Remote Access Tool - TacticalRMM Agent Registration to Potentially Attacker-Controlled Server

 Original Source: [Sigma source]
Title: Remote Access Tool - TacticalRMM Agent Registration to Potentially Attacker-Controlled Server
Status: experimental
Description:Detects TacticalRMM agent installations where the --api, --auth, and related flags are used on the command line. These parameters configure the agent to connect to a specific RMM server with authentication, client ID, and site ID. This technique could indicate a threat actor attempting to register the agent with an attacker-controlled RMM infrastructure silently.
References:
  -https://github.com/amidaware/tacticalrmm
  -https://apophis133.medium.com/powershell-script-tactical-rmm-installation-45afb639eff3
Author: Ahmed Nosir (@egycondor)
Date: 2025-05-29
modified:None
Tags:
  • -'attack.command-and-control'
  • -'attack.t1219'
  • -'attack.t1105'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    Image|contains: '\TacticalAgent\tacticalrmm.exe'
    CommandLine|contains|all:
      -'--api'
      -'--auth'
      -'--client-id'
      -'--site-id'
      -'--agent-type'

  condition:selection
Falsepositives:
  -Legitimate system administrator deploying TacticalRMM
Level: medium