Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0496 — Behavior-Chain Detection for Remote Access Tools (Tool-Agnostic)
DET0496

Behavior-Chain Detection for Remote Access Tools (Tool-Agnostic)

3 analytic(s) · 1 technique(s) detected

Analytics

3
AN1366 Analytic 1366
Windows

Chain of remote access tool behavior: (1) initial execution of remote-control/assist agent or GUI under user context; (2) persistence via service or autorun; (3) long-lived outbound connection/tunnel to external infrastructure; (4) interactive control signals such as shell or file-manager child processes spawned by the RAT parent.

WinEventLog:Sysmon EventCode=1 WinEventLog:System EventCode=7045 WinEventLog:Sysmon EventCode=12 WinEventLog:Sysmon EventCode=13, 14 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=3, 22
[TimeWindow] Correlation period binding start→persistence→egress→child (default 15m, adjust per environment).
[UserContext] Differentiate help-desk/jump hosts and admin accounts from standard endpoints.
[ProcessAllowlist] Known-good remote support tools; suppress expected events while still correlating anomalous sequences.
[InstallPathRegex] Alert when services/agents execute from user-writable or temp paths.
[ExternalIPAllowlist] Vendors’ support clouds/CDNs to reduce false positives on egress detection.
[ShellSpawnRegex] Define which child shells from GUI parents are acceptable versus suspicious.
[EgressHeuristics] Thresholds for session duration, connection counts, and bytes_out/bytes_in ratio.
AN1367 Analytic 1367
Linux

Sequence of RAT agent execution, systemd persistence, and long-lived external egress; optional interactive shells spawned from the agent.

auditd:SYSCALL execve: Agent/headless flags (listen/connect/reverse/tunnel) or remote-control binaries spawning shells auditd:PATH WRITE: Drop of binaries/scripts in ~/.local, /tmp, or /opt tool dirs WinEventLog:Sysmon EventCode=3, 22
[TimeWindow] Bind exec→service→egress events; extend for staged deployments.
[DaemonAllowlist] Approved .service names/paths to avoid flagging corporate agents.
[SuspiciousChildProcesses] Define shells/interpreters considered anomalous when spawned by GUI/agent parents.
[EgressHeuristics] Flow heuristics for long-lived, client-heavy connections post-install.
AN1368 Analytic 1368
macOS

Electron/GUI or headless RAT execution followed by LaunchAgent/Daemon persistence and persistent external connections; interactive children (osascript/sh/curl) spawned by parent.

macos:unifiedlog Process exec of remote-control apps or binaries with headless/connect flags macos:osquery CREATE/MODIFY: Creation of LaunchAgents/Daemons plists in user/system locations macos:osquery CONNECT: Long-lived connections from remote-control parents to external IPs/domains
[AllowedAppBundlePaths] Legitimate remote-support apps under /Applications.
[LaunchdAllowlist] Known-good LaunchAgents/Daemons identifiers.
[TimeWindow] Window for correlating exec→launchd→egress events.
[EgressHeuristics] Duration/volume thresholds for persistent sessions.

Detected Techniques

1

Command & Control (1)

Details

MITRE ID
DET0496
STIX ID
x-mitre-detection-strategy--ec412019-109f-4f84-aa2f-d623f40254e0
Analytics
3
Techniques Detected
1
By Tactic
Command & Control
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.