Remote Services

T1021

Technique with 8 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may use Valid Accounts to log into a service that accepts remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user.

In an enterprise environment, servers and workstations can be organized into domains. Domains provide centralized identity management, allowing users to login using one set of credentials across the entire network. If an adversary is able to obtain a set of valid domain credentials, they could login to many different machines using remote access protocols such as secure shell (SSH) or remote desktop protocol (RDP). They could also login to accessible SaaS or IaaS services, such as those that federate their identities to the domain, or management platforms for internal virtualization environments such as VMware vCenter.

Legitimate applications (such as Software Deployment Tools and other administrative programs) may utilize Remote Services to access remote hosts. For example, Apple Remote Desktop (ARD) on macOS is native software used for remote management. ARD leverages a blend of protocols, including VNC to send the screen and control buffers and SSH for secure file transfer. Adversaries can abuse applications such as ARD to gain remote code execution and perform lateral movement. In versions of macOS prior to 10.14, an adversary can escalate an SSH session to an ARD session which enables an adversary to accept TCC (Transparency, Consent, and Control) prompts without user interaction and gain access to data.

Detection rules155

Rules on DetectionCode tagged with T1021 or one of its sub-techniques.

Sigma88

RuleLevelLog sourceTechnique
CobaltStrike Service Installations - Systemcriticalwindows / NULLT1021.002
Potential DCOM InternetExplorer.Application DLL Hijackcriticalwindows / file_eventT1021.002 T1021.003
Potential DCOM InternetExplorer.Application DLL Hijack - Image Loadcriticalwindows / image_loadT1021.002 T1021.003
Wmiprvse Wbemcomn DLL Hijack - Filecriticalwindows / file_eventT1021.002
BaaUpdate.exe Suspicious DLL Loadhighwindows / image_loadT1021.003
CobaltStrike Service Installations - Securityhighwindows / NULLT1021.002
DCOM InternetExplorer.Application Iertutil DLL Hijack - Securityhighwindows / NULLT1021.002 T1021.003
First Time Seen Remote Named Pipehighwindows / NULLT1021.002
First Time Seen Remote Named Pipe - Zeekhighzeek / NULLT1021.002
HackTool - NetExec Executionhighwindows / process_creationT1021
HackTool - NetExec File Indicatorshighwindows / file_eventT1021.002
HackTool - Potential Impacket Lateral Movement Activityhighwindows / process_creationT1021.003
HackTool - SharpMove Tool Executionhighwindows / process_creationT1021.002
Impacket PsExec Executionhighwindows / NULLT1021.002
Metasploit Or Impacket Service Installation Via SMB PsExechighwindows / NULLT1021.002

Splunk67

RuleTypeRiskData sourceTechnique
Allow Inbound Traffic By Firewall Rule RegistryTTPNULLSysmon EventID 13T1021.001
Allow Inbound Traffic In Firewall RuleTTPNULLPowershell Script Block Logging 4104T1021.001
Cisco IOS XE Remote Access Probe BurstAnomalyNULLCisco IOS LogsT1021.004
Cisco IOS XE VTY Access Class TamperingAnomalyNULLCisco IOS LogsT1021
Cisco Network Interface ModificationsAnomalyNULLCisco IOS LogsT1021
Cisco Privileged Account Creation with HTTP Command ExecutionCorrelationNULLT1021.004
Cisco Privileged Account Creation with Suspicious SSH ActivityCorrelationNULLT1021.004
Cisco Secure Firewall - Communication Over Suspicious PortsAnomalyNULLCisco Secure Firewall Threat Defense Connection EventT1021
Cisco Secure Firewall - SSH Connection to Non-Standard PortAnomalyNULLCisco Secure Firewall Threat Defense Intrusion EventT1021.004
Cisco Secure Firewall - SSH Connection to sshd_opernsAnomalyNULLCisco Secure Firewall Threat Defense Intrusion EventT1021.004
Detect PsExec With accepteula FlagTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1021.002
Enable RDP In Other Port NumberTTPNULLSysmon EventID 13T1021
ESXi Shell Access EnabledTTPNULLVMWare ESXi SyslogT1021
ESXi SSH EnabledTTPNULLVMWare ESXi SyslogT1021.004
Executable File Written in Administrative SMB ShareTTPNULLWindows Event Log Security 5145T1021.002

Sub-techniques8

IDNameExamples
T1021.001Remote Desktop Protocol63
T1021.002SMB/Windows Admin Shares65
T1021.003Distributed Component Object Model3
T1021.004SSH27
T1021.005VNC11
T1021.006Windows Remote Management10
T1021.007Cloud Services5
T1021.008Direct Cloud VM Connections0

Groups3

Software4

Campaigns0

None recorded.

Procedure examples7

Groups3

Used byProcedure example
GroupAquatic Panda

Aquatic Panda used remote scheduled tasks to install malicious software on victim systems during lateral movement actions.

GroupEmber Bear

Ember Bear uses valid network credentials gathered through credential harvesting to move laterally within victim networks, often employing the Impacket framework to do so.

GroupWizard Spider

Wizard Spider has used the WebDAV protocol to execute Ryuk payloads hosted on network file shares.

Software4

Used byProcedure example
ToolBrute Ratel C4

Brute Ratel C4 has the ability to use RPC for lateral movement.

MalwareKivars

Kivars has the ability to remotely trigger keyboard input and mouse clicks.

MalwareMacMa

MacMa can manage remote screen sessions.

MalwareStuxnet

Stuxnet can propagate via peer-to-peer communication and updates using RPC.

References7

  1. Apple Remote Desktop Admin Guide 3.3 Open source
    Apple. (n.d.). Apple Remote Desktop Administrator Guide Version 3.3. Retrieved October 5, 2021.
  2. FireEye 2019 Apple Remote Desktop Open source
    Jake Nicastro, Willi Ballenthin. (2019, October 9). Living off the Orchard: Leveraging Apple Remote Desktop for Good and Evil. Retrieved August 16, 2021.
  3. Kickstart Apple Remote Desktop commands Open source
    Apple. (n.d.). Use the kickstart command-line utility in Apple Remote Desktop. Retrieved September 23, 2021.
  4. Lockboxx ARD 2019 Open source
    Dan Borges. (2019, July 21). MacOS Red Teaming 206: ARD (Apple Remote Desktop Protocol). Retrieved September 10, 2021.
  5. Remote Management MDM macOS Open source
    Apple. (n.d.). Use MDM to enable Remote Management in macOS. Retrieved September 23, 2021.
  6. SSH Secure Shell Open source
    SSH.COM. (n.d.). SSH (Secure Shell). Retrieved March 23, 2020.
  7. TechNet Remote Desktop Services Open source
    Microsoft. (n.d.). Remote Desktop Services. Retrieved June 1, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.