Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Persistence/ T1133

T1133External Remote Services

T1133 — External Remote Services is a MITRE ATT&CK technique in the Persistence tactic. Clankerusecase tracks 52 detection use cases covering it and 8 threat-intel articles citing it.

PersistenceInitial Access
View on the matrix → Filter Detection Library MITRE official spec ↗
52Use cases
8Articles
0Sub-techniques
2Tactics

Use cases covering this technique (52)

[WEEKLY] AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation Internal exploit · alerting DSΣPDDCS [WEEKLY] Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) Internal exploit · alerting DSPDD [WEEKLY] Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request Internal actions · alerting DSPDD [WEEKLY] Internet-Exposed AI Agent/LLM Service Spawns Shell or LOLBin After Inbound Connection Internal exploit · alerting DSΣPDDCS [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Internal exploit · alerting DSΣPDD [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write Internal exploit · alerting DSPDD Detect Exchange Web Shell ESCU actions · alerting P Exchange PowerShell Abuse via SSRF ESCU actions · alerting P Java Writing JSP File ESCU actions · alerting P Living Off The Land Detection ESCU actions · alerting P Log4Shell CVE-2021-44228 Exploitation ESCU actions · alerting P MS Exchange Mailbox Replication service writing Active Server Pages ESCU actions · alerting P Outbound Network Connection from Java Using Default Ports ESCU actions · alerting P PaperCut NG Suspicious Behavior Debug Log ESCU actions · hunting P Web or Application Server Spawning a Shell ESCU actions · alerting P Windows MOVEit Transfer Writing ASPX ESCU actions · alerting P Windows PaperCut NG Spawn Shell ESCU actions · alerting P Windows RDPClient Connection Sequence Events ESCU actions · hunting P Cisco Network Interface Modifications ESCU actions · hunting P F5 BIG-IP iControl REST Vulnerability CVE-2022-1388 ESCU actions · alerting P Confluence Unauthenticated Remote Code Execution CVE-2022-26134 ESCU actions · alerting P Detect attackers scanning for vulnerable JBoss servers ESCU actions · alerting P Exploit Public Facing Application via Apache Commons Text ESCU actions · hunting P Exploit Public-Facing Fortinet FortiNAC CVE-2022-39952 ESCU actions · alerting P Fortinet Appliance Auth bypass ESCU actions · alerting P Hunting for Log4Shell ESCU actions · hunting P Ivanti EPMM Remote Unauthenticated API Access CVE-2023-35078 ESCU actions · alerting P Ivanti EPMM Remote Unauthenticated API Access CVE-2023-35082 ESCU actions · alerting P Log4Shell JNDI Payload Injection Attempt ESCU actions · hunting P Log4Shell JNDI Payload Injection with Outbound Connection ESCU actions · hunting P PaperCut NG Remote Web Access Attempt ESCU actions · alerting P ProxyShell ProxyNotShell Behavior Detected ESCU actions · alerting P Spring4Shell Payload URL Request ESCU actions · alerting P Supernova Webshell ESCU actions · alerting P VMWare Aria Operations Exploit Attempt ESCU actions · alerting P VMware Server Side Template Injection Hunt ESCU actions · hunting P VMware Workspace ONE Freemarker Server-side Template Injection ESCU actions · hunting P Web JSP Request via URL ESCU actions · alerting P Web Spring4Shell HTTP Request Class Module ESCU actions · alerting P Web Spring Cloud Function FunctionRouter ESCU actions · alerting P Windows Exchange Autodiscover SSRF Abuse ESCU actions · alerting P Linux Java Spawning Shell ESCU actions · alerting P Windows Java Spawning Shells ESCU actions · alerting P [LLM] Inbound Screen Sharing (VNC port 5900) from a public IP to a Mac — CVE-2026-65400 exposure Bespoke exploit · hunting DSΣPCS [LLM] Corporate sign-in from DPRK IT-worker VPS / AstrillVPN infrastructure (Famous Chollima) Bespoke delivery · hunting DSΣPDD [LLM] Managed endpoint network egress to DPRK IT-worker VPS / AstrillVPN IPs Bespoke c2 · hunting DSΣPDDCS [LLM] Nuxt dev server bound to non-loopback interface (nuxi/nuxt dev --host) Bespoke delivery · hunting DSΣPDDCS [LLM] AnyDesk silent/unattended install used for DragonForce access Bespoke c2 · alerting DSΣPDDCS [LLM] Flyto2 flyto-verification unauthenticated POST /run on :8344 (CVE-2026-67426 SSRF entry) Bespoke exploit · hunting DSΣPCS [LLM] Unauthenticated inbound SFTP to goshs followed by remote file operations Bespoke actions · hunting DSPDDCS [LLM] Node.js debugger/inspector launched bound to all network interfaces (CVE-2018-12120/-13567) Bespoke exploit · alerting DSΣPDDCS [LLM] Remote (non-loopback) connection to an exposed Node.js debug/inspect port 5858/9229 Bespoke exploit · alerting DSPDDCS

Articles citing this technique (8)