T1133External Remote Services
T1133 — External Remote Services is a MITRE ATT&CK technique in the Persistence tactic. Clankerusecase tracks 51 detection use cases covering it and 6 threat-intel articles citing it.
PersistenceInitial Access
51Use cases
6Articles
0Sub-techniques
2Tactics
Use cases covering this technique (51)
[WEEKLY] AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation [WEEKLY] Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) [WEEKLY] Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request [WEEKLY] Internet-Exposed AI Agent/LLM Service Spawns Shell or LOLBin After Inbound Connection [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write Detect Exchange Web Shell Exchange PowerShell Abuse via SSRF Java Writing JSP File Living Off The Land Detection Log4Shell CVE-2021-44228 Exploitation MS Exchange Mailbox Replication service writing Active Server Pages Outbound Network Connection from Java Using Default Ports PaperCut NG Suspicious Behavior Debug Log Web or Application Server Spawning a Shell Windows MOVEit Transfer Writing ASPX Windows PaperCut NG Spawn Shell Windows RDPClient Connection Sequence Events Cisco Network Interface Modifications F5 BIG-IP iControl REST Vulnerability CVE-2022-1388 Confluence Unauthenticated Remote Code Execution CVE-2022-26134 Detect attackers scanning for vulnerable JBoss servers Exploit Public Facing Application via Apache Commons Text Exploit Public-Facing Fortinet FortiNAC CVE-2022-39952 Fortinet Appliance Auth bypass Hunting for Log4Shell Ivanti EPMM Remote Unauthenticated API Access CVE-2023-35078 Ivanti EPMM Remote Unauthenticated API Access CVE-2023-35082 Log4Shell JNDI Payload Injection Attempt Log4Shell JNDI Payload Injection with Outbound Connection PaperCut NG Remote Web Access Attempt ProxyShell ProxyNotShell Behavior Detected Spring4Shell Payload URL Request Supernova Webshell VMWare Aria Operations Exploit Attempt VMware Server Side Template Injection Hunt VMware Workspace ONE Freemarker Server-side Template Injection Web JSP Request via URL Web Spring4Shell HTTP Request Class Module Web Spring Cloud Function FunctionRouter Windows Exchange Autodiscover SSRF Abuse Linux Java Spawning Shell Windows Java Spawning Shells [LLM] Vulnerable goshs SFTP launch: empty-credential basic-auth (-b 'user:' / ':pass') with -sftp and no -fkf [LLM] goshs process accepting inbound SFTP/SSH connections (exposed file server) [LLM] Telnet credential brute force against internet-exposed IoT/Linux devices (Tengu dropper entry) [LLM] Edge device recruited as ORB relay — inbound sessions from UAT-7810 IPs [LLM] FortiBleed password-spray success burst against internet-facing Fortinet/edge auth [LLM] FortiGate rogue super_admin / SSL-VPN account creation following CVE-2024-55591 exploit [LLM] Node.js debugger/inspector launched bound to all network interfaces (CVE-2018-12120/-13567) [LLM] Remote (non-loopback) connection to an exposed Node.js debug/inspect port 5858/9229Articles citing this technique (6)
crit Winning 54% of the time art-214