Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Command and Control/ T1219

T1219Remote Access Tools

T1219 — Remote Access Tools is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 27 detection use cases covering it and 87 threat-intel articles citing it.

Command and Control
View on the matrix → Filter Detection Library MITRE official spec ↗
27Use cases
87Articles
3Sub-techniques
1Tactic

Sub-techniques (3)

Use cases covering this technique (27)

RMM tool installed by non-IT user — remote-access utility for hands-on-keyboard Internal install · hunting DSΣP Detect Remote Access Software Usage File ESCU actions · hunting P Detect Remote Access Software Usage FileInfo ESCU actions · hunting P Detect Remote Access Software Usage Process ESCU actions · hunting P Detect Remote Access Software Usage Registry ESCU actions · hunting P Windows Level RMM PowerShell Script Installer ESCU actions · hunting P Windows Level RMM Watchdog Task Created ESCU actions · hunting P Windows Remote Access Software BRC4 Loaded Dll ESCU actions · hunting P Windows Remote Access Software RMS Registry ESCU actions · alerting P Windows RMM Tool Execution ESCU actions · hunting P Cisco Secure Firewall - Communication Over Suspicious Ports ESCU actions · hunting P Cisco Secure Firewall - Remote Access Software Usage Traffic ESCU actions · hunting P Detect Remote Access Software Usage DNS ESCU actions · hunting P Detect Remote Access Software Usage Traffic ESCU actions · hunting P HTTP RMM User Agent ESCU actions · hunting P Detect Remote Access Software Usage URL ESCU actions · hunting P Windows Remote Access Software Hunt ESCU actions · hunting P [LLM] Trojanized MeshAgent covert backdoor: SYSTEM service beaconing over WSS (Sinobi) Bespoke c2 · hunting DSΣPDDCS [LLM] Zoho Assist Unattended Agent deployed for headless remote control (Warlock/Storm-2603) Bespoke install · hunting DSΣPDDCS [LLM] Level RMM enrollment with BlueDash attacker API key (GxSCHE8EZwfyYN3iPQHPai8D) Bespoke install · alerting DSΣPDDCS [LLM] Multiple RMM agents co-resident on one host (BlueDash redundant access) Bespoke install · alerting DSPDDCS [LLM] Unsanctioned RMM trio deployment: Endpoint Central, Mesh Agent, Tactical RMM Bespoke c2 · hunting DSPDDCS [LLM] The Gentlemen SystemBC C2 beacon to known operator IPs Bespoke c2 · hunting DSΣPDDCS [LLM] Outbound C2 to PlugX/ShadowPad/Cobalt Strike/Remcos infrastructure targeting Pakistani law enforcement Bespoke c2 · alerting DSΣPDDCS [LLM] OpenClaw Gateway WebSocket listener / loopback connection on TCP 18789 Bespoke c2 · hunting DSΣPDDCS [LLM] MuddyWater SimpleHelp RMM client spawning shell or recon LOLBin Bespoke install · alerting DSΣP [LLM] ScreenConnect MSI sideload from lmfao.su (Solidity Language post-exploit RAT install) Bespoke install · alerting DSΣPDDCS

Articles citing this technique (87)