Remote Access Tool Services Have Been Installed - Security

 Original Source: [Sigma source]
Title: Remote Access Tool Services Have Been Installed - Security
Status: test
Description:Detects service installation of different remote access tools software. These software are often abused by threat actors to perform
References:
  -https://redcanary.com/blog/misbehaving-rats/
Author: Connor Martin, Nasreddine Bencherchali (Nextron Systems)
Date: 2022-12-23
modified:2024-12-07
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.execution'
  • -'attack.t1543.003'
  • -'attack.t1569.002'
Logsource:
  • product: windows
  • service: security
  • definition: The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697
Detection:
  selection:
    EventID: '4697'
    ServiceName|contains:
      -'AmmyyAdmin'
      -'AnyDesk'
      -'Atera'
      -'BASupportExpressSrvcUpdater'
      -'BASupportExpressStandaloneService'
      -'chromoting'
      -'GoToAssist'
      -'GoToMyPC'
      -'jumpcloud'
      -'LMIGuardianSvc'
      -'LogMeIn'
      -'monblanking'
      -'Parsec'
      -'RManService'
      -'RPCPerformanceService'
      -'RPCService'
      -'SplashtopRemoteService'
      -'SSUService'
      -'TeamViewer'
      -'TightVNC'
      -'vncserver'
      -'Zoho'

  condition:selection
Falsepositives:
  -The rule doesn't look for anything suspicious so false positives are expected. If you use one of the tools mentioned, comment it out
Level: medium