Potential RMM Execution from a Commonly Abused Web Service
Identifies execution of software whose reported code-signature subject matches a known remote monitoring and management (RMM) publisher with a download origin on a commonly abused web service. Adversaries use these…
Description
Identifies execution of software whose reported code-signature subject matches a known remote monitoring and management (RMM) publisher with a download origin on a commonly abused web service. Adversaries use these services to deliver remote-access software during social engineering and intrusion campaigns.
Detection logic
Its licence does not clear it for publishing here
Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.
Detection requirements
- Platform
- ESXiLinuxmacOSNetwork DevicesWindows
The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.
Known benign triggers
- IT or managed service providers may distribute RMM binaries through public hosting or shared download links. Confirm the package, host, operator, timing, and enrollment destination against a change record or support ticket.
- Publishers in the maintained signer list may also sign scanners, backup clients, or other non-RMM software. Confirm the actual product and purpose from executable, command-line, hash, and deployment evidence.
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
References
| Reference | Cited by |
|---|---|
| www.cloudflare.com/cloudforce-one/research/new-ssa-themed-phishing-campaign-installs-trojanized-screenconnect/ | Only this detection cites it |
| www.cloudflare.com/cloudforce-one/research/report/vercel-hosted-rmm-abuse-campaign-evolves-with-telegram-c2-for-victim-filtering/ | Only this detection cites it |
| www.forescout.com/blog/from-urls-to-malware-how-threat-actors-abuse-domain-security-in-2025/ | Only this detection cites it |
| www.huntress.com/blog/series-of-unfortunate-rmm-events | 3 |
| www.microsoft.com/en-us/security/blog/2026/09/29/phishing-abuses-rmm-tools-persistent-access | 2 |
From the source
- At source
- Open at source
- Upstream identifier
- e06df914-e526-4a52-ab9d-0fd10d8015dd
- Tagged by the source as
- Data Source: Elastic DefendDomain: EndpointOS: WindowsPlatform: WindowsRule Type: ES|QLTactic: Command and ControlThreat: Remote Management Tool AbuseUse Case: Threat Detection
Licence
- Published under
- Elastic License 2.0Read the licence
- Attribution
- Required
Authorship
- Written by
- Published
- Oct 2, 2026
- Version
- 1