Back to results

Potential RMM Execution from a Commonly Abused Web Service

Identifies execution of software whose reported code-signature subject matches a known remote monitoring and management (RMM) publisher with a download origin on a commonly abused web service. Adversaries use these…

Description

Identifies execution of software whose reported code-signature subject matches a known remote monitoring and management (RMM) publisher with a download origin on a commonly abused web service. Adversaries use these services to deliver remote-access software during social engineering and intrusion campaigns.

Detection logic

Its licence does not clear it for publishing here

Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.

Detection requirements

Platform
ESXiLinuxmacOSNetwork DevicesWindows

The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.

Known benign triggers

  • IT or managed service providers may distribute RMM binaries through public hosting or shared download links. Confirm the package, host, operator, timing, and enrollment destination against a change record or support ticket.
  • Publishers in the maintained signer list may also sign scanners, backup clients, or other non-RMM software. Confirm the actual product and purpose from executable, command-line, hash, and deployment evidence.

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice