364. Another RMM in a Ransomware Affiliate's Toolkit

Hello everyone!

Today we'll look at another example of a very common technique - Remote Access Tools: Remote Desktop Software (T1219.002).

Ransomware gangs have lots of such tools in their arsenal. For example, Power Admin -  legitimate tool that provides functionality to monitor servers and applications, as well as file access auditing. 

Of course, it may be a good target for detection and hunting, for example:

event_type: "processcreatewin"

AND

proc_file_productname: "pa server monitor"

See you tomorrow!

Comments

Popular posts from this blog

033. Free Google Threat Intelligence Course

082. Huniting for Malicious Browser Extensions

001. The Zeltser Challenge