heroui logo

Potential RMM Execution from a Commonly Abused Web Service

Elastic Detection Rules

View Source
Summary
Detection rule to identify potential execution of remote monitoring and management (RMM) software signed by known RMM publishers and downloaded from commonly abused hosting or file-sharing services. The ES|QL rule correlates two data streams on Windows endpoints: (1) process start events where process.code_signature.subject_name matches a long curated allowlist of RMM publishers, and (2) file creation events where file.origin_url is present. It normalizes executable paths and origin URLs, then matches the origin domain against an expansive set of hosting platforms (GitHub, Bitbucket, AWS S3, Azure, Google Drive/Docs, Dropbox, Ngrok, CDN/file-sharing services, IPFS, and similar domains) to link the downloaded artifact to an internet-hosted source. A fallback path allows correlation when process.origin_url is missing by using file.origin_url, ensuring detection even when origin metadata is incomplete. The query produces events with contextual fields (host, user, process, code signature, origin URLs, and file-origin timing) for investigation and prioritizes detections with a low severity but actionable indicators of potential RMM activity. The rule is designed to minimize false positives by requiring a known RMM signer in combination with a known/abused download origin, while acknowledging that legitimate administrators or MSPs could appear in the signer list and that some providers may distribute legitimate software. The rule is labeled as potentially indicative of C2-like activity through RMM tooling and supports endpoint investigations within Elastic Defend on Windows endpoints.
Categories
  • Endpoint
  • Windows
Data Sources
  • Process
  • File
ATT&CK Techniques
  • T1105
  • T1219
  • T1219.002
Created: 2026-09-16