Rogue RMM Persistence and Defense Evasion
An intruder has established persistent access by installing unauthorized RMM tools and blinded security controls using evasion utilities like HideUL to mask the redundant access paths.
Based on research by Huntress 2026-09-25 9 steps · 3 queries T1190 T1219 T1562 T1566
Brief
Why this hunt matters
Recent reporting from Huntress in Rogue RMM Abuse: How Attackers Exploit Remote Access Tools highlights a shift in persistence tactics. Attackers no longer rely solely on custom backdoors; they deploy legitimate Remote Monitoring and Management (RMM) tools. These tools provide stable access and often bypass basic file-based detections. This hunt targets the specific behavior of "stacking" RMMs and the use of evasion utilities to hide these connections.
How the Hunt Flows
The hunt begins with a scoping phase using the hb_software_inventory surface. This query builds a list of hosts where ScreenConnect, ITarian, or ConnectWise agents are registered through standard package managers. This step provides an initial list of systems for deeper inspection, though it does not yet confirm malicious intent.
Following the inventory check, the hunt moves into a parallel behavioral analysis phase using hb_process_activity. One branch searches for the execution of HideUL (e.g., hideul_x64.exe). This utility has no legitimate business application; attackers use it to suppress security logging and hide their RMM sessions. The presence of this binary is a high-confidence indicator of an active intrusion.
Simultaneously, a second branch looks for RMM stacking. This query counts unique RMM clients running on a single host. While an IT team might use one tool, they rarely run two or three distinct RMM services on the same workstation. The hunt uses process names and original file names to identify these tools even if the adversary renames the binaries to evade detection.
Finally, a triage agent correlates the inventory data with the behavioral results. If a host shows both RMM stacking and the execution of evasion tools, the hunt triggers an isolation response or routes the case for manual forensic review. The analyst then traces the parent processes to find the initial delivery vector, such as an Adobe InDesign lure or a TransferXL download.
What this hunt cannot see
This hunt has two primary blind spots. First, if an attacker successfully uses HideUL to blind the security agent before the stacking behavior begins, the telemetry for those processes will not reach the platform. This hunt relies on the security agent's integrity. Second, the initial scoping query only sees RMM tools installed via package managers. If an attacker runs a portable version of ScreenConnect that does not register as installed software, the hunt must rely entirely on the behavioral process queries.
In this series
Steps
-
Inventory of known RMM packages
Query · scopingFind hosts with ScreenConnect or ITarian installed via package managers to focus the behavioral analysis.
reads hb_software_inventorysqlSELECT device_hostname, package_name, vendor_name, package_version FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%screenconnect%' OR LOWER(package_name) LIKE '%itarian%' OR LOWER(vendor_name) LIKE '%connectwise%' OR LOWER(vendor_name) LIKE '%itarian%')What a hit looks like. A list of hosts with RMM software. Silence means no RMM was installed via standard package managers, but does not rule out portable versions.
-
Defense evasion tool execution
Query · detection candidateIdentify the execution of HideUL, which attackers use to blind security telemetry, using path-suffix matching.
reads hb_process_activitysqlSELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_name) LIKE '%hideul_x64.exe' OR LOWER(process_name) LIKE '%hideul.exe') AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. A process match for HideUL. This utility has no legitimate business purpose and is used to hide RMM activity.
-
RMM stacking and redundancy
Query · baselineDetect hosts where multiple different RMM tools are running simultaneously, incorporating original file names to catch renamed binaries.
reads hb_process_activitysqlSELECT device_hostname, COUNT(DISTINCT CASE WHEN LOWER(process_name) LIKE '%screenconnect%' OR LOWER(process_original_file_name) LIKE '%screenconnect%' THEN 'ScreenConnect' WHEN LOWER(process_name) LIKE '%itarian%' OR LOWER(process_original_file_name) LIKE '%itarian%' OR LOWER(process_name) LIKE '%itsm_service%' OR LOWER(process_name) LIKE '%itcm%' THEN 'ITarian' END) AS unique_rmm_count, GROUP_CONCAT(DISTINCT process_name) AS rmm_processes, MIN(time) AS first_seen FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_name) LIKE '%screenconnect%' OR LOWER(process_name) LIKE '%itarian%' OR LOWER(process_name) LIKE '%itsm_service%' OR LOWER(process_name) LIKE '%itcm%' OR LOWER(process_original_file_name) LIKE '%screenconnect%' OR LOWER(process_original_file_name) LIKE '%itarian%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname HAVING unique_rmm_count > 1What a hit looks like. Hosts running multiple distinct RMM clients simultaneously. This stacking behavior is characteristic of an intruder ensuring redundant access.
-
Analyze RMM activity
Agent triageCorrelate inventory, evasion execution, and stacking behavior to identify rogue installs.
-
Route based on RMM risk
DecisionDirect high-confidence rogue RMM detections to immediate containment.
-
Isolate compromised host
Response actionShut down the attacker's remote sessions by isolating the host.
-
Analyst forensic review
Analyst taskVerify the agent's verdict and investigate the initial phishing delivery.
-
Remediation and tuning
Analyst taskEnsure full removal of the attacker's redundancy and tune detections.
Coverage
Scenario coverage
| Stage | Covered | How, or why not |
|---|---|---|
| Rogue RMM Installation and Persistence T1219 |
Yes | rmm-inventory-scoping, detect-rmm-stacking |
| Defense Evasion Activity T1562 |
Yes | detect-evasion-binaries |
| Redundant RMM Stacking T1219 |
Yes | detect-rmm-stacking, rmm-triage-agent |
| Phishing Delivery and Lure T1566 |
Out of scope | Belongs to another part of the 'Rogue RMM Abuse: How Attackers Exploit Remote Access Tools' series. |
| C2 Redirect and Payload Download T1203 |
Out of scope | Belongs to another part of the 'Rogue RMM Abuse: How Attackers Exploit Remote Access Tools' series. |
Blind spots
- Needs Unmodified EDR telemetry. If HideUL successfully disables logging, the stacking activity will be invisible to process and registry surfaces. It would answer whether HideUL successfully blinded the logging agent. Remediation: Deploy tamper-protection for the security agent and monitor for service stop events.
- Needs hb_software_inventory. The scoping query based on software inventory will miss portable versions of ITarian or ScreenConnect. It would answer whether the RMM was run as a portable binary without installation. Remediation: Rely on hb_process_activity and hb_network_connection for behavioral leads on portable tools.
Parameters & data
Parameters
| Parameter | Type | Default | What it is |
|---|---|---|---|
lookback_days | number | 14 | Days of history to examine. |
scope_hosts | list[host] | — | Hosts to focus on from scoping; empty searches the estate. |
Telemetry
| Source | Category | Telemetry |
|---|---|---|
| Endpoint telemetry (hb_ surfaces) | endpoint | endpoint |
Source
---
analysis: "A simple detection rule fires on a single RMM installer; this hunt pivots\
\ to look for 'stacking'\u2014multiple distinct RMMs on one host\u2014and correlates\
\ it with specialized evasion binaries like HideUL to distinguish an intrusion from\
\ a configuration error."
blind_spots:
- id: telemetry-evasion-gap
owner: Endpoint Engineering
question: whether HideUL successfully blinded the logging agent
remediation: Deploy tamper-protection for the security agent and monitor for service
stop events.
requires: Unmodified EDR telemetry
risk: If HideUL successfully disables logging, the stacking activity will be invisible
to process and registry surfaces.
stage: defense-evasion-activity
- id: portable-rmm-blindness
owner: Threat Hunting
question: whether the RMM was run as a portable binary without installation
remediation: Rely on hb_process_activity and hb_network_connection for behavioral
leads on portable tools.
requires: hb_software_inventory
risk: The scoping query based on software inventory will miss portable versions
of ITarian or ScreenConnect.
stage: rogue-rmm-installation-and-persistence
coverage:
- stage: rogue-rmm-installation-and-persistence
status: covered
steps:
- rmm-inventory-scoping
- detect-rmm-stacking
- stage: defense-evasion-activity
status: covered
steps:
- detect-evasion-binaries
- stage: redundant-rmm-stacking
status: covered
steps:
- detect-rmm-stacking
- rmm-triage-agent
- reason: 'Belongs to another part of the ''Rogue RMM Abuse: How Attackers Exploit
Remote Access Tools'' series.'
stage: phishing-delivery-and-lure
status: out_of_scope
- reason: 'Belongs to another part of the ''Rogue RMM Abuse: How Attackers Exploit
Remote Access Tools'' series.'
stage: c2-redirect-and-payload-download
status: out_of_scope
guardrails:
claims: no_unsupported
evidence: citation_required
missing_data: not_benign
telemetry: untrusted
hunt:
applicability: campaign-specific
handoff: keep-as-periodic-hunt
justification: RMM abuse is involved in nearly 40% of recent incidents; detecting
rogue management stacking is critical to ensuring an attacker hasn't left a secondary
persistence path behind after initial remediation.
methodology: model-assisted
trigger: intel-report
hypothesis: An intruder has established persistent access by installing unauthorized
RMM tools and blinded security controls using evasion utilities like HideUL to mask
the redundant access paths.
labels:
- hunt
- attack.t1219
- attack.t1562
- attack.t1566
- attack.t1190
name: Rogue RMM Persistence and Defense Evasion
parameters:
lookback_days:
default: '14'
description: Days of history to examine.
from:
kind: manual
observed: '2026-09-23'
ref: hunt-standard
type: number
scope_hosts:
default: []
description: Hosts to focus on from scoping; empty searches the estate.
from:
kind: manual
observed: '2026-09-23'
ref: analyst-input
type: list[host]
provenance:
authors:
- name: Huntbase hunt generation
org: huntbase.io
generated:
by: huntbase-hunt-generation
from: https://www.huntress.com/blog/rogue-rmm-abuse-phishing-persistent-access
gates:
- dry-run
- lint
model: hb_google/gemini-3-flash-preview
rationale: Target all Windows endpoints. Phishing for RMM abuse typically targets
end-users rather than IT staff, making the presence of these tools on non-admin
workstations a high-priority lead.
references:
- name: "Huntress \u2014 Rogue RMM Abuse: How Attackers Exploit Remote Access Tools"
url: https://www.huntress.com/blog/rogue-rmm-abuse-phishing-persistent-access
related:
- hunt: unauthorized-remote-access-tool-usage
reason: This hunt focuses on attacker stacking and evasion, not general policy violations
for unauthorized software.
relation: out-of-scope-alternative
- hunt: rogue-rmm-delivery-trusted-service-phishing
relation: follows
scenario:
stages:
- name: Phishing Delivery and Lure
observables:
- TransferXL email
- Adobe InDesign lure page
- View Document button
- ZIP files
- Nested PDF lures
slug: phishing-delivery-and-lure
tactic: initial-access
techniques:
- T1566
- name: C2 Redirect and Payload Download
observables:
- Attacker-controlled C2 infrastructure
- Rogue RMM installer download
- ScreenConnect client installer
- ITarian client installer
slug: c2-redirect-and-payload-download
tactic: execution
techniques:
- T1203
- name: Rogue RMM Installation and Persistence
observables:
- ITarian client installation
- ScreenConnect client installation
- SYSTEM-level privileges
- Persistent remote access service
slug: rogue-rmm-installation-and-persistence
tactic: persistence
techniques:
- T1219
- name: Defense Evasion Activity
observables:
- HideUL_x64.exe
slug: defense-evasion-activity
tactic: defense-evasion
techniques:
- T1562
- name: Redundant RMM Stacking
observables:
- Multiple rogue RMM clients
- ITarian and ScreenConnect coexistence
- Redundant ScreenConnect instances
slug: redundant-rmm-stacking
tactic: persistence
techniques:
- T1219
summary: Threat actors are using phishing emails with lures hosted on legitimate
services like TransferXL and Adobe InDesign to trick victims into installing rogue
RMM tools like ITarian and ScreenConnect. These tools provide persistent, hands-on
control and are often deployed in redundant pairs alongside defense evasion binaries
like HideUL_x64.exe to maintain long-term access.
series:
index: 2
slug: rogue-rmm-abuse-how-attackers-exploit-remote-access-tools
title: 'Rogue RMM Abuse: How Attackers Exploit Remote Access Tools'
total: 2
severity: medium
targets:
analyst:
name: Tier-2 analyst
role: analyst
endpoint:
category: endpoint
name: Endpoint telemetry (hb_ surfaces)
telemetry:
- endpoint
hunter:
agent: true
name: Hunt agent
tlp: clear
type: investigation
---
# Rogue RMM Persistence and Defense Evasion
This hunt identifies the lifecycle of RMM abuse where attackers deploy legitimate remote management tools for redundant persistence. It specifically looks for the stacking of multiple RMM clients on a single host—a high-confidence indicator of rogue activity—alongside the use of evasion utilities intended to mask malicious connections. By examining both software inventory and active process behavior, the hunt distinguishes between authorized IT tools and attacker-controlled instances.
## rmm-inventory-scoping
<!-- Inventory of known RMM packages -->
Find hosts with ScreenConnect or ITarian installed via package managers to focus the behavioral analysis.
```sqlite target=endpoint role=scoping
~~~yaml
expected: A list of hosts with RMM software. Silence means no RMM was installed via
standard package managers, but does not rule out portable versions.
reads:
- device_hostname
- package_name
- vendor_name
- package_version
silence: not_evidence_of_absence
source: hb_software_inventory
verified: dry-run
verified_at: '2026-09-25'
~~~
SELECT device_hostname, package_name, vendor_name, package_version FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%screenconnect%' OR LOWER(package_name) LIKE '%itarian%' OR LOWER(vendor_name) LIKE '%connectwise%' OR LOWER(vendor_name) LIKE '%itarian%')
```
## behavioral-checks
<!-- Behavioral evidence gathering -->
parallel:
- → detect-evasion-binaries
- → detect-rmm-stacking
join: → rmm-triage-agent
## detect-evasion-binaries
<!-- Defense evasion tool execution -->
Identify the execution of HideUL, which attackers use to blind security telemetry, using path-suffix matching.
```sqlite target=endpoint role=detection-candidate params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: A process match for HideUL. This utility has no legitimate business purpose
and is used to hide RMM activity.
reads:
- device_hostname
- process_name
- process_cmd_line
- user_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-25'
~~~
SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_name) LIKE '%hideul_x64.exe' OR LOWER(process_name) LIKE '%hideul.exe') AND time >= datetime('now', '-{{lookback_days}} days')
```
## detect-rmm-stacking
<!-- RMM stacking and redundancy -->
Detect hosts where multiple different RMM tools are running simultaneously, incorporating original file names to catch renamed binaries.
```sqlite target=endpoint role=baseline params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
baseline:
compare: new_this_window
window: '{{lookback_days}}d'
expected: Hosts running multiple distinct RMM clients simultaneously. This stacking
behavior is characteristic of an intruder ensuring redundant access.
prevalence:
by: device_hostname
key:
- rmm_processes
rare_below: 2
reads:
- device_hostname
- process_name
- process_original_file_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-25'
~~~
SELECT device_hostname, COUNT(DISTINCT CASE WHEN LOWER(process_name) LIKE '%screenconnect%' OR LOWER(process_original_file_name) LIKE '%screenconnect%' THEN 'ScreenConnect' WHEN LOWER(process_name) LIKE '%itarian%' OR LOWER(process_original_file_name) LIKE '%itarian%' OR LOWER(process_name) LIKE '%itsm_service%' OR LOWER(process_name) LIKE '%itcm%' THEN 'ITarian' END) AS unique_rmm_count, GROUP_CONCAT(DISTINCT process_name) AS rmm_processes, MIN(time) AS first_seen FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_name) LIKE '%screenconnect%' OR LOWER(process_name) LIKE '%itarian%' OR LOWER(process_name) LIKE '%itsm_service%' OR LOWER(process_name) LIKE '%itcm%' OR LOWER(process_original_file_name) LIKE '%screenconnect%' OR LOWER(process_original_file_name) LIKE '%itarian%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname HAVING unique_rmm_count > 1
```
## rmm-triage-agent
<!-- Analyze RMM activity -->
```agent target=hunter
cite: required
context:
- rmm-inventory-scoping
- detect-evasion-binaries
- detect-rmm-stacking
max_iterations: 4
objective: Determine if RMM tools on the host are rogue by checking for stacking of
multiple distinct RMMs and the presence of the HideUL evasion tool.
success_criteria: A verdict of malicious | suspicious | benign per host, citing specific
stacking patterns or evasion execution.
tools:
- endpoint
```
## route-on-verdict
<!-- Route based on RMM risk -->
if~: "the rmm-triage-agent verdict is malicious for at least one host due to RMM stacking or evasion binary execution" (confidence: high, judge=hunter)
then: → isolate-endpoint
indeterminate: → analyst-manual-review
unavailable: → analyst-manual-review (blind_spot: telemetry-evasion-gap)
else: → analyst-manual-review
## isolate-endpoint
<!-- Isolate compromised host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host from the network immediately. Terminate all active ScreenConnect and ITarian processes and remove the persistence services after acquiring a forensic sample.
```
→ analyst-manual-review
## analyst-manual-review
<!-- Analyst forensic review -->
```manual target=analyst
Verify the RMM tools against the approved software catalog. Review hb_http_activity for connections to TransferXL or Adobe InDesign lure pages within 24 hours prior to the RMM installation. Trace parent processes of the RMM installers to identify the initial lure file.
```
→ investigation-closeout
## investigation-closeout
<!-- Remediation and tuning -->
```manual target=analyst
Confirm all redundant RMM clients are removed. If HideUL was detected, perform a deep scan to ensure no other security tools were tampered with. Record the incident and update the RMM inventory list.
```
→ end
Run it
Take this hunt into your environment.
Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.
Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.