Huntbase Hub · All hunts

Threat hunts for AnyDesk

4 hunts covering AnyDesk, each with a hypothesis, the queries that test it and what the hunt cannot see.

4 hunts

  1. medium Part 2 of 2
    Research by Cisco Talos

    Unauthorized RMM and Ransomware Precursors

    An adversary is using unauthorized remote management tools to maintain persistence and is performing credential harvesting or staging ransomware encryption.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  2. medium Part 1 of 2
    Research by Cisco Talos

    Cloud Identity and AI Agent Anomalies

    An adversary has used social engineering or exploited public-facing remote services to compromise an administrative identity, then used that access to manipulate cloud repositories or orchestration layers via automated agents.

    3 query2 analytic2 checkpoint1 action2 task
    credential access · discovery · impact
  3. high Part 2 of 2
    Research by Huntress

    On-Host Miner Compilation and Resource Hijacking

    An adversary has compiled a custom Monero miner directly on an endpoint using .NET and C compilers before executing it as a system process to hijack compute resources.

    3 query1 analytic1 checkpoint1 action2 task
    defense evasion · execution · impact
  4. high Part 2 of 2
    Research by Huntress

    INC Ransomware Wave 2: BYOVD and RAT Deployment

    An adversary has deployed remote access tools and Bring Your Own Vulnerable Driver (BYOVD) loaders to neutralize security products before executing INC ransomware.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution