Windows Level RMM PowerShell Script Installer: endpointEndpointNoneversion:2
Detects the PowerShell installer for the Level tool.
Level is a commercial remote management tool from Level.io.
Remote management tools, when used for legitimate purposes, can help IT professionals and system administrators remotely access and manage computer systems.
However, threat actors may exploit these tools for malicious purposes.
It can be used to maintain persistence and execution on a host by a malicious actor.
Detect Remote Access Software Usage Registry: endpointEndpointNoneversion:13
The following analytic detects when a known remote access software is added to common persistence locations on a device within the environment. Adversaries use these utilities to retain remote access capabilities to the environment. Utilities in the lookup include AnyDesk, GoToMyPC, LogMeIn, TeamViewer and much more. Review the lookup for the entire list and add any others.
Windows Suspicious Named Pipe: endpointEndpointNoneversion:5
The following analytic detects the creation or connection to known suspicious named pipes.
It leverages Sysmon EventCodes 17 and 18 to identify known default pipe names used by malicious or suspicious tools.
If confirmed malicious, this could allow an attacker to abuse these to potentially gain privilege escalation,
persistence, c2 communications, or further system compromise.
Detect Remote Access Software Usage File: endpointEndpointNoneversion:16
The following analytic detects the writing of files from known remote access software to disk within the environment.
It leverages data from Endpoint Detection and Response (EDR) agents, focusing on file path, file name, and user information.
This activity is significant as adversaries often use remote access tools like AnyDesk, GoToMyPC, LogMeIn, and TeamViewer to maintain unauthorized access.
If confirmed malicious, this could allow attackers to persist in the environment, potentially leading to data exfiltration, further compromise, or complete control over affected systems.
It is best to update both the remote_access_software_usage_exception.csv lookup and the remote_access_software lookup with any known or approved remote access software to reduce false positives and increase coverage.
In order to enhance performance, the detection filters for specific file names extensions / names that are used in the remote_access_software lookup.
If add additional entries, consider updating the search filters to include those file names / extensions as well, if not alread covered.
Windows RMM Tool Execution: endpointEndpointNoneversion:2
Detects process creation events of various remote access tools.
Remote management tools, when used for legitimate purposes, can help IT professionals and system administrators remotely access and manage computer systems.
However, threat actors may exploit these tools for malicious purposes.
HTTP RMM User Agent: networkNetworkNoneversion:5
This Splunk query analyzes web logs to identify and categorize user agents, detecting various types of Remote Monitoring and Mangement applications. This activity can signify possible compromised hosts on the network.
Detect Remote Access Software Usage Traffic: networkNetworkNoneversion:16
The following analytic detects network traffic associated with known remote access software applications, such as AnyDesk, GoToMyPC, LogMeIn, and TeamViewer.
It leverages Palo Alto traffic logs mapped to the Network_Traffic data model in Splunk. This activity is significant because adversaries often use remote access tools to maintain unauthorized access to compromised environments.
If confirmed malicious, this activity could allow attackers to control systems remotely, exfiltrate data, or deploy additional malware, posing a severe threat to the organization's security.
Windows Suspicious C2 Named Pipe: endpointEndpointNoneversion:6
The following analytic detects the creation or connection to known suspicious C2 named pipes.
It leverages Sysmon EventCodes 17 and 18 to identify known default pipe names used by C2 tools.
If confirmed malicious, this could allow an attacker to abuse these to potentially gain persistence, command and control, or further system compromise.
Detect Remote Access Software Usage URL: networkNetworkNoneversion:16
The following analytic detects the execution of known remote access software within the environment.
It leverages network logs mapped to the Web data model, identifying specific URLs and user agents associated with remote access tools like AnyDesk, GoToMyPC, LogMeIn, and TeamViewer.
This activity is significant as adversaries often use these utilities to maintain unauthorized remote access. If confirmed malicious, this could allow attackers to control systems remotely, exfiltrate data, or further compromise the network, posing a severe security risk.
Detect Remote Access Software Usage DNS: endpointEndpointNoneversion:14
The following analytic detects DNS queries to domains associated with known remote access software such as AnyDesk, GoToMyPC, LogMeIn, and TeamViewer. This detection is crucial as adversaries often use these tools to maintain access and control over compromised environments. Identifying such behavior is vital for a Security Operations Center (SOC) because unauthorized remote access can lead to data breaches, ransomware attacks, and other severe impacts if these threats are not mitigated promptly.
Cisco Secure Firewall - Remote Access Software Usage Traffic: networkNetworkNoneversion:9
The following analytic detects network traffic associated with known remote access software applications
that are covered by Cisco Secure Firewall Application Detectors, such as AnyDesk, GoToMyPC, LogMeIn, and TeamViewer.
It leverages Cisco Secure Firewall Threat Defense Connection Event.
This activity is significant because adversaries often use remote access tools to maintain unauthorized access to compromised environments.
If confirmed malicious, this activity could allow attackers to control systems remotely, exfiltrate
data, or deploy additional malware, posing a severe threat to the organization's security.
Windows RMM Named Pipe: endpointEndpointNoneversion:5
The following analytic detects the creation or connection to known suspicious named pipes, which is a technique often used by offensive tools.
It leverages Sysmon EventCodes 17 and 18 to identify known default pipe names used by RMM tools.
If confirmed malicious, this could allow an attacker to abuse these to potentially gain persistence, command and control, or further system compromise.
Windows Level RMM Watchdog Task Created: endpointEndpointNoneversion:2
Detects the watchdog task created when Level is installed.
Level is a commercial remote management tool from Level.io.
Remote management tools, when used for legitimate purposes, can help IT professionals and system administrators remotely access and manage computer systems.
However, threat actors may exploit these tools for malicious purposes.
It can be used to maintain persistence and execution on a host by a malicious actor.
Detect Remote Access Software Usage FileInfo: endpointEndpointNoneversion:15
The following analytic detects the execution of processes with file or code signing attributes from known remote access software within the environment. It leverages Sysmon EventCode 1 data and cross-references a lookup table of remote access utilities such as AnyDesk, GoToMyPC, LogMeIn, and TeamViewer. This activity is significant as adversaries often use these tools to maintain unauthorized remote access. If confirmed malicious, this could allow attackers to persist in the environment, potentially leading to data exfiltration or further compromise of the network.
Detect Remote Access Software Usage Process: endpointEndpointNoneversion:17
The following analytic detects the execution of known remote access software within the environment. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and parent processes mapped to the Endpoint data model. We then compare with with a list of known remote access software shipped as a lookup file - remote_access_software. This activity is significant as adversaries often use remote access tools like AnyDesk, GoToMyPC, LogMeIn, and TeamViewer to maintain unauthorized access. If confirmed malicious, this could allow attackers to control systems remotely, exfiltrate data, or deploy additional malware, posing a severe threat to the organization's security.