← All hunts medium TLP:CLEAR Part 2 of 2

Rogue RMM Persistence and Defense Evasion

An intruder has established persistent access by installing unauthorized RMM tools and blinded security controls using evasion utilities like HideUL to mask the redundant access paths.

Based on research by Huntress 2026-09-25 9 steps · 3 queries T1190 T1219 T1562 T1566

Brief

Why this hunt matters

Recent reporting from Huntress in Rogue RMM Abuse: How Attackers Exploit Remote Access Tools highlights a shift in persistence tactics. Attackers no longer rely solely on custom backdoors; they deploy legitimate Remote Monitoring and Management (RMM) tools. These tools provide stable access and often bypass basic file-based detections. This hunt targets the specific behavior of "stacking" RMMs and the use of evasion utilities to hide these connections.

How the Hunt Flows

The hunt begins with a scoping phase using the hb_software_inventory surface. This query builds a list of hosts where ScreenConnect, ITarian, or ConnectWise agents are registered through standard package managers. This step provides an initial list of systems for deeper inspection, though it does not yet confirm malicious intent.

Following the inventory check, the hunt moves into a parallel behavioral analysis phase using hb_process_activity. One branch searches for the execution of HideUL (e.g., hideul_x64.exe). This utility has no legitimate business application; attackers use it to suppress security logging and hide their RMM sessions. The presence of this binary is a high-confidence indicator of an active intrusion.

Simultaneously, a second branch looks for RMM stacking. This query counts unique RMM clients running on a single host. While an IT team might use one tool, they rarely run two or three distinct RMM services on the same workstation. The hunt uses process names and original file names to identify these tools even if the adversary renames the binaries to evade detection.

Finally, a triage agent correlates the inventory data with the behavioral results. If a host shows both RMM stacking and the execution of evasion tools, the hunt triggers an isolation response or routes the case for manual forensic review. The analyst then traces the parent processes to find the initial delivery vector, such as an Adobe InDesign lure or a TransferXL download.

What this hunt cannot see

This hunt has two primary blind spots. First, if an attacker successfully uses HideUL to blind the security agent before the stacking behavior begins, the telemetry for those processes will not reach the platform. This hunt relies on the security agent's integrity. Second, the initial scoping query only sees RMM tools installed via package managers. If an attacker runs a portable version of ScreenConnect that does not register as installed software, the hunt must rely entirely on the behavioral process queries.

In this series

Steps

  1. Inventory of known RMM packages

    Query · scoping

    Find hosts with ScreenConnect or ITarian installed via package managers to focus the behavioral analysis.

    reads hb_software_inventorysql
    SELECT device_hostname, package_name, vendor_name, package_version FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%screenconnect%' OR LOWER(package_name) LIKE '%itarian%' OR LOWER(vendor_name) LIKE '%connectwise%' OR LOWER(vendor_name) LIKE '%itarian%')

    What a hit looks like. A list of hosts with RMM software. Silence means no RMM was installed via standard package managers, but does not rule out portable versions.

  2. Defense evasion tool execution

    Query · detection candidate

    Identify the execution of HideUL, which attackers use to blind security telemetry, using path-suffix matching.

    reads hb_process_activitysql
    SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_name) LIKE '%hideul_x64.exe' OR LOWER(process_name) LIKE '%hideul.exe') AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. A process match for HideUL. This utility has no legitimate business purpose and is used to hide RMM activity.

  3. RMM stacking and redundancy

    Query · baseline

    Detect hosts where multiple different RMM tools are running simultaneously, incorporating original file names to catch renamed binaries.

    reads hb_process_activitysql
    SELECT device_hostname, COUNT(DISTINCT CASE WHEN LOWER(process_name) LIKE '%screenconnect%' OR LOWER(process_original_file_name) LIKE '%screenconnect%' THEN 'ScreenConnect' WHEN LOWER(process_name) LIKE '%itarian%' OR LOWER(process_original_file_name) LIKE '%itarian%' OR LOWER(process_name) LIKE '%itsm_service%' OR LOWER(process_name) LIKE '%itcm%' THEN 'ITarian' END) AS unique_rmm_count, GROUP_CONCAT(DISTINCT process_name) AS rmm_processes, MIN(time) AS first_seen FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_name) LIKE '%screenconnect%' OR LOWER(process_name) LIKE '%itarian%' OR LOWER(process_name) LIKE '%itsm_service%' OR LOWER(process_name) LIKE '%itcm%' OR LOWER(process_original_file_name) LIKE '%screenconnect%' OR LOWER(process_original_file_name) LIKE '%itarian%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname HAVING unique_rmm_count > 1

    What a hit looks like. Hosts running multiple distinct RMM clients simultaneously. This stacking behavior is characteristic of an intruder ensuring redundant access.

  4. Analyze RMM activity

    Agent triage

    Correlate inventory, evasion execution, and stacking behavior to identify rogue installs.

  5. Route based on RMM risk

    Decision

    Direct high-confidence rogue RMM detections to immediate containment.

  6. Isolate compromised host

    Response action

    Shut down the attacker's remote sessions by isolating the host.

  7. Analyst forensic review

    Analyst task

    Verify the agent's verdict and investigate the initial phishing delivery.

  8. Remediation and tuning

    Analyst task

    Ensure full removal of the attacker's redundancy and tune detections.

Coverage

Scenario coverage

StageCoveredHow, or why not
Rogue RMM Installation and Persistence
T1219
Yes rmm-inventory-scoping, detect-rmm-stacking
Defense Evasion Activity
T1562
Yes detect-evasion-binaries
Redundant RMM Stacking
T1219
Yes detect-rmm-stacking, rmm-triage-agent
Phishing Delivery and Lure
T1566
Out of scope Belongs to another part of the 'Rogue RMM Abuse: How Attackers Exploit Remote Access Tools' series.
C2 Redirect and Payload Download
T1203
Out of scope Belongs to another part of the 'Rogue RMM Abuse: How Attackers Exploit Remote Access Tools' series.

Blind spots

  • Needs Unmodified EDR telemetry. If HideUL successfully disables logging, the stacking activity will be invisible to process and registry surfaces. It would answer whether HideUL successfully blinded the logging agent. Remediation: Deploy tamper-protection for the security agent and monitor for service stop events.
  • Needs hb_software_inventory. The scoping query based on software inventory will miss portable versions of ITarian or ScreenConnect. It would answer whether the RMM was run as a portable binary without installation. Remediation: Rely on hb_process_activity and hb_network_connection for behavioral leads on portable tools.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
lookback_daysnumber14Days of history to examine.
scope_hostslist[host]—Hosts to focus on from scoping; empty searches the estate.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: "A simple detection rule fires on a single RMM installer; this hunt pivots\
  \ to look for 'stacking'\u2014multiple distinct RMMs on one host\u2014and correlates\
  \ it with specialized evasion binaries like HideUL to distinguish an intrusion from\
  \ a configuration error."
blind_spots:
- id: telemetry-evasion-gap
  owner: Endpoint Engineering
  question: whether HideUL successfully blinded the logging agent
  remediation: Deploy tamper-protection for the security agent and monitor for service
    stop events.
  requires: Unmodified EDR telemetry
  risk: If HideUL successfully disables logging, the stacking activity will be invisible
    to process and registry surfaces.
  stage: defense-evasion-activity
- id: portable-rmm-blindness
  owner: Threat Hunting
  question: whether the RMM was run as a portable binary without installation
  remediation: Rely on hb_process_activity and hb_network_connection for behavioral
    leads on portable tools.
  requires: hb_software_inventory
  risk: The scoping query based on software inventory will miss portable versions
    of ITarian or ScreenConnect.
  stage: rogue-rmm-installation-and-persistence
coverage:
- stage: rogue-rmm-installation-and-persistence
  status: covered
  steps:
  - rmm-inventory-scoping
  - detect-rmm-stacking
- stage: defense-evasion-activity
  status: covered
  steps:
  - detect-evasion-binaries
- stage: redundant-rmm-stacking
  status: covered
  steps:
  - detect-rmm-stacking
  - rmm-triage-agent
- reason: 'Belongs to another part of the ''Rogue RMM Abuse: How Attackers Exploit
    Remote Access Tools'' series.'
  stage: phishing-delivery-and-lure
  status: out_of_scope
- reason: 'Belongs to another part of the ''Rogue RMM Abuse: How Attackers Exploit
    Remote Access Tools'' series.'
  stage: c2-redirect-and-payload-download
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: keep-as-periodic-hunt
  justification: RMM abuse is involved in nearly 40% of recent incidents; detecting
    rogue management stacking is critical to ensuring an attacker hasn't left a secondary
    persistence path behind after initial remediation.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An intruder has established persistent access by installing unauthorized
  RMM tools and blinded security controls using evasion utilities like HideUL to mask
  the redundant access paths.
labels:
- hunt
- attack.t1219
- attack.t1562
- attack.t1566
- attack.t1190
name: Rogue RMM Persistence and Defense Evasion
parameters:
  lookback_days:
    default: '14'
    description: Days of history to examine.
    from:
      kind: manual
      observed: '2026-09-23'
      ref: hunt-standard
    type: number
  scope_hosts:
    default: []
    description: Hosts to focus on from scoping; empty searches the estate.
    from:
      kind: manual
      observed: '2026-09-23'
      ref: analyst-input
    type: list[host]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.huntress.com/blog/rogue-rmm-abuse-phishing-persistent-access
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Target all Windows endpoints. Phishing for RMM abuse typically targets
  end-users rather than IT staff, making the presence of these tools on non-admin
  workstations a high-priority lead.
references:
- name: "Huntress \u2014 Rogue RMM Abuse: How Attackers Exploit Remote Access Tools"
  url: https://www.huntress.com/blog/rogue-rmm-abuse-phishing-persistent-access
related:
- hunt: unauthorized-remote-access-tool-usage
  reason: This hunt focuses on attacker stacking and evasion, not general policy violations
    for unauthorized software.
  relation: out-of-scope-alternative
- hunt: rogue-rmm-delivery-trusted-service-phishing
  relation: follows
scenario:
  stages:
  - name: Phishing Delivery and Lure
    observables:
    - TransferXL email
    - Adobe InDesign lure page
    - View Document button
    - ZIP files
    - Nested PDF lures
    slug: phishing-delivery-and-lure
    tactic: initial-access
    techniques:
    - T1566
  - name: C2 Redirect and Payload Download
    observables:
    - Attacker-controlled C2 infrastructure
    - Rogue RMM installer download
    - ScreenConnect client installer
    - ITarian client installer
    slug: c2-redirect-and-payload-download
    tactic: execution
    techniques:
    - T1203
  - name: Rogue RMM Installation and Persistence
    observables:
    - ITarian client installation
    - ScreenConnect client installation
    - SYSTEM-level privileges
    - Persistent remote access service
    slug: rogue-rmm-installation-and-persistence
    tactic: persistence
    techniques:
    - T1219
  - name: Defense Evasion Activity
    observables:
    - HideUL_x64.exe
    slug: defense-evasion-activity
    tactic: defense-evasion
    techniques:
    - T1562
  - name: Redundant RMM Stacking
    observables:
    - Multiple rogue RMM clients
    - ITarian and ScreenConnect coexistence
    - Redundant ScreenConnect instances
    slug: redundant-rmm-stacking
    tactic: persistence
    techniques:
    - T1219
  summary: Threat actors are using phishing emails with lures hosted on legitimate
    services like TransferXL and Adobe InDesign to trick victims into installing rogue
    RMM tools like ITarian and ScreenConnect. These tools provide persistent, hands-on
    control and are often deployed in redundant pairs alongside defense evasion binaries
    like HideUL_x64.exe to maintain long-term access.
series:
  index: 2
  slug: rogue-rmm-abuse-how-attackers-exploit-remote-access-tools
  title: 'Rogue RMM Abuse: How Attackers Exploit Remote Access Tools'
  total: 2
severity: medium
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
tlp: clear
type: investigation
---


# Rogue RMM Persistence and Defense Evasion

This hunt identifies the lifecycle of RMM abuse where attackers deploy legitimate remote management tools for redundant persistence. It specifically looks for the stacking of multiple RMM clients on a single host—a high-confidence indicator of rogue activity—alongside the use of evasion utilities intended to mask malicious connections. By examining both software inventory and active process behavior, the hunt distinguishes between authorized IT tools and attacker-controlled instances.

## rmm-inventory-scoping
<!-- Inventory of known RMM packages -->
Find hosts with ScreenConnect or ITarian installed via package managers to focus the behavioral analysis.

```sqlite target=endpoint role=scoping
~~~yaml
expected: A list of hosts with RMM software. Silence means no RMM was installed via
  standard package managers, but does not rule out portable versions.
reads:
- device_hostname
- package_name
- vendor_name
- package_version
silence: not_evidence_of_absence
source: hb_software_inventory
verified: dry-run
verified_at: '2026-09-25'
~~~
SELECT device_hostname, package_name, vendor_name, package_version FROM hb_software_inventory WHERE (LOWER(package_name) LIKE '%screenconnect%' OR LOWER(package_name) LIKE '%itarian%' OR LOWER(vendor_name) LIKE '%connectwise%' OR LOWER(vendor_name) LIKE '%itarian%')
```

## behavioral-checks
<!-- Behavioral evidence gathering -->
parallel:
- → detect-evasion-binaries
- → detect-rmm-stacking
join: → rmm-triage-agent

## detect-evasion-binaries
<!-- Defense evasion tool execution -->
Identify the execution of HideUL, which attackers use to blind security telemetry, using path-suffix matching.

```sqlite target=endpoint role=detection-candidate params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: A process match for HideUL. This utility has no legitimate business purpose
  and is used to hide RMM activity.
reads:
- device_hostname
- process_name
- process_cmd_line
- user_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-25'
~~~
SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_name) LIKE '%hideul_x64.exe' OR LOWER(process_name) LIKE '%hideul.exe') AND time >= datetime('now', '-{{lookback_days}} days')
```

## detect-rmm-stacking
<!-- RMM stacking and redundancy -->
Detect hosts where multiple different RMM tools are running simultaneously, incorporating original file names to catch renamed binaries.

```sqlite target=endpoint role=baseline params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
baseline:
  compare: new_this_window
  window: '{{lookback_days}}d'
expected: Hosts running multiple distinct RMM clients simultaneously. This stacking
  behavior is characteristic of an intruder ensuring redundant access.
prevalence:
  by: device_hostname
  key:
  - rmm_processes
  rare_below: 2
reads:
- device_hostname
- process_name
- process_original_file_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-25'
~~~
SELECT device_hostname, COUNT(DISTINCT CASE WHEN LOWER(process_name) LIKE '%screenconnect%' OR LOWER(process_original_file_name) LIKE '%screenconnect%' THEN 'ScreenConnect' WHEN LOWER(process_name) LIKE '%itarian%' OR LOWER(process_original_file_name) LIKE '%itarian%' OR LOWER(process_name) LIKE '%itsm_service%' OR LOWER(process_name) LIKE '%itcm%' THEN 'ITarian' END) AS unique_rmm_count, GROUP_CONCAT(DISTINCT process_name) AS rmm_processes, MIN(time) AS first_seen FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_name) LIKE '%screenconnect%' OR LOWER(process_name) LIKE '%itarian%' OR LOWER(process_name) LIKE '%itsm_service%' OR LOWER(process_name) LIKE '%itcm%' OR LOWER(process_original_file_name) LIKE '%screenconnect%' OR LOWER(process_original_file_name) LIKE '%itarian%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname HAVING unique_rmm_count > 1
```

## rmm-triage-agent
<!-- Analyze RMM activity -->
```agent target=hunter
cite: required
context:
- rmm-inventory-scoping
- detect-evasion-binaries
- detect-rmm-stacking
max_iterations: 4
objective: Determine if RMM tools on the host are rogue by checking for stacking of
  multiple distinct RMMs and the presence of the HideUL evasion tool.
success_criteria: A verdict of malicious | suspicious | benign per host, citing specific
  stacking patterns or evasion execution.
tools:
- endpoint
```

## route-on-verdict
<!-- Route based on RMM risk -->
if~: "the rmm-triage-agent verdict is malicious for at least one host due to RMM stacking or evasion binary execution" (confidence: high, judge=hunter)
then: → isolate-endpoint
indeterminate: → analyst-manual-review
unavailable: → analyst-manual-review (blind_spot: telemetry-evasion-gap)
else: → analyst-manual-review

## isolate-endpoint
<!-- Isolate compromised host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host from the network immediately. Terminate all active ScreenConnect and ITarian processes and remove the persistence services after acquiring a forensic sample.
```
→ analyst-manual-review

## analyst-manual-review
<!-- Analyst forensic review -->
```manual target=analyst
Verify the RMM tools against the approved software catalog. Review hb_http_activity for connections to TransferXL or Adobe InDesign lure pages within 24 hours prior to the RMM installation. Trace parent processes of the RMM installers to identify the initial lure file.
```
→ investigation-closeout

## investigation-closeout
<!-- Remediation and tuning -->
```manual target=analyst
Confirm all redundant RMM clients are removed. If HideUL was detected, perform a deep scan to ensure no other security tools were tampered with. Record the incident and update the RMM inventory list.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.