Skip Navigation
Get a Demo

Join the Zscaler Agentic SecOps Launch Event: ⚡ ️Machine-speed protection 🧠 Elite Red Canary expertise.

Save my seat >>
 
 
 
 
 
 
 
 
 
Resources Videos
Security operations

SecOps Weekly: Episode 74 – The challenge of detecting RMM abuse

SecOps Weekly | 07.28.26

The challenge of detecting RMM abuse

Jason Killam, Senior Detection Engineer, Zscaler, discusses the challenges of tracking and detecting remote monitoring management (RMM) tools.

SHOW NOTES

In this episode of SecOps Weekly, Principal Security Researcher Phil Hagen and Senior Detection Engineer Jason Killam discuss the challenges posed by Remote Management and Monitoring (RMM) tools in the security space. The presenters explain how these legitimate tools, such as AnyDesk and LogMeIn, are being abused by threat actors to gain remote access to systems under various pretexts, including social engineering tactics like fake party invites or tax forms. The discussion covers the difficulty of detecting these tools because they are often signed by legitimate companies, making them harder to distinguish from authorized help desk activity. The session also touches upon how attackers use RMMs to pivot through networks and deploy ransomware.

TIMESTAMPS

  • 00:00: Welcome to SecOps Weekly!
  • 01:44 : What are RMM tools?
  • 05:13: The challenge of tracking RMM abuse
  • 09:12: Researching the nefarious use
  • 15:02: What defenders can do about it

Security gaps? We got you.

Sign up for our monthly email newsletter for expert insights on MDR, threat intel, and security ops—straight to your inbox.


 
 
Back to Top