Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0259 — Remote Desktop Software Execution and Beaconing Detection
DET0259

Remote Desktop Software Execution and Beaconing Detection

3 analytic(s) · 1 technique(s) detected

Analytics

3
AN0714 Analytic 0714
Windows

Adversary installation or use of RMM software (e.g., TeamViewer, AnyDesk, ScreenConnect) followed by outbound beaconing or remote session establishment

WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=3, 22 WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall new rule allowing inbound or outbound connections for remote desktop software
[Image] RMM software can vary; defenders should update rules to account for additional binaries (e.g., ConnectWise, Zoho Assist)
[DestinationPort] RMM software may use configurable or random high ports outside of standard (e.g., 7070, 5650)
[ParentImage] Expected parent process may vary in different enterprise contexts
[TimeWindow] Correlation window for install-to-beacon or process-to-network event should match operational environment
AN0715 Analytic 0715
Linux

Execution of known or custom VNC/remote desktop daemons or tunneling agents that initiate external communication after launch

auditd:SYSCALL execve NSM:Flow outbound connections to RMM services or to unusual destination ports
[binary_name] Custom-compiled or renamed VNC servers (e.g., x11vnc, tightvncserver) may require local tuning
[OutboundIPRange] Destination IP or ASN may shift depending on geolocation of cloud-hosted RMM backends
AN0716 Analytic 0716
macOS

Initiation of remote desktop sessions via AnyDesk, TeamViewer, or Chrome Remote Desktop accompanied by unexpected user logins or system modifications

macos:unifiedlog launch of remote desktop app or helper binary macos:unifiedlog network sessions initiated by remote desktop apps
[process_signature] App may be notarized and signed differently depending on distribution method (App Store vs .pkg)
[sandbox_exception] If the remote desktop tool circumvents sandbox, it may produce additional telemetry in local TCC logs

Detected Techniques

1

Details

MITRE ID
DET0259
STIX ID
x-mitre-detection-strategy--834e853c-479d-4ddd-a1a3-349b09466b8d
Analytics
3
Techniques Detected
1
By Tactic
Command & Control
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.