Title:
Remote Access Tool Services Have Been Installed - Security
Status:
test
Description:Detects service installation of different remote access tools software. These software are often abused by threat actors to perform
References:
-https://redcanary.com/blog/misbehaving-rats/
Author: Connor Martin, Nasreddine Bencherchali (Nextron Systems)
Date: 2022-12-23
modified:2024-12-07
Tags:
- -'attack.privilege-escalation'
- -'attack.persistence'
- -'attack.execution'
- -'attack.t1543.003'
- -'attack.t1569.002'
Logsource:
- product: windows
- service: security
- definition: The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697
Detection:
selection:
EventID:
'4697'
ServiceName|contains:
-'AmmyyAdmin'
-'AnyDesk'
-'Atera'
-'BASupportExpressSrvcUpdater'
-'BASupportExpressStandaloneService'
-'chromoting'
-'GoToAssist'
-'GoToMyPC'
-'jumpcloud'
-'LMIGuardianSvc'
-'LogMeIn'
-'monblanking'
-'Parsec'
-'RManService'
-'RPCPerformanceService'
-'RPCService'
-'SplashtopRemoteService'
-'SSUService'
-'TeamViewer'
-'TightVNC'
-'vncserver'
-'Zoho'
condition:
selection
Falsepositives:
-The rule doesn't look for anything suspicious so false positives are expected. If you use one of the tools mentioned, comment it out
Level:
medium