Remote Access Tools T1219
Tactic: Command & Control
An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.
Events covered
23 catalog events are tagged with this technique by at least one rule.
Authoring guide
Patterns shared across the 100 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.
Fields filtered most (73 distinct)
The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.
Top indicator values (1095 distinct)
Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.
Exclusions (165 distinct)
Field/operator/value combinations excluded by rules under this technique (top-level not() clauses), sorted by how many rules exclude each. These are the false-positive paths the community has learned to filter out. A new rule that ignores the high-count entries here will likely fire on the same noisy paths. Click a value to expand the rules under this technique that exclude it.
Rules under this technique
Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.
Sigma 50 rules
- Antivirus Exploitation Framework Detection
- Anydesk Temporary Artefact
- Atera Agent Installation
- DNS Query To AzureWebsites.NET By Non-Browser Process
- DNS Query To Remote Access Software Domain From Non-Browser App
- GoToAssist Temporary Installation Artefact
- HackTool - Inveigh Execution Artefacts
- HackTool - RemoteKrbRelay SMB Relay Secrets Dump Module Indicators
- Hijack Legit RDP Session to Move Laterally
- Installation of TeamViewer Desktop
- Mesh Agent Service Installation
- Mstsc.EXE Execution With Local RDP File
- OpenEDR Spawning Command Shell
- Potential Amazon SSM Agent Hijacking
- Potential CSharp Streamer RAT Loading .NET Executable Image
- Potential Linux Amazon SSM Agent Hijacking
- Potential Remote Desktop Connection to Non-Domain Host
- Potential SocGholish Second Stage C2 DNS Query
- Potentially Suspicious File Creation by OpenEDR's ITSMService
- QuickAssist Execution
- Remote Access Tool - Action1 Arbitrary Code Execution and Remote Sessions
- Remote Access Tool - AnyDesk Execution
- Remote Access Tool - Anydesk Execution From Suspicious Folder
- Remote Access Tool - AnyDesk Incoming Connection
- Remote Access Tool - AnyDesk Piped Password Via CLI
- Remote Access Tool - AnyDesk Silent Installation
- Remote Access Tool - GoToAssist Execution
- Remote Access Tool - LogMeIn Execution
- Remote Access Tool - MeshAgent Command Execution via MeshCentral
- Remote Access Tool - NetSupport Execution
- Remote Access Tool - Potential MeshAgent Execution - MacOS
- Remote Access Tool - Potential MeshAgent Execution - Windows
- Remote Access Tool - Renamed MeshAgent Execution - MacOS
- Remote Access Tool - Renamed MeshAgent Execution - Windows
- Remote Access Tool - ScreenConnect Execution
- Remote Access Tool - ScreenConnect Potential Suspicious Remote Command Execution
- Remote Access Tool - Simple Help Execution
- Remote Access Tool - TacticalRMM Agent Registration to Potentially Attacker-Controlled Server
- Remote Access Tool - UltraViewer Execution
- Renamed Visual Studio Code Tunnel Execution
- ScreenConnect Temporary Installation Artefact
- Suspicious Binary Writes Via AnyDesk
- Suspicious Mstsc.EXE Execution With Local RDP File
- Suspicious TSCON Start as SYSTEM
- Suspicious Velociraptor Child Process
- TacticalRMM Service Installation
- TeamViewer Domain Query By Non-TeamViewer Application
- TeamViewer Remote Session
- Use of UltraVNC Remote Access Software
- Visual Studio Code Tunnel Execution
Elastic 15 rules
- Attempt to Establish VScode Remote Tunnel
- First Time Seen DNS Query to RMM Domain
- First Time Seen Remote Monitoring and Management Tool
- Multiple Remote Management Tool Vendors on Same Host
- NetSupport Manager Execution from an Unusual Path
- Newly Observed ScreenConnect Host Server
- Potential REMCOS Trojan Execution
- Potential Traffic Tunneling using QEMU
- Remote File Copy via TeamViewer
- Remote GitHub Actions Runner Registration
- Remote Management Access Launch After MSI Install
- Suspicious ScreenConnect Client Child Process
- Suspicious Shell Execution via Velociraptor
- VNC (Virtual Network Computing) from the Internet
- VNC (Virtual Network Computing) to the Internet
Splunk 32 rules
- AnyDesk Command Line Execution (Sysmon)
- AnyDesk Command Line Execution (Windows Event Log)
- AnyDesk Execution from Suspicious Folder (Sysmon)
- AnyDesk Execution from Suspicious Folder (Windows Event Log)
- AnyDesk Silent Install (Sysmon)
- AnyDesk Silent Install (Windows Event Log)
- AteraAgent Installation - Windows (Sysmon)
- AteraAgent Installation - Windows (Windows Event Log)
- Cisco Secure Firewall - Communication Over Suspicious Ports
- Cisco Secure Firewall - Remote Access Software Usage Traffic
- Detect Remote Access Software Usage DNS
- Detect Remote Access Software Usage File
- Detect Remote Access Software Usage FileInfo
- Detect Remote Access Software Usage Process
- Detect Remote Access Software Usage Registry
- Detect Remote Access Software Usage Traffic
- Detect Remote Access Software Usage URL
- HTTP RMM User Agent
- Remote Access Software Execution (Sysmon)
- Remote Access Software Execution (Windows Event Log)
- SimpleHelp Remote Access Tool Execution (Sysmon)
- SimpleHelp Remote Access Tool Execution (Windows Event Log)
- SimpleHelp Remote Access Tool Service Installation (Windows Event Log)
- Suspicious AteraAgent Installation - Windows (PowerShell)
- Suspicious AteraAgent Installation - Windows (Sysmon)
- Suspicious AteraAgent Installation - Windows (Windows Event Log)
- Temporary ConnectWise xml File Activity (Windows Event Log)
- Windows Level RMM PowerShell Script Installer
- Windows Level RMM Watchdog Task Created
- Windows Remote Access Software BRC4 Loaded Dll
- Windows Remote Access Software RMS Registry
- Windows RMM Tool Execution