T1219 Remote Access Software — Detection & Response
An adversary may use legitimate desktop support and remote access software to establish an interactive command and control channel to target systems within networks. These services, such as AnyDesk, TeamViewer, ScreenConnect, Splashtop, Atera, and LogMeIn, are commonly used as legitimate technical support software and may be allowed by application control within a target environment. Remote access software may be installed and used post-compromise as an alternate communications channel for redundant access or as a way to establish an interactive remote desktop session with the target system.
Coverage at a glance
- Detections shipped
- 5
- Avg. verdict time
- < 5 min
- Data sources
- 4+
Threat context
How adversaries use T1219 Remote Access Software — Detection & Response
An adversary may use legitimate desktop support and remote access software to establish an interactive command and control channel to target systems within networks. These services, such as AnyDesk, TeamViewer, ScreenConnect, Splashtop, Atera, and LogMeIn, are commonly used as legitimate technical support software and may be allowed by application control within a target environment. Remote access software may be installed and used post-compromise as an alternate communications channel for redundant access or as a way to establish an interactive remote desktop session with the target system.
Remote monitoring and management (RMM) tools have become a dominant C2 channel across ransomware, business email compromise, and access-broker operations because they combine legitimate code-signing, encrypted transport to well-known cloud endpoints, and interactive keyboard-and-mouse control in a single package. Groups such as Scattered Spider, BlackCat/ALPHV affiliates, and the operators behind ScreenConnect abuse campaigns routinely drop AnyDesk, ScreenConnect, Splashtop, or Atera within minutes of gaining initial access, either via phishing lures directed at the help desk or via silent installers pushed after initial exploitation. Because the tools use cloud relays (anydesk.com, screenconnect.com, atera.com), traffic blends with legitimate MSP activity and is trusted by many egress controls. The install-then-immediately-connect-outbound pattern is the most reliable behavioural indicator.
Detections ManySignal ships
Ready-to-deploy detection rules
| Rule name | Severity | Data source |
|---|---|---|
| Unauthorized RMM Binary Executed — AnyDesk, ScreenConnect, Atera not in sanctioned list Execution of a known remote-access tool binary (AnyDesk.exe, ScreenConnect.ClientService.exe, AteraAgent.exe, SplashtopStreamer.exe) on a host or in a business unit where that tool is not the sanctioned RMM. | High | EDR process telemetry |
| Install-Then-Outbound Pattern — RMM installed and connects to vendor cloud within 5 minutes New installation of a remote-access tool followed within a short window by outbound DNS or TLS to the tool's cloud relay, consistent with attacker-initiated deployment rather than IT-scheduled rollout. | Critical | EDR + DNS logs |
| RMM Process from Unusual Path — Remote access binary running from Temp, Downloads, or ProgramData A remote-access tool executes from a user-writable directory (%TEMP%, %APPDATA%, Downloads, ProgramData root) rather than its normal Program Files installation path, indicating a portable or attacker-dropped copy. | High | EDR process telemetry |
| Multiple RMM Tools on Single Host — Two or more distinct remote-access products installed A single endpoint has two or more different remote-access tools installed simultaneously, a pattern strongly correlated with adversary redundancy rather than legitimate IT use. | High | Software inventory / EDR |
| DNS to RMM Vendor Not in Sanctioned Set — Query to anydesk/screenconnect/atera domain from non-IT host DNS resolution for a remote-access vendor domain from a host that is not part of the IT support fleet and where that vendor is not the enterprise-sanctioned RMM. | Medium | DNS logs |
Related techniques and tactics
T1078 Valid Accounts — Detection & Response
ATT&CK Technique
T1110 Brute Force — Detection & Response
ATT&CK Technique
T1566 Phishing — Detection & Response
ATT&CK Technique
T1059 Command and Scripting Interpreter — Detection & Response
ATT&CK Technique
T1053 Scheduled Task/Job — Detection & Response
ATT&CK Technique
T1548 Abuse Elevation Control Mechanism — Detection & Response
ATT&CK Technique
T1068 Exploitation for Privilege Escalation — Detection & Response
ATT&CK Technique
T1134 Access Token Manipulation — Detection & Response
ATT&CK Technique
T1098 Account Manipulation — Detection & Response
ATT&CK Technique
T1136 Create Account — Detection & Response
ATT&CK Technique
T1556 Modify Authentication Process — Detection & Response
ATT&CK Technique
T1621 Multi-Factor Authentication Request Generation — Detection & Response
ATT&CK Technique
T1219 Remote Access Software — Detection & Response: frequently asked questions
Why not just block all remote-access software?
Most organizations depend on one RMM for legitimate IT support, MSP delivery, or vendor access. The practical control is to sanction exactly one tool, allowlist its binary and cloud endpoints, and treat every other remote-access product as unauthorized. ManySignal ships a maintained catalog of RMM binaries and vendor domains to make this policy enforceable out of the box.
How is T1219 different from T1071 (Application Layer Protocol) for C2?
T1071 covers custom or generic use of protocols like HTTPS, DNS, or WebSocket for C2 traffic that the adversary controls end-to-end. T1219 specifically covers abuse of legitimate remote-access products where the vendor's cloud relay is the transport — the adversary does not need to stand up C2 infrastructure at all, which is why it is increasingly preferred.
Does ManySignal detect ScreenConnect abuse specifically?
Yes. ManySignal ships detections for ScreenConnect.ClientService.exe execution outside sanctioned paths, ScreenConnect installer MSI events, DNS to *.screenconnect.com and instance-specific subdomains, and the install-then-outbound behavioural pattern that characterizes the 2024 ScreenConnect authentication-bypass exploitation campaigns.
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.