual Network Computing) from the Internet
- VNC (Virtual Network Computing) to the Internet
Splunk 32 rules
- AnyDesk Command Line Execution (Sysmon)
- AnyDesk Command Line Execution (Windows Event Log)
- AnyDesk Execution from Suspicious Folder (Sysmon)
- AnyDesk Execution from Suspicious Folder (Windows Event Log)
- AnyDesk Silent Install (Sysmon)
- AnyDesk Silent Install (Windows Event Log)
- AteraAgent Installation - Windows (Sysmon)
- AteraAgent Installation - Windows (Windows Event Log)
- Cisco Secure Firewall - Communication Over Suspicious Ports
- Cisco Secure Firewall - Remote Access Software Usage Traffic
- Detect Remote Access Software Usage DNS
- Detect Remote Access Software Usage File
- Detect Remote Access Software Usage FileInfo
- Detect Remote Access Software Usage Process
- Detect Remote Access Software Usage Registry
- Detect Remote Access Software Usage Traffic
- Detect Remote Access Software Usage URL
- HTTP RMM User Agent
- Remote Access Software Execution (Sysmon)
- Remote Access Software Execution (Windows Event Log)
- SimpleHelp Remote Access Tool Execution (Sysmon)
- SimpleHelp Remote Access Tool Execution (Windows Event Log)
- SimpleHelp Remote Access Tool Service Installation (Windows Event Log)
- Suspicious AteraAgent Installation - Windows (PowerShell)
- Suspicious AteraAgent Installation - Windows (Sysmon)
- Suspicious AteraAgent Installation - Windows (Windows Event Log)
- Temporary ConnectWise xml File Activity (Windows Event Log)
- Windows Level RMM PowerShell Script Installer
- Windows Level RMM Watchdog Task Created
- Windows Remote Access Software BRC4 Loaded Dll
- Windows Remote Access Software RMS Registry
- Windows RMM Tool Execution