T1219.002sub-technique of T1219 Remote Access Tools
Remote Desktop Software
Linux · macOS · Windows1 piece on this siteT1219.002 on attack.mitre.org
An adversary may use legitimate desktop support software to establish an interactive command and control channel to target systems within networks. Desktop support software provides a graphical interface for remotely controlling another computer, transmitting the display output, keyboard input, and mouse control between devices using various protocols.
If this is happening now
Checklists and playbooks to open while the alert is still live.
First-hour playbookMembers
A remote access tool nobody installed
AnyDesk, ScreenConnect, TeamViewer, Atera, Splashtop or something like them appears on a host where IT does not use it, or a sanctioned tool connects to an account or relay you do not own.
T1219T1219.002
how MITRE says to see it
Remote Desktop Software Execution and Beaconing Detection
- Adversary installation or use of RMM software (e.g., TeamViewer, AnyDesk, ScreenConnect) followed by outbound beaconing or remote session establishment
- Execution of known or custom VNC/remote desktop daemons or tunneling agents that initiate external communication after launch
- Initiation of remote desktop sessions via AnyDesk, TeamViewer, or Chrome Remote Desktop accompanied by unexpected user logins or system modifications
what reduces it
- M1037 Filter Network Traffic. Properly configure firewalls, application firewalls, and proxies to limit outgoing traffic to sites and services used by remote access software.
- M1038 Execution Prevention. Use application control to mitigate installation and use of unapproved software that can be used for remote access.
- M1042 Disable or Remove Feature or Program. Consider disabling unnecessary remote connection functionality, including both unapproved software installations and specific features built into supported applications.