Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Persistence/ T1133

T1133External Remote Services

T1133 — External Remote Services is a MITRE ATT&CK technique in the Persistence tactic. Clankerusecase tracks 51 detection use cases covering it and 6 threat-intel articles citing it.

PersistenceInitial Access
View on the matrix → Filter Detection Library MITRE official spec ↗
51Use cases
6Articles
0Sub-techniques
2Tactics

Use cases covering this technique (51)

[WEEKLY] AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation Internal exploit · alerting DSΣPDDCS [WEEKLY] Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) Internal exploit · alerting DSPDD [WEEKLY] Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request Internal actions · alerting DSPDD [WEEKLY] Internet-Exposed AI Agent/LLM Service Spawns Shell or LOLBin After Inbound Connection Internal exploit · alerting DSΣPDDCS [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Internal exploit · alerting DSΣPDD [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write Internal exploit · alerting DSPDD Detect Exchange Web Shell ESCU actions · alerting P Exchange PowerShell Abuse via SSRF ESCU actions · alerting P Java Writing JSP File ESCU actions · alerting P Living Off The Land Detection ESCU actions · alerting P Log4Shell CVE-2021-44228 Exploitation ESCU actions · alerting P MS Exchange Mailbox Replication service writing Active Server Pages ESCU actions · alerting P Outbound Network Connection from Java Using Default Ports ESCU actions · alerting P PaperCut NG Suspicious Behavior Debug Log ESCU actions · hunting P Web or Application Server Spawning a Shell ESCU actions · alerting P Windows MOVEit Transfer Writing ASPX ESCU actions · alerting P Windows PaperCut NG Spawn Shell ESCU actions · alerting P Windows RDPClient Connection Sequence Events ESCU actions · hunting P Cisco Network Interface Modifications ESCU actions · hunting P F5 BIG-IP iControl REST Vulnerability CVE-2022-1388 ESCU actions · alerting P Confluence Unauthenticated Remote Code Execution CVE-2022-26134 ESCU actions · alerting P Detect attackers scanning for vulnerable JBoss servers ESCU actions · alerting P Exploit Public Facing Application via Apache Commons Text ESCU actions · hunting P Exploit Public-Facing Fortinet FortiNAC CVE-2022-39952 ESCU actions · alerting P Fortinet Appliance Auth bypass ESCU actions · alerting P Hunting for Log4Shell ESCU actions · hunting P Ivanti EPMM Remote Unauthenticated API Access CVE-2023-35078 ESCU actions · alerting P Ivanti EPMM Remote Unauthenticated API Access CVE-2023-35082 ESCU actions · alerting P Log4Shell JNDI Payload Injection Attempt ESCU actions · hunting P Log4Shell JNDI Payload Injection with Outbound Connection ESCU actions · hunting P PaperCut NG Remote Web Access Attempt ESCU actions · alerting P ProxyShell ProxyNotShell Behavior Detected ESCU actions · alerting P Spring4Shell Payload URL Request ESCU actions · alerting P Supernova Webshell ESCU actions · alerting P VMWare Aria Operations Exploit Attempt ESCU actions · alerting P VMware Server Side Template Injection Hunt ESCU actions · hunting P VMware Workspace ONE Freemarker Server-side Template Injection ESCU actions · hunting P Web JSP Request via URL ESCU actions · alerting P Web Spring4Shell HTTP Request Class Module ESCU actions · alerting P Web Spring Cloud Function FunctionRouter ESCU actions · alerting P Windows Exchange Autodiscover SSRF Abuse ESCU actions · alerting P Linux Java Spawning Shell ESCU actions · alerting P Windows Java Spawning Shells ESCU actions · alerting P [LLM] Vulnerable goshs SFTP launch: empty-credential basic-auth (-b 'user:' / ':pass') with -sftp and no -fkf Bespoke exploit · alerting DSΣPDDCS [LLM] goshs process accepting inbound SFTP/SSH connections (exposed file server) Bespoke delivery · hunting DSPDDCS [LLM] Telnet credential brute force against internet-exposed IoT/Linux devices (Tengu dropper entry) Bespoke delivery · alerting DSP [LLM] Edge device recruited as ORB relay — inbound sessions from UAT-7810 IPs Bespoke c2 · hunting DSPDDCS [LLM] FortiBleed password-spray success burst against internet-facing Fortinet/edge auth Bespoke exploit · alerting SP [LLM] FortiGate rogue super_admin / SSL-VPN account creation following CVE-2024-55591 exploit Bespoke install · alerting SP [LLM] Node.js debugger/inspector launched bound to all network interfaces (CVE-2018-12120/-13567) Bespoke exploit · alerting DSΣPDDCS [LLM] Remote (non-loopback) connection to an exposed Node.js debug/inspect port 5858/9229 Bespoke exploit · alerting DSPDDCS

Articles citing this technique (6)