%GoCortexIO Snippets

Cortex XDR

Hunt for unauthorised deployments of legitimate, signed Remote Monitoring and Management tools being abused for hands-on-keyboard adversary activity.

| 5 minutes to implement | ~1 min read
markdown
> Make sure you're comfortable with the results in your own environment before using this more widely.

# Snippet - Remote management and monitoring tool execution.

## Scenario 

Imagine an environment where an adversary deploys a legitimate remote management and monitoring (RMM) tool to maintain hands-on access. The tool is signed and operates "as intended", which is why it slips past signature-based controls.

Logic: a presence-and-absence hunt rather than a maliciousness verdict. Compare each hit against your sanctioned RMM list; anything outside it is worth a quick conversation with the host's owner. 

Also consider hunting for approved RMM tools using non standard relay addresses to look for stealthy adversaries that have done their homework.

- [https://attack.mitre.org/techniques/T1219/](https://attack.mitre.org/techniques/T1219/)
- [https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-025a](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-025a)
- [https://lolrmm.io/](https://lolrmm.io/)
- [https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/generic_rmm_detection.yml](https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/generic_rmm_detection.yml)
xql
// Make sure you're comfortable with the results in your own environment before using this more widely.
// Use the list at LOLRMM to add/remove tools. The below is just a sample to assist you building your query.
dataset = xdr_data
| filter event_type = ENUM.PROCESS and event_sub_type = ENUM.PROCESS_START
| filter lowercase(action_process_image_name) in (
    "anydesk.exe", "atera.exe", "ateraagent.exe", "screenconnect.clientservice.exe",
    "screenconnect.windowsclient.exe", "splashtop.exe", "splashtopstreamer.exe",
    "teamviewer.exe", "rustdesk.exe", "netsupport.exe", "client32.exe")
| fields _time, agent_hostname, actor_effective_username, causality_actor_process_image_name, action_process_image_command_line
| limit 500
See all 21 snippets