Security research

www.huntress.com/blog/series-of-unfortunate-rmm-events

https://www.huntress.com/blog/series-of-unfortunate-rmm-events
Published on
www.huntress.com

ATT&CK techniques those detections carry

  • T1219Remote Access Tools
  • T1219.002Remote Desktop Software
  • T1105Ingress Tool Transfer
  • T1036Masquerading
  • T1204User Execution
  • T1204.002Malicious File
  • T1218System Binary Proxy Execution
  • T1218.007Msiexec
Open the original

3 published detections cite this

Citing it, not covering it: each of these was written with this as evidence, and carries the source it came from and the licence it was published under.

Detections citing this reference
DetectionSeverity
Lure-Themed Internet-Delivered RMM ExecutableMedium
Potential RMM Execution from a Commonly Abused Web ServiceLow
RMM Software Installation from an Internet-Originated MSILow

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice