Episode 74 - The challenge of detecting RMM abuse
SHOW NOTES
In this episode of SecOps Weekly, Principal Security Researcher Phil Hagen and Senior Detection Engineer Jason Killam discuss the challenges posed by Remote Management and Monitoring (RMM) tools in the security space. The presenters explain how these legitimate tools, such as AnyDesk and LogMeIn, are being abused by threat actors to gain remote access to systems under various pretexts, including social engineering tactics like fake party invites or tax forms. The discussion covers the difficulty of detecting these tools because they are often signed by legitimate companies, making them harder to distinguish from authorized help desk activity. The session also touches upon how attackers use RMMs to pivot through networks and deploy ransomware.
TIMESTAMPS
- 00:00: Welcome to SecOps Weekly!
- 01:44 : What are RMM tools?
- 05:13: The challenge of tracking RMM abuse
- 09:12: Researching the nefarious use
- 15:02: What defenders can do about it