Title:Remote Access Tool - TacticalRMM Agent Registration to Potentially Attacker-Controlled Server Status:experimental Description:Detects TacticalRMM agent installations where the --api, --auth, and related flags are used on the command line.
These parameters configure the agent to connect to a specific RMM server with authentication, client ID, and site ID.
This technique could indicate a threat actor attempting to register the agent with an attacker-controlled RMM infrastructure silently.
References: -https://github.com/amidaware/tacticalrmm -https://apophis133.medium.com/powershell-script-tactical-rmm-installation-45afb639eff3 Author: Ahmed Nosir (@egycondor) Date: 2025-05-29 modified:None Tags: