ManySignal
T1219 MITRE ATT&CK

T1219 Remote Access Software — Detection & Response

An adversary may use legitimate desktop support and remote access software to establish an interactive command and control channel to target systems within networks. These services, such as AnyDesk, TeamViewer, ScreenConnect, Splashtop, Atera, and LogMeIn, are commonly used as legitimate technical support software and may be allowed by application control within a target environment. Remote access software may be installed and used post-compromise as an alternate communications channel for redundant access or as a way to establish an interactive remote desktop session with the target system.

Coverage at a glance

Detections shipped
5
Avg. verdict time
< 5 min
Data sources
4+

Threat context

How adversaries use T1219 Remote Access Software — Detection & Response

An adversary may use legitimate desktop support and remote access software to establish an interactive command and control channel to target systems within networks. These services, such as AnyDesk, TeamViewer, ScreenConnect, Splashtop, Atera, and LogMeIn, are commonly used as legitimate technical support software and may be allowed by application control within a target environment. Remote access software may be installed and used post-compromise as an alternate communications channel for redundant access or as a way to establish an interactive remote desktop session with the target system.

Remote monitoring and management (RMM) tools have become a dominant C2 channel across ransomware, business email compromise, and access-broker operations because they combine legitimate code-signing, encrypted transport to well-known cloud endpoints, and interactive keyboard-and-mouse control in a single package. Groups such as Scattered Spider, BlackCat/ALPHV affiliates, and the operators behind ScreenConnect abuse campaigns routinely drop AnyDesk, ScreenConnect, Splashtop, or Atera within minutes of gaining initial access, either via phishing lures directed at the help desk or via silent installers pushed after initial exploitation. Because the tools use cloud relays (anydesk.com, screenconnect.com, atera.com), traffic blends with legitimate MSP activity and is trusted by many egress controls. The install-then-immediately-connect-outbound pattern is the most reliable behavioural indicator.

Detections ManySignal ships

Ready-to-deploy detection rules

Rule name Severity Data source

Unauthorized RMM Binary Executed — AnyDesk, ScreenConnect, Atera not in sanctioned list

Execution of a known remote-access tool binary (AnyDesk.exe, ScreenConnect.ClientService.exe, AteraAgent.exe, SplashtopStreamer.exe) on a host or in a business unit where that tool is not the sanctioned RMM.

High EDR process telemetry

Install-Then-Outbound Pattern — RMM installed and connects to vendor cloud within 5 minutes

New installation of a remote-access tool followed within a short window by outbound DNS or TLS to the tool's cloud relay, consistent with attacker-initiated deployment rather than IT-scheduled rollout.

Critical EDR + DNS logs

RMM Process from Unusual Path — Remote access binary running from Temp, Downloads, or ProgramData

A remote-access tool executes from a user-writable directory (%TEMP%, %APPDATA%, Downloads, ProgramData root) rather than its normal Program Files installation path, indicating a portable or attacker-dropped copy.

High EDR process telemetry

Multiple RMM Tools on Single Host — Two or more distinct remote-access products installed

A single endpoint has two or more different remote-access tools installed simultaneously, a pattern strongly correlated with adversary redundancy rather than legitimate IT use.

High Software inventory / EDR

DNS to RMM Vendor Not in Sanctioned Set — Query to anydesk/screenconnect/atera domain from non-IT host

DNS resolution for a remote-access vendor domain from a host that is not part of the IT support fleet and where that vendor is not the enterprise-sanctioned RMM.

Medium DNS logs

T1219 Remote Access Software — Detection & Response: frequently asked questions

Why not just block all remote-access software?

Most organizations depend on one RMM for legitimate IT support, MSP delivery, or vendor access. The practical control is to sanction exactly one tool, allowlist its binary and cloud endpoints, and treat every other remote-access product as unauthorized. ManySignal ships a maintained catalog of RMM binaries and vendor domains to make this policy enforceable out of the box.

How is T1219 different from T1071 (Application Layer Protocol) for C2?

T1071 covers custom or generic use of protocols like HTTPS, DNS, or WebSocket for C2 traffic that the adversary controls end-to-end. T1219 specifically covers abuse of legitimate remote-access products where the vendor's cloud relay is the transport — the adversary does not need to stand up C2 infrastructure at all, which is why it is increasingly preferred.

Does ManySignal detect ScreenConnect abuse specifically?

Yes. ManySignal ships detections for ScreenConnect.ClientService.exe execution outside sanctioned paths, ScreenConnect installer MSI events, DNS to *.screenconnect.com and instance-specific subdomains, and the install-then-outbound behavioural pattern that characterizes the 2024 ScreenConnect authentication-bypass exploitation campaigns.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.