364. Another RMM in a Ransomware Affiliate's Toolkit
Hello everyone!
Today we'll look at another example of a very common technique - Remote Access Tools: Remote Desktop Software (T1219.002).
Ransomware gangs have lots of such tools in their arsenal. For example, Power Admin - legitimate tool that provides functionality to monitor servers and applications, as well as file access auditing.
Of course, it may be a good target for detection and hunting, for example:
event_type: "processcreatewin"
AND
proc_file_productname: "pa server monitor"
See you tomorrow!

Comments
Post a Comment