T1219Remote Access Tools
T1219 — Remote Access Tools is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 27 detection use cases covering it and 87 threat-intel articles citing it.
Command and Control
27Use cases
87Articles
3Sub-techniques
1Tactic
Sub-techniques (3)
Use cases covering this technique (27)
RMM tool installed by non-IT user — remote-access utility for hands-on-keyboard Detect Remote Access Software Usage File Detect Remote Access Software Usage FileInfo Detect Remote Access Software Usage Process Detect Remote Access Software Usage Registry Windows Level RMM PowerShell Script Installer Windows Level RMM Watchdog Task Created Windows Remote Access Software BRC4 Loaded Dll Windows Remote Access Software RMS Registry Windows RMM Tool Execution Cisco Secure Firewall - Communication Over Suspicious Ports Cisco Secure Firewall - Remote Access Software Usage Traffic Detect Remote Access Software Usage DNS Detect Remote Access Software Usage Traffic HTTP RMM User Agent Detect Remote Access Software Usage URL Windows Remote Access Software Hunt [LLM] Trojanized MeshAgent covert backdoor: SYSTEM service beaconing over WSS (Sinobi) [LLM] Zoho Assist Unattended Agent deployed for headless remote control (Warlock/Storm-2603) [LLM] Level RMM enrollment with BlueDash attacker API key (GxSCHE8EZwfyYN3iPQHPai8D) [LLM] Multiple RMM agents co-resident on one host (BlueDash redundant access) [LLM] Unsanctioned RMM trio deployment: Endpoint Central, Mesh Agent, Tactical RMM [LLM] The Gentlemen SystemBC C2 beacon to known operator IPs [LLM] Outbound C2 to PlugX/ShadowPad/Cobalt Strike/Remcos infrastructure targeting Pakistani law enforcement [LLM] OpenClaw Gateway WebSocket listener / loopback connection on TCP 18789 [LLM] MuddyWater SimpleHelp RMM client spawning shell or recon LOLBin [LLM] ScreenConnect MSI sideload from lmfao.su (Solidity Language post-exploit RAT install)Articles citing this technique (87)
crit Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads art-06
crit Begun, the Patch Wars have art-150
high GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration art-153
crit CISA KEV: CVE-2025-3935 — ConnectWise ScreenConnect Improper Authentication Vulnerability art-945
crit CISA KEV: CVE-2024-1709 — ConnectWise ScreenConnect Authentication Bypass Vulnerability art-1396
high SREs bring ORDER(R) to CHAOS art-1965
med How Onna Technologies uses Snyk & Sysdig to secure the SDLC while saving time and money art-2016
high Securing PHP containers art-2082
med Cloud security challenges art-2247