Techniques › T1219 › T1219.002
T1219.002 Remote Desktop Software
command and control — Linux, macOS, Windows · attack.mitre.org · JSON
1
MITRE detection strategy
3
analytics
46
Sigma rules tagged attack.t1219.002
0
KEV CVEs mapped here
<p>An adversary may use legitimate desktop support software to establish an interactive command and control channel to target systems within networks. Desktop support software provides a graphical interface for remotely controlling another computer, transmitting the display output, keyboard input, and mouse control between devices using various protocols. Desktop support software, such as
VNC, Team Viewer, AnyDesk, ScreenConnect, LogMein, AmmyyAdmin, and other remote monitoring and management (RMM) tools, are commonly used as legitimate technical support software and may be allowed by application control within a target environment.</p><p>Remote access modules/features may also exist as part of otherwise existing software such as Zoom or Google Chrome’s Remote Desktop.</p>KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0259 Remote Desktop Software Execution and Beaconing Detection v1.0
AN0714 WindowsAdversary installation or use of RMM software (e.g., TeamViewer, AnyDesk, ScreenConnect) followed by outbound beaconing or remote session establishmentWinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall
new rule allowing inbound or outbound connections for remote desktop software→ DC0051 Firewall Rule ModificationTunable:ImageDestinationPortParentImageTimeWindowAN0715 LinuxExecution of known or custom VNC/remote desktop daemons or tunneling agents that initiate external communication after launchNSM:Flowoutbound connections to RMM services or to unusual destination ports→ DC0082 Network Connection CreationTunable:binary_nameOutboundIPRangeAN0716 macOSInitiation of remote desktop sessions via AnyDesk, TeamViewer, or Chrome Remote Desktop accompanied by unexpected user logins or system modificationsmacos:unifiedlognetwork sessions initiated by remote desktop apps→ DC0082 Network Connection CreationTunable:process_signaturesandbox_exception
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1219.002
Author: Florian Roth (Nextron Systems)
· 2022-05-20 (modified 2025-02-24) · logsource: product=windows category=process_creation · 065b00ca-5d5c-4557-ac95-64a6d0b64d86
An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks.
These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment.
Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
Author: frack113
· 2022-02-11 (modified 2024-07-20) · logsource: product=windows category=file_event · 0b9ad457-2554-44c1-82c2-d56a99c42377
An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks.
These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment.
Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
Author: Arnim Rupp (Nextron Systems)
· 2026-06-15 · logsource: category=antivirus · 101a1877-2cf4-474d-abfd-7f6ac4788d1a
Detects a highly relevant Antivirus alert that reports APT malware.
This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
Author: Ján Trenčanský
· 2021-08-06 (modified 2023-03-05) · logsource: product=windows category=process_creation · 114e7f1c-f137-48c8-8f54-3088c24ce4b9
Detects AnyDesk Remote Desktop silent installation. Which can be used by attackers to gain remote access.
Author: frack113
· 2022-10-02 · logsource: product=windows category=process_creation · 145322e4-0fd3-486b-81ca-9addc75736d8
An adversary may use legitimate desktop support and remote access software,to establish an interactive command and control channel to target systems within networks
Author: Florian Roth (Nextron Systems)
· 2022-01-30 · logsource: product=windows category=file_event · 162ab1e4-6874-4564-853c-53ec3ab8be01
Detects the creation of log files during a TeamViewer remote session
Author: Norbert Jaśniewicz (AlphaSOC)
· 2025-05-19 · logsource: product=macos category=process_creation · 22c45af6-f590-4d44-bab3-b5b2d2a2b6d9
Detects potential execution of MeshAgent which is a tool used for remote access.
Historical data shows that threat actors rename MeshAgent binary to evade detection.
Matching command lines with the '--meshServiceName' argument can indicate that the MeshAgent is being used for remote access.
Author: Florian Roth (Nextron Systems), Arnim Rupp
· 2018-09-09 (modified 2026-06-15) · logsource: category=antivirus · 238527ad-3c2c-4e4f-a1f6-92fd63adb864
Detects a highly relevant Antivirus alert that reports an exploitation framework.
This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-09-28 (modified 2025-02-24) · logsource: product=windows category=file_event · 2d367498-5112-4ae5-a06a-96e7bc33a211
Detects AnyDesk writing binary files to disk other than "gcapi.dll".
According to RedCanary research it is highly abnormal for AnyDesk to write executable files to disk besides gcapi.dll,
which is a legitimate DLL that is part of the Google Chrome web browser used to interact with the Google Cloud API. (See reference section for more details)
Author: Norbert Jaśniewicz (AlphaSOC)
· 2025-05-19 · logsource: product=windows category=process_creation · 2fbbe9ff-0afc-470b-bdc0-592198339968
Detects potential execution of MeshAgent which is a tool used for remote access.
Historical data shows that threat actors rename MeshAgent binary to evade detection.
Matching command lines with the '--meshServiceName' argument can indicate that the MeshAgent is being used for remote access.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2024-06-27 · logsource: product=windows category=file_event · 3ab79e90-9fab-4cdf-a7b2-6522bc742adb
Detects the creation of file with specific names used by RemoteKrbRelay SMB Relay attack module.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-11-28 · logsource: product=windows service=system · 4bb79b62-ef12-4861-981d-2aab43fab642
Detects a TacticalRMM service installation. Tactical RMM is a remote monitoring & management tool.
Author: frack113, Connor Martin
· 2022-07-11 (modified 2024-12-17) · logsource: product=windows category=dns_query · 4d07b1f4-cb00-4470-b9f8-b0191d48ff52
An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks.
These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment.
Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
Author: Samir Bousseaden
· 2019-02-21 (modified 2021-11-27) · logsource: product=windows category=file_event · 52753ea4-b3a0-4365-910d-36cff487b789
Detects the usage of tsclient share to place a backdoor on the RDP source machine's startup folder
Author: frack113
· 2022-02-13 (modified 2023-03-05) · logsource: product=windows category=process_creation · 57bff678-25d1-4d6c-8211-8ca106d12053
An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks.
These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment.
Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
Author: frack113
· 2022-02-13 · logsource: product=windows category=file_event · 5d756aee-ad3e-4306-ad95-cb1abec48de2
An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks.
These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment.
Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
Author: Nasreddine Bencherchali (Nextron Systems), Christopher Peacock @securepeacock
· 2023-04-18 (modified 2023-04-30) · logsource: product=windows category=process_creation · 5fdce3ac-e7f9-4ecd-a3aa-a4d78ebbf0af
Detects potential RDP connection via Mstsc using a local ".rdp" file
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-04-18 · logsource: product=windows category=process_creation · 6e22722b-dfb1-4508-a911-49ac840b40f8
Detects potential RDP connection via Mstsc using a local ".rdp" file located in suspicious locations.
Author: Luca Di Bartolomeo
· 2024-06-22 · logsource: product=windows category=image_load · 6f6afac3-8e7a-4e4b-9588-2608ffe08f82
Detects potential CSharp Streamer RAT loading .NET executable image by using the default file name and path associated with the tool.
Author: Dusty Miller
· 2023-02-23 · logsource: product=windows category=dns_query · 70761fe8-6aa2-4f80-98c1-a57049c08e66
Detects a DNS query initiated from a "wscript" process for domains matching a specific pattern that was seen being used by SocGholish for its Command and Control traffic
Author: @Kostastsale
· 2024-09-22 · logsource: product=windows category=process_creation · 74a2b202-73e0-4693-9a3a-9d36146d0775
Detects the use of MeshAgent to execute commands on the target host, particularly when threat actors might abuse it to execute commands directly.
MeshAgent can execute commands on the target host by leveraging win-console to obscure their activities and win-dispatcher to run malicious code through IPC with child processes.
Author: frack113
· 2022-09-25 (modified 2023-03-06) · logsource: product=windows category=process_creation · 758ff488-18d5-4cbe-8ec4-02b6285a434f
An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks.
These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment.
Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
Author: Florian Roth (Nextron Systems)
· 2022-01-30 (modified 2023-09-18) · logsource: product=windows category=dns_query · 778ba9a8-45e4-4b80-8e3e-34a419f0b85e
Detects DNS queries to a TeamViewer domain only resolved by a TeamViewer client by an image that isn't named TeamViewer (sometimes used by threat actors for obfuscation)
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), @Kostastsale
· 2022-02-25 (modified 2024-02-28) · logsource: product=windows category=process_creation · 7b582f1a-b318-4c6a-bf4e-66fe49bf55a5
Detects potentially suspicious child processes launched via the ScreenConnect client service.
Author: Bhabesh Raj
· 2021-09-01 (modified 2022-12-25) · logsource: product=windows service=application · 87261fb2-69d0-42fe-b9de-88c6b5f65a43
Detects successful installation of Atera Remote Monitoring & Management (RMM) agent as recently found to be used by Conti operators
Author: frack113
· 2022-09-25 (modified 2024-03-14) · logsource: product=windows category=process_creation · 88656cec-6c3b-487c-82c0-f73ebb805503
An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks.
These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment.
Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
Author: Nasreddine Bencherchali (Nextron Systems)
· 2024-02-23 · logsource: product=windows category=process_creation · 95e60a2b-4705-444b-b7da-ba0ea81a3ee2
An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks.
These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment.
Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
Author: frack113
· 2022-01-28 · logsource: product=windows category=file_event · 9711de76-5d4f-4c50-a94f-21e4e8f8384d
TeamViewer_Desktop.exe is create during install
Author: Arnim Rupp (Nextron Systems)
· 2026-06-15 · logsource: category=antivirus · 97233998-3838-4581-88c6-f1d19d3993fb
Detects a highly relevant Antivirus alert that reports a remote access tool.
This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
Author: Florian Roth (Nextron Systems)
· 2018-03-17 (modified 2022-05-27) · logsource: product=windows category=process_creation · 9847f263-4a81-424f-970c-875dab15b79b
Detects a tscon.exe start as LOCAL SYSTEM
Author: @kostastsale
· 2023-04-13 · logsource: product=windows category=process_creation · aa3168fb-d594-4f93-a92d-7a9ba675b766
Detects the execution of Action1 in order to execute arbitrary code or establish a remote session.
Action1 is a powerful Remote Monitoring and Management tool that enables users to execute commands, scripts, and binaries.
Through the web interface of action1, the administrator must create a new policy or an app to establish remote execution and then points that the agent is installed.
Hunting Opportunity 1- Weed Out The Noise
When threat actors execute a script, a command, or a binary through these new policies and apps, the names of these become visible in the command line during the execution process. Below is an example of the command line that contains the deployment of a binary through a policy with name "test_app_1":
ParentCommandLine: "C:\WINDOWS\Action1\action1_agent.exe schedule:Deploy_App__test_app_1_1681327673425 runaction:0"
After establishing a baseline, we can split the command to extract the policy name and group all the policy names and inspect the results with a list of frequency occurrences.
Hunting Opportunity 2 - Remote Sessions On Out Of Office Hours
If you have admins within your environment using remote sessions to administer endpoints, you can create a threat-hunting query and modify the time of the initiated sessions looking for abnormal activity.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-09-28 (modified 2023-03-05) · logsource: product=windows category=process_creation · b1377339-fda6-477a-b455-ac0923f9ec2c
Detects piping the password to an anydesk instance via CMD and the '--set-password' flag.
Author: Norbert Jaśniewicz (AlphaSOC)
· 2025-05-19 · logsource: product=windows category=process_creation · b471f462-eb0d-4832-be35-28d94bdb4780
Detects the execution of a renamed instance of the Remote Monitoring and Management (RMM) tool, MeshAgent.
RMM tools such as MeshAgent are commonly utilized by IT administrators for legitimate remote support and system management.
However, malicious actors may exploit these tools by renaming them to bypass detection mechanisms, enabling unauthorized access and control over compromised systems.
Author: frack113
· 2022-02-11 (modified 2025-02-24) · logsource: product=windows category=process_creation · b52e84a3-029e-4529-b09b-71d19dd27e94
An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks.
These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment.
Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
Author: frack113
· 2022-02-13 (modified 2023-03-05) · logsource: product=windows category=process_creation · b6d98a4f-cef0-4abf-bbf6-24132854a83d
An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks.
These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment.
Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-10-24 (modified 2024-06-27) · logsource: product=windows category=file_event · bb09dd3e-2b78-4819-8e35-a7c1b874e449
Detects the presence and execution of Inveigh via dropped artefacts
Author: Norbert Jaśniewicz (AlphaSOC)
· 2025-05-19 · logsource: product=macos category=process_creation · bd3b5eaa-439d-4a42-8f35-a49f5c8a2582
Detects the execution of a renamed instance of the Remote Monitoring and Management (RMM) tool, MeshAgent.
RMM tools such as MeshAgent are commonly utilized by IT administrators for legitimate remote support and system management.
However, malicious actors may exploit these tools by renaming them to bypass detection mechanisms, enabling unauthorized access and control over compromised systems.
Author: James Pemberton
· 2020-05-22 (modified 2021-11-27) · logsource: product=windows service=ntlm · ce5678bb-b9aa-4fb5-be4b-e57f686256ad
Detects logons using NTLM to hosts that are potentially not part of the domain.
Author: Muhammad Faisal
· 2023-08-02 · logsource: product=windows category=process_creation · d20ee2f4-822c-4827-9e15-41500b1fff10
Detects potential Amazon SSM agent hijack attempts as outlined in the Mitiga research report.
Author: @d4ns4n_ (Wuerth-Phoenix)
· 2024-09-02 (modified 2025-02-24) · logsource: product=windows category=network_connection · d58ba5c6-0ed7-4b9d-a433-6878379efda9
Detects incoming connections to AnyDesk. This could indicate a potential remote attacker trying to connect to a listening instance of AnyDesk and use it as potential command and control channel.
Author: frack113
· 2022-02-11 (modified 2023-03-05) · logsource: product=windows category=process_creation · d85873ef-a0f8-4c48-a53a-6b621f11729d
An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks.
These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment.
Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
Author: Nasreddine Bencherchali (Nextron Systems)
· 2024-06-24 · logsource: product=windows category=dns_query · e043f529-8514-4205-8ab0-7f7d2927b400
Detects a DNS query by a non browser process on the system to "azurewebsites.net". The latter was often used by threat actors as a malware hosting and exfiltration site.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-11-28 · logsource: product=windows service=system · e0d1ad53-c7eb-48ec-a87a-72393cc6cedc
Detects a Mesh Agent service installation. Mesh Agent is used to remotely manage computers
Author: Muhammad Faisal (@faisalusuf)
· 2024-12-19 · logsource: product=windows category=process_creation · e20b5b14-ce93-4230-88af-981983ef6e74
Detects the execution of Microsoft Quick Assist tool "QuickAssist.exe". This utility can be used by attackers to gain remote access.
Author: Muhammad Faisal
· 2023-08-03 · logsource: product=linux category=process_creation · f9b3edc5-3322-4fc7-8aa3-245d646cc4b7
Detects potential Amazon SSM agent hijack attempts as outlined in the Mitiga research report.
Author: frack113
· 2022-02-13 · logsource: product=windows category=file_event · fec96f39-988b-4586-b746-b93d59fd1922
An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks.
These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment.
Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
Rules tagged at the parent level (attack.t1219) 6
These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-09-28 (modified 2025-10-29) · logsource: product=windows category=process_creation · 2cf29f11-e356-4f61-98c0-1bdb9393d6da
Detects renamed Visual Studio Code tunnel execution. Attackers can abuse this functionality to establish a C2 channel
Remote Access Tool - TacticalRMM Agent Registration to Potentially Attacker-Controlled Server
mediumexperimental
Author: Ahmed Nosir (@egycondor)
· 2025-05-29 · logsource: product=windows category=process_creation · 2db93a3f-3249-4f73-9e68-0e77a0f8ae7e
Detects TacticalRMM agent installations where the --api, --auth, and related flags are used on the command line.
These parameters configure the agent to connect to a specific RMM server with authentication, client ID, and site ID.
This technique could indicate a threat actor attempting to register the agent with an attacker-controlled RMM infrastructure silently.
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-08-29 · logsource: product=windows category=process_creation · 4bc90587-e6ca-4b41-be0b-ed4d04e4ed0c
Detects the suspicious use of the Velociraptor DFIR tool to execute other tools or download additional payloads, as seen in a campaign where it was abused for remote access and to stage further attacks.
Author: @kostastsale
· 2026-02-19 · logsource: product=windows category=process_creation · 7f3a9c2d-4e8b-4a7f-9d3e-5c6f8a9b2e1d
Detects the OpenEDR ssh-shellhost.exe spawning a command shell (cmd.exe) or PowerShell with PTY (pseudo-terminal) capabilities.
This may indicate remote command execution through OpenEDR's remote management features, which could be legitimate administrative activity or potential abuse of the remote access tool.
Threat actors may leverage OpenEDR's remote shell capabilities to execute commands on compromised systems, facilitating lateral movement or other command-and-control operations.
Author: Nasreddine Bencherchali (Nextron Systems), citron_ninja
· 2023-10-25 (modified 2025-10-29) · logsource: product=windows category=process_creation · 90d6bd71-dffb-4989-8d86-a827fedd6624
Detects Visual Studio Code tunnel execution. Attackers can abuse this functionality to establish a C2 channel
Author: @kostastsale
· 2026-02-19 · logsource: product=windows category=file_event · 9e4b7d3a-6f2c-4e9a-8d1b-3c5e7a9f2b4d
Detects the creation of potentially suspicious files by OpenEDR's ITSMService process.
The ITSMService is responsible for remote management operations and can create files on the system through the Process Explorer or file management features.
While legitimate for IT operations, creation of executable or script files could indicate unauthorized file uploads, data staging, or malicious file deployment.