{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "keep-as-periodic-hunt",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "RMM abuse is involved in nearly 40% of recent incidents; detecting rogue management stacking is critical to ensuring an attacker hasn't left a secondary persistence path behind after initial remediation."
      },
      "name": "Rogue RMM Persistence and Defense Evasion",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1219",
        "attack.t1562",
        "attack.t1566",
        "attack.t1190"
      ],
      "series": {
        "slug": "rogue-rmm-abuse-how-attackers-exploit-remote-access-tools",
        "index": 2,
        "title": "Rogue RMM Abuse: How Attackers Exploit Remote Access Tools",
        "total": 2
      },
      "related": [
        {
          "hunt": "unauthorized-remote-access-tool-usage",
          "reason": "This hunt focuses on attacker stacking and evasion, not general policy violations for unauthorized software.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "rogue-rmm-delivery-trusted-service-phishing",
          "relation": "follows"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A simple detection rule fires on a single RMM installer; this hunt pivots to look for 'stacking'\u2014multiple distinct RMMs on one host\u2014and correlates it with specialized evasion binaries like HideUL to distinguish an intrusion from a configuration error.",
      "coverage": [
        {
          "stage": "rogue-rmm-installation-and-persistence",
          "steps": [
            "rmm-inventory-scoping",
            "detect-rmm-stacking"
          ],
          "status": "covered"
        },
        {
          "stage": "defense-evasion-activity",
          "steps": [
            "detect-evasion-binaries"
          ],
          "status": "covered"
        },
        {
          "stage": "redundant-rmm-stacking",
          "steps": [
            "detect-rmm-stacking",
            "rmm-triage-agent"
          ],
          "status": "covered"
        },
        {
          "stage": "phishing-delivery-and-lure",
          "reason": "Belongs to another part of the 'Rogue RMM Abuse: How Attackers Exploit Remote Access Tools' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "c2-redirect-and-payload-download",
          "reason": "Belongs to another part of the 'Rogue RMM Abuse: How Attackers Exploit Remote Access Tools' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Phishing Delivery and Lure",
            "slug": "phishing-delivery-and-lure",
            "tactic": "initial-access",
            "techniques": [
              "T1566"
            ],
            "observables": [
              "TransferXL email",
              "Adobe InDesign lure page",
              "View Document button",
              "ZIP files",
              "Nested PDF lures"
            ]
          },
          {
            "name": "C2 Redirect and Payload Download",
            "slug": "c2-redirect-and-payload-download",
            "tactic": "execution",
            "techniques": [
              "T1203"
            ],
            "observables": [
              "Attacker-controlled C2 infrastructure",
              "Rogue RMM installer download",
              "ScreenConnect client installer",
              "ITarian client installer"
            ]
          },
          {
            "name": "Rogue RMM Installation and Persistence",
            "slug": "rogue-rmm-installation-and-persistence",
            "tactic": "persistence",
            "techniques": [
              "T1219"
            ],
            "observables": [
              "ITarian client installation",
              "ScreenConnect client installation",
              "SYSTEM-level privileges",
              "Persistent remote access service"
            ]
          },
          {
            "name": "Defense Evasion Activity",
            "slug": "defense-evasion-activity",
            "tactic": "defense-evasion",
            "techniques": [
              "T1562"
            ],
            "observables": [
              "HideUL_x64.exe"
            ]
          },
          {
            "name": "Redundant RMM Stacking",
            "slug": "redundant-rmm-stacking",
            "tactic": "persistence",
            "techniques": [
              "T1219"
            ],
            "observables": [
              "Multiple rogue RMM clients",
              "ITarian and ScreenConnect coexistence",
              "Redundant ScreenConnect instances"
            ]
          }
        ],
        "summary": "Threat actors are using phishing emails with lures hosted on legitimate services like TransferXL and Adobe InDesign to trick victims into installing rogue RMM tools like ITarian and ScreenConnect. These tools provide persistent, hands-on control and are often deployed in redundant pairs alongside defense evasion binaries like HideUL_x64.exe to maintain long-term access."
      },
      "severity": "medium",
      "rationale": "Target all Windows endpoints. Phishing for RMM abuse typically targets end-users rather than IT staff, making the presence of these tools on non-admin workstations a high-priority lead.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An intruder has established persistent access by installing unauthorized RMM tools and blinded security controls using evasion utilities like HideUL to mask the redundant access paths.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "analyst-input",
            "kind": "manual",
            "observed": "2026-09-23"
          },
          "type": "list[host]",
          "default": [],
          "description": "Hosts to focus on from scoping; empty searches the estate."
        },
        "lookback_days": {
          "from": {
            "ref": "hunt-standard",
            "kind": "manual",
            "observed": "2026-09-23"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.huntress.com/blog/rogue-rmm-abuse-phishing-persistent-access",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.huntress.com/blog/rogue-rmm-abuse-phishing-persistent-access",
          "name": "Huntress \u2014 Rogue RMM Abuse: How Attackers Exploit Remote Access Tools"
        }
      ],
      "blind_spots": [
        {
          "id": "telemetry-evasion-gap",
          "risk": "If HideUL successfully disables logging, the stacking activity will be invisible to process and registry surfaces.",
          "owner": "Endpoint Engineering",
          "stage": "defense-evasion-activity",
          "question": "whether HideUL successfully blinded the logging agent",
          "requires": "Unmodified EDR telemetry",
          "remediation": "Deploy tamper-protection for the security agent and monitor for service stop events."
        },
        {
          "id": "portable-rmm-blindness",
          "risk": "The scoping query based on software inventory will miss portable versions of ITarian or ScreenConnect.",
          "owner": "Threat Hunting",
          "stage": "rogue-rmm-installation-and-persistence",
          "question": "whether the RMM was run as a portable binary without installation",
          "requires": "hb_software_inventory",
          "remediation": "Rely on hb_process_activity and hb_network_connection for behavioral leads on portable tools."
        }
      ]
    },
    "name": "Rogue RMM Persistence and Defense Evasion",
    "description": "This hunt identifies the lifecycle of RMM abuse where attackers deploy legitimate remote management tools for redundant persistence. It specifically looks for the stacking of multiple RMM clients on a single host\u2014a high-confidence indicator of rogue activity\u2014alongside the use of evasion utilities intended to mask malicious connections. By examining both software inventory and active process behavior, the hunt distinguishes between authorized IT tools and attacker-controlled instances."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "rogue-rmm-abuse-how-attackers-exploit-remote-access-tools",
          "index": 2,
          "title": "Rogue RMM Abuse: How Attackers Exploit Remote Access Tools",
          "total": 2
        },
        "coverage": [
          {
            "stage": "rogue-rmm-installation-and-persistence",
            "steps": [
              "rmm-inventory-scoping",
              "detect-rmm-stacking"
            ],
            "status": "covered"
          },
          {
            "stage": "defense-evasion-activity",
            "steps": [
              "detect-evasion-binaries"
            ],
            "status": "covered"
          },
          {
            "stage": "redundant-rmm-stacking",
            "steps": [
              "detect-rmm-stacking",
              "rmm-triage-agent"
            ],
            "status": "covered"
          },
          {
            "stage": "phishing-delivery-and-lure",
            "reason": "Belongs to another part of the 'Rogue RMM Abuse: How Attackers Exploit Remote Access Tools' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "c2-redirect-and-payload-download",
            "reason": "Belongs to another part of the 'Rogue RMM Abuse: How Attackers Exploit Remote Access Tools' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An intruder has established persistent access by installing unauthorized RMM tools and blinded security controls using evasion utilities like HideUL to mask the redundant access paths.",
        "blind_spots": [
          {
            "id": "telemetry-evasion-gap",
            "risk": "If HideUL successfully disables logging, the stacking activity will be invisible to process and registry surfaces.",
            "owner": "Endpoint Engineering",
            "stage": "defense-evasion-activity",
            "question": "whether HideUL successfully blinded the logging agent",
            "requires": "Unmodified EDR telemetry",
            "remediation": "Deploy tamper-protection for the security agent and monitor for service stop events."
          },
          {
            "id": "portable-rmm-blindness",
            "risk": "The scoping query based on software inventory will miss portable versions of ITarian or ScreenConnect.",
            "owner": "Threat Hunting",
            "stage": "rogue-rmm-installation-and-persistence",
            "question": "whether the RMM was run as a portable binary without installation",
            "requires": "hb_software_inventory",
            "remediation": "Rely on hb_process_activity and hb_network_connection for behavioral leads on portable tools."
          }
        ],
        "scoping_notes": "Target all Windows endpoints. Phishing for RMM abuse typically targets end-users rather than IT staff, making the presence of these tools on non-admin workstations a high-priority lead.",
        "beyond_detection": "A simple detection rule fires on a single RMM installer; this hunt pivots to look for 'stacking'\u2014multiple distinct RMMs on one host\u2014and correlates it with specialized evasion binaries like HideUL to distinguish an intrusion from a configuration error."
      }
    },
    {
      "id": "rmm-inventory-scoping",
      "type": "query",
      "label": "Inventory of known RMM packages",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT device_hostname, package_name, vendor_name, package_version FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%screenconnect%' OR LOWER(package_name) LIKE '%itarian%' OR LOWER(vendor_name) LIKE '%connectwise%' OR LOWER(vendor_name) LIKE '%itarian%')",
        "surface": "hb_software_inventory",
        "description": "Find hosts with ScreenConnect or ITarian installed via package managers to focus the behavioral analysis.",
        "expected_signal": "A list of hosts with RMM software. Silence means no RMM was installed via standard package managers, but does not rule out portable versions."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Inventory of known RMM packages",
        "reads": [
          "device_hostname",
          "package_name",
          "vendor_name",
          "package_version"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT device_hostname, package_name, vendor_name, package_version FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%screenconnect%' OR LOWER(package_name) LIKE '%itarian%' OR LOWER(vendor_name) LIKE '%connectwise%' OR LOWER(vendor_name) LIKE '%itarian%')",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hosts with RMM software. Silence means no RMM was installed via standard package managers, but does not rule out portable versions.",
        "verified": "dry-run",
        "verified_at": "2026-09-25"
      }
    },
    {
      "id": "detect-evasion-binaries",
      "type": "query",
      "label": "Defense evasion tool execution",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_name) LIKE '%hideul_x64.exe' OR LOWER(process_name) LIKE '%hideul.exe') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Identify the execution of HideUL, which attackers use to blind security telemetry, using path-suffix matching.",
        "expected_signal": "A process match for HideUL. This utility has no legitimate business purpose and is used to hide RMM activity."
      },
      "parents": [
        {
          "id": "rmm-inventory-scoping"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Defense evasion tool execution",
        "reads": [
          "device_hostname",
          "process_name",
          "process_cmd_line",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_name) LIKE '%hideul_x64.exe' OR LOWER(process_name) LIKE '%hideul.exe') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "A process match for HideUL. This utility has no legitimate business purpose and is used to hide RMM activity.",
        "verified": "dry-run",
        "verified_at": "2026-09-25"
      }
    },
    {
      "id": "detect-rmm-stacking",
      "type": "query",
      "label": "RMM stacking and redundancy",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT device_hostname, COUNT(DISTINCT CASE WHEN LOWER(process_name) LIKE '%screenconnect%' OR LOWER(process_original_file_name) LIKE '%screenconnect%' THEN 'ScreenConnect' WHEN LOWER(process_name) LIKE '%itarian%' OR LOWER(process_original_file_name) LIKE '%itarian%' OR LOWER(process_name) LIKE '%itsm_service%' OR LOWER(process_name) LIKE '%itcm%' THEN 'ITarian' END) AS unique_rmm_count, GROUP_CONCAT(DISTINCT process_name) AS rmm_processes, MIN(time) AS first_seen FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_name) LIKE '%screenconnect%' OR LOWER(process_name) LIKE '%itarian%' OR LOWER(process_name) LIKE '%itsm_service%' OR LOWER(process_name) LIKE '%itcm%' OR LOWER(process_original_file_name) LIKE '%screenconnect%' OR LOWER(process_original_file_name) LIKE '%itarian%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname HAVING unique_rmm_count > 1",
        "surface": "hb_process_activity",
        "description": "Detect hosts where multiple different RMM tools are running simultaneously, incorporating original file names to catch renamed binaries.",
        "expected_signal": "Hosts running multiple distinct RMM clients simultaneously. This stacking behavior is characteristic of an intruder ensuring redundant access."
      },
      "parents": [
        {
          "id": "rmm-inventory-scoping"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "RMM stacking and redundancy",
        "reads": [
          "device_hostname",
          "process_name",
          "process_original_file_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, COUNT(DISTINCT CASE WHEN LOWER(process_name) LIKE '%screenconnect%' OR LOWER(process_original_file_name) LIKE '%screenconnect%' THEN 'ScreenConnect' WHEN LOWER(process_name) LIKE '%itarian%' OR LOWER(process_original_file_name) LIKE '%itarian%' OR LOWER(process_name) LIKE '%itsm_service%' OR LOWER(process_name) LIKE '%itcm%' THEN 'ITarian' END) AS unique_rmm_count, GROUP_CONCAT(DISTINCT process_name) AS rmm_processes, MIN(time) AS first_seen FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_name) LIKE '%screenconnect%' OR LOWER(process_name) LIKE '%itarian%' OR LOWER(process_name) LIKE '%itsm_service%' OR LOWER(process_name) LIKE '%itcm%' OR LOWER(process_original_file_name) LIKE '%screenconnect%' OR LOWER(process_original_file_name) LIKE '%itarian%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname HAVING unique_rmm_count > 1",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "new_this_window"
        },
        "expected": "Hosts running multiple distinct RMM clients simultaneously. This stacking behavior is characteristic of an intruder ensuring redundant access.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "rmm_processes"
          ],
          "rare_below": 2
        },
        "verified_at": "2026-09-25"
      }
    },
    {
      "id": "rmm-triage-agent",
      "type": "analytic",
      "label": "Analyze RMM activity",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "rmm-inventory-scoping",
          "detect-evasion-binaries",
          "detect-rmm-stacking"
        ],
        "objective": "Determine if RMM tools on the host are rogue by checking for stacking of multiple distinct RMMs and the presence of the HideUL evasion tool.",
        "description": "Correlate inventory, evasion execution, and stacking behavior to identify rogue installs.",
        "max_iterations": 4,
        "expected_signal": "A verdict characterizing the RMM activity as rogue or authorized per host.",
        "success_criteria": "A verdict of malicious | suspicious | benign per host, citing specific stacking patterns or evasion execution."
      },
      "parents": [
        {
          "id": "detect-evasion-binaries",
          "kind": "merge"
        },
        {
          "id": "detect-rmm-stacking",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route based on RMM risk",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the rmm-triage-agent verdict is malicious for at least one host due to RMM stacking or evasion binary execution",
        "condition": "the rmm-triage-agent verdict is malicious for at least one host due to RMM stacking or evasion binary execution",
        "blind_spot": "telemetry-evasion-gap",
        "confidence": "high",
        "description": "Direct high-confidence rogue RMM detections to immediate containment.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "rmm-triage-agent"
        }
      ]
    },
    {
      "id": "isolate-endpoint",
      "type": "action",
      "label": "Isolate compromised host",
      "config": {
        "target": "endpoint",
        "description": "Shut down the attacker's remote sessions by isolating the host.",
        "instructions": "Isolate the host from the network immediately. Terminate all active ScreenConnect and ITarian processes and remove the persistence services after acquiring a forensic sample.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-manual-review",
      "type": "task",
      "label": "Analyst forensic review",
      "config": {
        "assignee": "analyst",
        "description": "Verify the agent's verdict and investigate the initial phishing delivery.",
        "instructions": "Verify the RMM tools against the approved software catalog. Review hb_http_activity for connections to TransferXL or Adobe InDesign lure pages within 24 hours prior to the RMM installation. Trace parent processes of the RMM installers to identify the initial lure file."
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "isolate-endpoint"
        }
      ]
    },
    {
      "id": "investigation-closeout",
      "type": "task",
      "label": "Remediation and tuning",
      "config": {
        "assignee": "analyst",
        "description": "Ensure full removal of the attacker's redundancy and tune detections.",
        "instructions": "Confirm all redundant RMM clients are removed. If HideUL was detected, perform a deep scan to ensure no other security tools were tampered with. Record the incident and update the RMM inventory list."
      },
      "parents": [
        {
          "id": "analyst-manual-review"
        }
      ]
    }
  ]
}