Back to Intelligence

RMM Tool Abuse in the Wild: Detecting and Blocking Unauthorized Remote Access Software After ScreenConnect Campaigns

SA
Security Arsenal Team
October 6, 2026
10 min read

The SANS Internet Storm Center is tracking a sustained and growing trend that every SOC needs to take seriously: threat actors are systematically abusing legitimate Remote Management and Monitoring (RMM) tools as their primary remote access and persistence mechanism. Following a recent ISC diary documenting ScreenConnect (ConnectWise) abuse observed in the wild, handlers have now identified additional RMM platforms being weaponized in active intrusions — and the pattern shows no sign of slowing.

This matters because RMM abuse is not a vulnerability in the traditional sense. There is no patch for it. These are legitimate, signed, commercially licensed products doing exactly what they were designed to do — provide remote access, command execution, file transfer, and unattended control. When an attacker drops AnyDesk, ScreenConnect, Atera, Splashtop, Tactical RMM, or MeshCentral on your endpoint, most security stacks see a trusted binary with a valid certificate and let it run. This technique — MITRE ATT&CK T1219 (Remote Access Software) — has become the preferred post-exploitation tooling for ransomware affiliates, initial access brokers, and even state-aligned operators precisely because it blends into enterprise noise.

If your organization cannot answer the question "which RMM tools are authorized here, and can we prove nothing else is running?" — you have a blind spot that adversaries are actively monetizing.

Technical Analysis

What Is Actually Happening

The campaign pattern documented by ISC handlers follows a repeatable playbook:

  1. Initial access is achieved through phishing, exposed remote services, or a prior compromise.
  2. The attacker installs or executes an RMM agent — often silently, using the vendor's own MSI installer with unattended/silent switches, or as a portable standalone executable that requires no installation at all.
  3. The RMM agent phones home to the vendor's legitimate cloud infrastructure (or a self-hosted relay, in the case of ScreenConnect, Tactical RMM, or MeshCentral), establishing an encrypted, outbound-only command-and-control channel that bypasses most perimeter controls.
  4. Persistence and lateral movement follow. The attacker now has interactive GUI access, a remote shell, file transfer, and in many cases the ability to push scripts and software to other managed endpoints — all under the cover of a signed, trusted application.

Why Traditional Controls Fail

  • Signed binaries: ScreenConnect, AnyDesk, TeamViewer, and similar agents carry valid code-signing certificates. Application whitelisting configured on publisher trust alone will wave them through.
  • Legitimate domains: C2 traffic rides the vendor's own cloud infrastructure (e.g., *.screenconnect.com, *.anydesk.com, vendor relay servers). Domain reputation feeds rarely flag these.
  • Outbound-only connections: Agents initiate connections outbound over 443/TCP, so no inbound firewall rule is violated.
  • Dual-use behavior: Every malicious action (remote shell, file transfer, service creation) is also a legitimate helpdesk action. Context — not the binary — determines maliciousness.

Exploitation Status

This is confirmed, active, in-the-wild abuse across multiple intrusion sets. RMM tooling has been a documented component of ransomware operations (including Black Basta, Akira, and multiple initial access broker playbooks) and is explicitly called out in joint CISA guidance on RMM abuse. Because no vulnerability is involved, there is no CVE and no KEV entry — the defense is entirely behavioral and policy-based.

Commonly Abused RMM Platforms (Observed in Real Intrusions)

  • ConnectWise ScreenConnect
  • AnyDesk
  • TeamViewer
  • Atera / Splashtop
  • Tactical RMM / MeshCentral (open-source, self-hosted — attacker infrastructure blends in nowhere)
  • SimpleHelp, N-able (N-Central/Take Control), LogMeIn/GoTo, DWService, RustDesk, UltraVNC

The defensive principle is identical regardless of vendor: anything not on your approved list is malicious until proven otherwise.

Detection & Response

This is a technical threat, and it is highly detectable — if you know your baseline. The single most important prerequisite is an authoritative allowlist of sanctioned RMM products. Every rule below assumes you will tune exclusions to your approved tooling. Without that allowlist, you will drown in false positives; with it, these detections are near-surgical.

Sigma Rules

YAML
---
title: Unauthorized RMM Tool Execution
description: Detects execution of commonly abused remote access and RMM tooling. Tune the filter against your organization's sanctioned RMM products. Threat actors increasingly deploy signed RMM agents (ScreenConnect, AnyDesk, Atera, MeshCentral, Tactical RMM, RustDesk) as a persistence and C2 mechanism per MITRE T1219.
logsource:
  category: process_creation
  product: windows
detection:
  selection_rmm:
    Image|endswith:
      - '\ScreenConnect.ClientService.exe'
      - '\ScreenConnect.WindowsClient.exe'
      - '\AnyDesk.exe'
      - '\AteraAgent.exe'
      - '\Splashtop\Remote\Server\SRServer.exe'
      - '\tacticalrmm.exe'
      - '\meshagent.exe'
      - '\MeshCentral.exe'
      - '\rustdesk.exe'
      - '\dwservice.exe'
      - '\simplehelp.exe'
      - '\UltraVNC\winvnc.exe'
  filter_authorized:
    Image|startswith:
      - 'C:\Program Files\YourApprovedRMM\'
  condition: selection_rmm and not filter_authorized
falsepositives:
  - Sanctioned helpdesk and MSP tooling — build and maintain an authoritative allowlist before enabling
level: high
---
title: Silent RMM Agent Installation via Msiexec
description: Detects silent or unattended MSI installation of RMM agents, a common technique where attackers push vendor installers with quiet switches to avoid user-visible prompts.
logsource:
  category: process_creation
  product: windows
detection:
  selection_installer:
    Image|endswith: '\msiexec.exe'
    CommandLine|contains:
      - '/qn'
      - '/quiet'
      - '/passive'
  selection_payload:
    CommandLine|contains:
      - 'screenconnect'
      - 'anydesk'
      - 'atera'
      - 'splashtop'
      - 'meshcentral'
      - 'tactical'
      - 'rustdesk'
      - 'simplehelp'
  condition: all of selection_*
falsepositives:
  - Legitimate software deployment via SCCM/Intune/PSP — correlate with your deployment tooling's service accounts and source machines
level: high
---
title: RMM Agent Execution from User-Writable or Temporary Paths
description: Detects RMM and remote access binaries executing from user profiles, temp directories, or other non-standard install locations. Portable RMM executables dropped by attackers almost never land in Program Files.
logsource:
  category: process_creation
  product: windows
detection:
  selection_paths:
    Image|contains:
      - '\AppData\Local\Temp\'
      - '\AppData\Roaming\'
      - '\Users\Public\'
      - '\ProgramData\'
      - '\Downloads\'
      - '$Recycle.Bin'
  selection_rmm_names:
    Image|endswith:
      - '\AnyDesk.exe'
      - '\ScreenConnect.ClientService.exe'
      - '\rustdesk.exe'
      - '\meshagent.exe'
      - '\TeamViewer.exe'
      - '\winvnc.exe'
  condition: all of selection_*
falsepositives:
  - Portable AnyDesk/TeamViewer quick-support sessions run by end users — investigate the initiating ticket or user request
level: high

KQL (Microsoft Sentinel / Defender)

KQL — Microsoft Sentinel / Defender
// Hunt: Unauthorized RMM process execution across the fleet
// Maintain the AuthorizedRMM list to reflect YOUR sanctioned tooling
let AuthorizedRMM = dynamic(["YourApprovedRMM.exe"]);
let RMMNames = dynamic([
    "ScreenConnect.ClientService.exe", "ScreenConnect.WindowsClient.exe",
    "AnyDesk.exe", "AteraAgent.exe", "tacticalrmm.exe", "meshagent.exe",
    "rustdesk.exe", "dwservice.exe", "simplehelp.exe", "winvnc.exe",
    "SRServer.exe", "TeamViewer_Service.exe"
]);
DeviceProcessEvents
| where TimeGenerated > ago(7d)
| where FileName in~ (RMMNames) and FileName !in~ (AuthorizedRMM)
| summarize FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated),
    CommandLines = make_set(ProcessCommandLine, 5),
    InitiatingAccounts = make_set(InitiatingProcessAccountName, 5)
    by DeviceName, FileName, FolderPath, SHA256
| extend SuspiciousPath = FolderPath has_any ("Temp", "Public", "Downloads", "Roaming", "ProgramData")
| sort by SuspiciousPath desc, FirstSeen asc;
KQL — Microsoft Sentinel / Defender
// Hunt: Network connections to RMM vendor infrastructure
// Useful where process telemetry is gapped; catches agent beaconing
let RMMDomains = dynamic([
    "screenconnect.com", "anydesk.com", "anydesk.net",
    "atera.com", "splashtop.com", "meshcentral.com",
    "rustdesk.com", "simple-help.com", "dwservice.net"
]);
DeviceNetworkEvents
| where TimeGenerated > ago(7d)
| where RemoteUrl has_any (RMMDomains)
| summarize Connections = count(), FirstSeen = min(TimeGenerated),
    RemoteIPs = make_set(RemoteIP, 10), Ports = make_set(RemotePort, 10)
    by DeviceName, InitiatingProcessFileName, InitiatingProcessFolderPath, RemoteUrl
| order by Connections desc;

Velociraptor VQL

VQL — Velociraptor
-- Hunt for unauthorized RMM agent processes and their network connections
-- Deploy as a fleet-wide hunt; review hits against your sanctioned RMM allowlist
SELECT Pid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE Name =~ '(?i)(screenconnect|anydesk|atera|tacticalrmm|meshagent|rustdesk|dwservice|simplehelp|winvnc|teamviewer)'
   OR Exe =~ '(?i)(screenconnect|anydesk|atera|tactical|mesh|rustdesk)'
VQL — Velociraptor
-- Hunt for RMM persistence artifacts: services registered by remote access tooling
SELECT Name, DisplayName, PathName, StartName, StartMode, State
FROM wmi_query(namespace='root/cimv2',
               query='SELECT Name, DisplayName, PathName, StartName, StartMode, State FROM Win32_Service')
WHERE PathName =~ '(?i)(screenconnect|anydesk|atera|splashtop|meshagent|rustdesk|dwservice|simplehelp)'

Remediation Script (PowerShell)

PowerShell
# ============================================================
# Audit-and-Remove: Unauthorized RMM Tooling
# Run elevated. STEP 1 = audit only. Set $Remediate = $true to remove.
# ============================================================
$Remediate = $false   # Flip to $true ONLY after reviewing audit output
$AuthorizedRMM = @()  # e.g. @('YourApprovedRMM') — names to EXCLUDE from action

$RMMPatterns = @(
    'ScreenConnect','AnyDesk','Atera','Splashtop','TacticalRMM',
    'MeshCentral','RustDesk','DWService','SimpleHelp','UltraVNC',
    'LogMeIn','GoToMyPC','N-able','Take Control'
)

# --- 1. Audit installed software (both registry hives) ---
$uninstallKeys = @(
    'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*',
    'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*',
    'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*'
)
$installed = Get-ItemProperty $uninstallKeys -ErrorAction SilentlyContinue |
    Where-Object { $_.DisplayName -and ($RMMPatterns | ForEach-Object { $_ } | Where-Object { $false }) -eq $null }  # placeholder guard
$installed = Get-ItemProperty $uninstallKeys -ErrorAction SilentlyContinue |
    Where-Object { $d = $_.DisplayName; $d -and ($RMMPatterns | Where-Object { $d -match [regex]::Escape($_) }) } |
    Select-Object DisplayName, DisplayVersion, Publisher, InstallDate, UninstallString, PSPath

# --- 2. Audit running processes and services ---
$procs = Get-Process | Where-Object { $n = $_.Name; $RMMPatterns | Where-Object { $n -match $_ } } |
    Select-Object Name, Id, Path
$services = Get-CimInstance Win32_Service |
    Where-Object { $p = $_.PathName; $p -and ($RMMPatterns | Where-Object { $p -match $_ }) } |
    Select-Object Name, DisplayName, State, StartMode, PathName

Write-Host "=== INSTALLED RMM SOFTWARE ==="; $installed | Format-Table -AutoSize
Write-Host "=== RUNNING RMM PROCESSES ===";   $procs     | Format-Table -AutoSize
Write-Host "=== RMM SERVICES ===";            $services  | Format-Table -AutoSize
$installed,$procs,$services | Export-Csv ".\RMM_Audit_$(Get-Date -Format yyyyMMdd_HHmm).csv" -NoTypeInformation

# --- 3. Optional remediation: stop services, kill processes, uninstall ---
if ($Remediate) {
    foreach ($svc in $services) {
        $isAuth = $AuthorizedRMM | Where-Object { $svc.DisplayName -match $_ }
        if (-not $isAuth) {
            Stop-Service -Name $svc.Name -Force -ErrorAction SilentlyContinue
            Set-Service  -Name $svc.Name -StartupType Disabled -ErrorAction SilentlyContinue
            Write-Host "[+] Disabled service: $($svc.Name)"
        }
    }
    foreach ($p in $procs) {
        $isAuth = $AuthorizedRMM | Where-Object { $p.Name -match $_ }
        if (-not $isAuth) { Stop-Process -Id $p.Id -Force -ErrorAction SilentlyContinue }
    }
    foreach ($app in $installed) {
        $isAuth = $AuthorizedRMM | Where-Object { $app.DisplayName -match $_ }
        if (-not $isAuth -and $app.UninstallString -match 'msiexec') {
            $guid = [regex]::Match($app.UninstallString,'\{[0-9A-Fa-f-]+\}').Value
            Start-Process msiexec.exe -ArgumentList "/x $guid /qn /norestart" -Wait
            Write-Host "[+] Uninstalled: $($app.DisplayName)"
        }
    }
}

Remediation & Hardening

There is no patch for RMM abuse — the defense is architectural. Prioritize in this order:

  1. Establish the authoritative allowlist. Document every sanctioned remote access product, its publisher, expected install path, service names, and approved use cases. This is the foundation for every detection above.
  2. Application control for everything else. Enforce WDAC or AppLocker rules that block execution of non-approved RMM binaries — including portable executables. Block by product name and publisher where feasible, but assume attackers will try renamed binaries; path- and hash-based rules for known-abused tools add a second layer.
  3. Network egress filtering. Restrict outbound access to RMM vendor domains/relay infrastructure for all hosts except approved management servers. Pay special attention to self-hosted platforms (ScreenConnect relays, MeshCentral, Tactical RMM) where the C2 destination is attacker-controlled infrastructure, not a known vendor domain — hunt for agents with unusual relay URLs.
  4. Alert on silent installs. Any msiexec with /qn or /quiet referencing remote access tooling, executed outside your deployment pipeline (SCCM/Intune/PSP service accounts), is a high-fidelity alert.
  5. Hunt quarterly, at minimum. RMM agents are quiet. Run the KQL and VQL hunts above on a scheduled basis and after every incident involving initial access.
  6. Educate the helpdesk. Confirm that your support staff's quick-support tooling (portable TeamViewer/AnyDesk sessions) is documented and ticket-correlated, so analyst time is not burned on sanctioned activity.

CISA and NSA joint guidance on RMM abuse explicitly recommends inventorying authorized remote access tools, blocking unauthorized ones at the application and network layer, and monitoring for their artifacts — treat this as the compliance baseline for your program.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.

RMM Tool Abuse in the Wild: Detecting and Blocking Unauthorized Remote Access Software After ScreenConnect Campaigns | Security Arsenal | Security Arsenal