T1219.002sub-technique of T1219 Remote Access Tools

Remote Desktop Software

Linux · macOS · Windows1 piece on this siteT1219.002 on attack.mitre.org

An adversary may use legitimate desktop support software to establish an interactive command and control channel to target systems within networks. Desktop support software provides a graphical interface for remotely controlling another computer, transmitting the display output, keyboard input, and mouse control between devices using various protocols.

MITRE ATT&CK 19.2, retrieved 2026-09-12

If this is happening now

1

Checklists and playbooks to open while the alert is still live.

First-hour playbookMembers

A remote access tool nobody installed

AnyDesk, ScreenConnect, TeamViewer, Atera, Splashtop or something like them appears on a host where IT does not use it, or a sanctioned tool connects to an account or relay you do not own.

T1219T1219.002

how MITRE says to see it

Remote Desktop Software Execution and Beaconing Detection

  • Adversary installation or use of RMM software (e.g., TeamViewer, AnyDesk, ScreenConnect) followed by outbound beaconing or remote session establishment
  • Execution of known or custom VNC/remote desktop daemons or tunneling agents that initiate external communication after launch
  • Initiation of remote desktop sessions via AnyDesk, TeamViewer, or Chrome Remote Desktop accompanied by unexpected user logins or system modifications

what reduces it

  • M1037 Filter Network Traffic. Properly configure firewalls, application firewalls, and proxies to limit outgoing traffic to sites and services used by remote access software.
  • M1038 Execution Prevention. Use application control to mitigate installation and use of unapproved software that can be used for remote access.
  • M1042 Disable or Remove Feature or Program. Consider disabling unnecessary remote connection functionality, including both unapproved software installations and specific features built into supported applications.

the rest of T1219

The description, detection analytics and mitigations are reproduced from MITRE ATT&CK, version 19.2, under its terms of use. The checklists, hunts, labs and everything else linked here are this site’s.