119. RustDesk: An RMM You May Not Heard About
Hello everyone!
I'm sure you are well-informed about various RMMs abused by adversaries. But have you heard about this one - RustDesk?
For example, it was used ITW by Akira ransomware affiliates. The tool is available for various platforms, here's a Windows version.
Let's look at some detection opportunities, and start from the binary itself:
event_type: "processcreatewin"
AND
proc_file_productname: "rustdesk"
You may also hunt for file or folder creation events related to RustDesk:
event_type: "filecreate"
AND
file_path: "rustdesk"
Make sure you checked non-Windows binaries as well!
See you tomorrow!
Comments
Post a Comment