← All hunts medium TLP:CLEAR Part 2 of 2

Unauthorized RMM and Ransomware Precursors

An adversary is using unauthorized remote management tools to maintain persistence and is performing credential harvesting or staging ransomware encryption.

Based on research by Cisco Talos 2026-10-02 9 steps · 3 queries T1003.001 T1133 T1486

Brief

Why Now

Cisco Talos recently highlighted the complexity of modern intrusions in The Fine Art of Frustrating the Adversary. They detail how attackers use legitimate tools to blend into environment noise. This hunt focuses on one of the most common dual-use patterns: Remote Monitoring and Management (RMM) software. While these tools facilitate IT administration, they also provide adversaries with persistent access and a platform for lateral movement.

How the Hunt Flows

The first phase scopes the environment by identifying hosts running common RMM software. The query checks for process names like AnyDesk, ScreenConnect, and Atera. Because many organizations use at least one of these tools for legitimate support, this step is a filter rather than a definitive alert. It builds a list of candidate hosts for deeper inspection.

Once the hunt identifies hosts with RMM activity, it initiates a parallel check for high-risk behaviors. One branch examines process telemetry for signs of credential harvesting. It specifically looks for command-line arguments targeting LSASS memory, such as minidump calls via comsvcs.dll or the use of ProcDump and Mimikatz. These actions frequently follow the establishment of an RMM-based foothold.

Simultaneously, the hunt monitors file system telemetry for mass modification events. The playbook looks for a high volume of unique file updates or renames on the same hosts. This behavioral indicator suggests the encryption phase of a ransomware attack is underway. Identifying this volume-based anomaly allows an analyst to catch the impact phase before the entire disk is lost.

In the final phase, the analyst correlates the findings. If a host running an unauthorized tool also exhibits LSASS dumping or mass file modification, the playbook provides instructions for immediate network isolation. If the tool presence is the only indicator, the workflow shifts to a manual verification task with IT asset owners to confirm if the software is a known exception.

Blind Spots

Visibility relies entirely on endpoint agent coverage. The hunt cannot see unauthorized tools running on unmanaged or shadow IT devices that lack the necessary telemetry. Furthermore, sophisticated adversaries might bypass command-line detection by using direct API calls or custom binaries to access memory. This hunt prioritizes high-confidence process and file indicators but may miss entirely in-memory techniques.

In this series

Steps

  1. Identify hosts running RMM software

    Query · scoping

    Find every host running remote management software that might not be part of the authorized IT toolkit.

    reads hb_process_activitysql
    SELECT device_hostname, process_name, process_path, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{rmm_names}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{rmm_names}}' || ',', ',' || LOWER(process_path) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. A list of hosts and their RMM processes. Silence means no such tools were running in the window.

  2. Credential harvesting via LSASS dumping

    Query · detection candidate

    Detect the use of comsvcs.dll or procdump to target LSASS on hosts identified as having RMM presence.

    reads hb_process_activitysql
    SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_cmd_line) LIKE '%comsvcs.dll%minidump%' OR LOWER(process_cmd_line) LIKE '%procdump%lsass%' OR LOWER(process_original_file_name) = 'mimikatz.exe') AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Any row showing LSASS memory access on an RMM-equipped host. Silence means no such commands were captured.

  3. Mass file modification for encryption

    Query · baseline

    Find hosts with an anomalous volume of renames or updates, typical of ransomware encryption activity.

    reads hb_file_activitysql
    SELECT device_hostname, COUNT(DISTINCT file_path) AS unique_files, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_file_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND activity_id IN (3, 5) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname HAVING unique_files > 500

    What a hit looks like. A list of hosts where a large number of unique files were renamed or updated in a short window.

  4. Triage endpoint risk indicators

    Agent triage

    Correlate RMM presence with credential harvesting and encryption behaviors to determine if an active intrusion is occurring.

  5. Route on risk verdict

    Decision

    Route to containment if an active threat is identified.

  6. Isolate compromised host

    Response action

    Prevent further movement or completion of encryption by isolating the host.

  7. Verify RMM authorization

    Analyst task

    Confirm with asset owners or IT if the identified RMM tool was an authorized exception.

  8. Close out hunt

    Analyst task

    Document findings and propose tuning.

Coverage

Scenario coverage

StageCoveredHow, or why not
Persistence via RMM Software
T1133
Yes find-unauthorized-rmm
LSASS Credential Access
T1003.001
Yes lsass-credential-access
Ransomware Encryption
T1486
Yes mass-file-activity
Phishing and Social Engineering
T1204.002
Out of scope Belongs to another part of the 'The Fine Art of Frustrating the Adversary' series.
Exploitation of Public-Facing Apps
T1190 · T1133
Out of scope Belongs to another part of the 'The Fine Art of Frustrating the Adversary' series.
Agentic Malactivity and Discovery
T1190
Out of scope Belongs to another part of the 'The Fine Art of Frustrating the Adversary' series.

Blind spots

  • Needs an endpoint agent on every host in scope. A host without an agent will not appear in hb_process_activity, leaving a visibility gap on unmanaged network segments. It would answer Are unauthorized tools running on unmanaged or shadow IT devices?.
  • Needs hb_module_activity with memory access logs. Sophisticated tools can bypass command-line based detection of credential harvesting by using direct API calls. It would answer Is the adversary using direct ReadProcessMemory calls from a custom binary?.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
lookback_daysnumber14Days of history to examine.
rmm_nameslist[string]anydesk.exe, screenconnect.exe, zoho.exe, atera.exe, connectwise.exe, teamviewer.exe, logmein.exeCommon RMM process names to identify in the scoping step.
scope_hostslist[host]—List of hosts identified in the scoping step; paste them here to narrow the follow-on queries.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: A simple rule for AnyDesk is too noisy. This hunt pivots from the tool discovery
  to verify harmful follow-on actions including LSASS dumping and mass file operations,
  providing the context needed for high-confidence isolation.
blind_spots:
- id: unmanaged-devices
  question: Are unauthorized tools running on unmanaged or shadow IT devices?
  requires: an endpoint agent on every host in scope
  risk: A host without an agent will not appear in hb_process_activity, leaving a
    visibility gap on unmanaged network segments.
- id: in-memory-credential-access
  question: Is the adversary using direct ReadProcessMemory calls from a custom binary?
  requires: hb_module_activity with memory access logs
  risk: Sophisticated tools can bypass command-line based detection of credential
    harvesting by using direct API calls.
  stage: credential-harvesting-lsass
coverage:
- stage: unauthorized-rmm-persistence
  status: covered
  steps:
  - find-unauthorized-rmm
- stage: credential-harvesting-lsass
  status: covered
  steps:
  - lsass-credential-access
- stage: data-encrypted-for-impact
  status: covered
  steps:
  - mass-file-activity
- reason: Belongs to another part of the 'The Fine Art of Frustrating the Adversary'
    series.
  stage: initial-access-social-engineering
  status: out_of_scope
- reason: Belongs to another part of the 'The Fine Art of Frustrating the Adversary'
    series.
  stage: exploitation-public-facing-apps
  status: out_of_scope
- reason: Belongs to another part of the 'The Fine Art of Frustrating the Adversary'
    series.
  stage: ai-agent-discovery-c2
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: RMM tools are the dual-use weapon of choice for ransomware groups;
    detecting them alongside behavioral follow-ons provides the highest probability
    of stopping an attack before encryption impact.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An adversary is using unauthorized remote management tools to maintain
  persistence and is performing credential harvesting or staging ransomware encryption.
labels:
- hunt
- attack.t1003.001
- attack.t1133
- attack.t1486
- credential access
- discovery
- impact
- initial access
- persistence
name: Unauthorized RMM and Ransomware Precursors
parameters:
  lookback_days:
    default: '14'
    description: Days of history to examine.
    from:
      kind: manual
      observed: '2024-01-01'
      ref: hunt-parameters
    type: number
  rmm_names:
    default:
    - anydesk.exe
    - screenconnect.exe
    - zoho.exe
    - atera.exe
    - connectwise.exe
    - teamviewer.exe
    - logmein.exe
    description: Common RMM process names to identify in the scoping step.
    from:
      kind: article
      observed: '2026-10-01'
      ref: talos-frustrating-adversary
    type: list[string]
  scope_hosts:
    default: []
    description: List of hosts identified in the scoping step; paste them here to
      narrow the follow-on queries.
    from:
      kind: manual
      observed: '2024-01-01'
      ref: analyst-scoping
    type: list[host]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://blog.talosintelligence.com/the-fine-art-of-frustrating-the-adversary/
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Start with servers and executive workstations where the impact of ransomware
  is highest. Filter out known IT admin accounts and authorized IP ranges.
references:
- name: "Cisco Talos \u2014 The Fine Art of Frustrating the Adversary"
  url: https://blog.talosintelligence.com/the-fine-art-of-frustrating-the-adversary/
related:
- hunt: social-engineering-lure-detection
  reason: Initial access via phishing is handled in a separate hunt focused on hb_http_activity.
  relation: out-of-scope-alternative
- hunt: cloud-identity-ai-agent-anomalies
  relation: follows
scenario:
  stages:
  - name: Phishing and Social Engineering
    observables:
    - Lures sent from expired domains
    - Communication with fictional employee profiles
    - Urgency-based messaging (unpaid taxes, injured relatives)
    slug: initial-access-social-engineering
    tactic: initial-access
    techniques:
    - T1204.002
  - name: Exploitation of Public-Facing Apps
    observables:
    - Unauthorized sign-ins to critical servers
    - Connections to Kubernetes API servers
    - Access to exposed VPN gateways
    slug: exploitation-public-facing-apps
    tactic: initial-access
    techniques:
    - T1190
    - T1133
  - name: Persistence via RMM Software
    observables:
    - Zoho Unattended Agent
    - AnyDesk
    - ScreenConnect
    - Atera
    - Unauthorized remote technician sessions
    slug: unauthorized-rmm-persistence
    tactic: persistence
    techniques:
    - T1133
  - name: LSASS Credential Access
    observables:
    - Mimikatz
    - comsvcs.dll
    - procdump -ma lsass.exe
    - Direct access to LSASS memory
    slug: credential-harvesting-lsass
    tactic: credential-access
    techniques:
    - T1003.001
  - name: Agentic Malactivity and Discovery
    observables:
    - Unexpected writes to package registries
    - Repository creation and dataset commits
    - API calls to Kubernetes interfaces
    - DNS-over-HTTPS relays usage
    - Access to cloud metadata services
    slug: ai-agent-discovery-c2
    tactic: discovery
    techniques:
    - T1190
  - name: Ransomware Encryption
    observables:
    - Execution of ransomware encryptor
    - High-volume file modification / renaming
    slug: data-encrypted-for-impact
    tactic: impact
    techniques:
    - T1486
  summary: This scenario outlines the diverse set of adversary behaviors described
    by Cisco Talos, moving from initial access via social engineering or service exploitation
    to persistence using legitimate remote-management tools. It concludes with credential
    harvesting from LSASS memory, data encryption for impact, and emerging malicious
    activity from misconfigured AI agents targeting cloud infrastructure.
series:
  index: 2
  slug: the-fine-art-of-frustrating-the-adversary
  title: The Fine Art of Frustrating the Adversary
  total: 2
severity: medium
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
tlp: clear
type: investigation
---


# Unauthorized RMM and Ransomware Precursors

Adversaries often use legitimate Remote Monitoring and Management (RMM) tools like AnyDesk, ScreenConnect, and Atera to establish a persistent, low-noise foothold. This hunt identifies the presence of unauthorized RMM software and then looks for immediate high-risk follow-on activities: credential harvesting via LSASS memory dumping and high-volume file modifications indicative of ransomware encryption. By correlating the presence of these tools with behavioral indicators of impact, we can interrupt the attack chain before final data encryption.

## find-unauthorized-rmm
<!-- Identify hosts running RMM software -->
Find every host running remote management software that might not be part of the authorized IT toolkit.

```sqlite target=endpoint role=scoping params=(lookback_days=lookback_days, rmm_names=rmm_names)
~~~yaml
expected: A list of hosts and their RMM processes. Silence means no such tools were
  running in the window.
prevalence:
  by: device_hostname
  key:
  - process_name
  rare_below: 3
reads:
- device_hostname
- process_name
- process_path
- process_cmd_line
- user_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT device_hostname, process_name, process_path, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{rmm_names}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR instr(',' || '{{rmm_names}}' || ',', ',' || LOWER(process_path) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## risk-corroboration
<!-- Corroborate with high-risk behaviors -->
parallel:
- → lsass-credential-access
- → mass-file-activity
join: → triage-endpoint-risk

## lsass-credential-access
<!-- Credential harvesting via LSASS dumping -->
Detect the use of comsvcs.dll or procdump to target LSASS on hosts identified as having RMM presence.

```sqlite target=endpoint role=detection-candidate params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Any row showing LSASS memory access on an RMM-equipped host. Silence means
  no such commands were captured.
reads:
- device_hostname
- process_name
- process_cmd_line
- user_name
- time
- process_original_file_name
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(process_cmd_line) LIKE '%comsvcs.dll%minidump%' OR LOWER(process_cmd_line) LIKE '%procdump%lsass%' OR LOWER(process_original_file_name) = 'mimikatz.exe') AND time >= datetime('now', '-{{lookback_days}} days')
```

## mass-file-activity
<!-- Mass file modification for encryption -->
Find hosts with an anomalous volume of renames or updates, typical of ransomware encryption activity.

```sqlite target=endpoint role=baseline params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: A list of hosts where a large number of unique files were renamed or updated
  in a short window.
reads:
- device_hostname
- file_path
- activity_id
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-10-02'
~~~
SELECT device_hostname, COUNT(DISTINCT file_path) AS unique_files, MIN(time) AS first_seen, MAX(time) AS last_seen FROM hb_file_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND activity_id IN (3, 5) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname HAVING unique_files > 500
```

## triage-endpoint-risk
<!-- Triage endpoint risk indicators -->
```agent target=hunter
cite: required
context:
- find-unauthorized-rmm
- lsass-credential-access
- mass-file-activity
max_iterations: 4
objective: Determine if the RMM tool presence correlates with observed credential
  harvesting or mass file activity to confirm an active intrusion.
success_criteria: A verdict of malicious, suspicious, or benign for every host found
  in the scoping step.
tools:
- endpoint
```

## route-on-risk
<!-- Route on risk verdict -->
if~: "the triage verdict is malicious for at least one host based on the correlation of RMM and follow-on behaviors" (confidence: high, judge=hunter)
then: → isolate-compromised-host
indeterminate: → manual-authorization-check
unavailable: → manual-authorization-check (blind_spot: unmanaged-devices)
else: → manual-authorization-check

## isolate-compromised-host
<!-- Isolate compromised host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host immediately via the EDR platform. Do not reboot the machine.
```
→ manual-authorization-check

## manual-authorization-check
<!-- Verify RMM authorization -->
```manual target=analyst
Cross-reference the host and user against the approved software list and ticket history.
```
→ hunt-closeout

## hunt-closeout
<!-- Close out hunt -->
```manual target=analyst
Record the number of false positives. If malicious, document the time from RMM execution to LSASS dump for alerting thresholds.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, then reviewed by a person.