Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Command and Control/ T1219

T1219Remote Access Tools

T1219 — Remote Access Tools is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 29 detection use cases covering it and 78 threat-intel articles citing it.

Command and Control
View on the matrix → Filter Detection Library MITRE official spec ↗
29Use cases
78Articles
3Sub-techniques
1Tactic

Sub-techniques (3)

Use cases covering this technique (29)

RMM tool installed by non-IT user — remote-access utility for hands-on-keyboard Internal install · hunting DSΣP Detect Remote Access Software Usage File ESCU actions · hunting P Detect Remote Access Software Usage FileInfo ESCU actions · hunting P Detect Remote Access Software Usage Process ESCU actions · hunting P Detect Remote Access Software Usage Registry ESCU actions · hunting P Windows Level RMM PowerShell Script Installer ESCU actions · hunting P Windows Level RMM Watchdog Task Created ESCU actions · hunting P Windows Remote Access Software BRC4 Loaded Dll ESCU actions · hunting P Windows Remote Access Software RMS Registry ESCU actions · alerting P Windows RMM Tool Execution ESCU actions · hunting P Cisco Secure Firewall - Communication Over Suspicious Ports ESCU actions · hunting P Cisco Secure Firewall - Remote Access Software Usage Traffic ESCU actions · hunting P Detect Remote Access Software Usage DNS ESCU actions · hunting P Detect Remote Access Software Usage Traffic ESCU actions · hunting P HTTP RMM User Agent ESCU actions · hunting P Detect Remote Access Software Usage URL ESCU actions · hunting P Windows Remote Access Software Hunt ESCU actions · hunting P [LLM] esxi.sh downloader deploys architecture-specific reverse_ssh from 185.144.28.120 Bespoke install · hunting DSΣPDDCS [LLM] Managed endpoint network egress to DPRK IT-worker VPS / AstrillVPN IPs Bespoke c2 · hunting DSΣPDDCS [LLM] Reverse-shell egress from Flowise node process tree (nc/shell child dialing out) Bespoke c2 · alerting DSPCS [LLM] AnyDesk silent/unattended install used for DragonForce access Bespoke c2 · alerting DSΣPDDCS [LLM] Trojanized MeshAgent running outside its install path (Sinobi ransomware C2) Bespoke c2 · alerting DSΣPDDCS [LLM] Zoho Assist Unattended Agent deployment (Warlock / Storm-2603 ransomware) Bespoke install · alerting DSΣPDDCS [LLM] Trojanized MeshAgent installed as SYSTEM auto-start service (Sinobi covert C2) Bespoke install · alerting DSΣDDCS [LLM] Zoho Assist Unattended Agent deployment for headless remote access (Warlock / Storm-2603) Bespoke install · alerting DSΣDDCS [LLM] Outbound C2 to PlugX/ShadowPad/Cobalt Strike/Remcos infrastructure targeting Pakistani law enforcement Bespoke c2 · alerting DSΣPDDCS [LLM] OpenClaw Gateway WebSocket listener / loopback connection on TCP 18789 Bespoke c2 · hunting DSΣPDDCS [LLM] MuddyWater SimpleHelp RMM client spawning shell or recon LOLBin Bespoke install · alerting DSΣP [LLM] ScreenConnect MSI sideload from lmfao.su (Solidity Language post-exploit RAT install) Bespoke install · alerting DSΣPDDCS

Articles citing this technique (78)