Skip to content

Commit 4d06544

Browse files
authored
Add RMM Process detected hunting
1 parent e889de6 commit 4d06544

1 file changed

Lines changed: 5 additions & 0 deletions

File tree

s1_powerquery_hunting.json

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -389,5 +389,10 @@
389389
"category" : "Command & Control",
390390
"name": "Remote installation of custom chromium extensions",
391391
"query": "endpoint.os = \"windows\" AND event.type contains:anycase (\"File Creation\", \"File Modification\") AND (tgt.file.path matches:anycase \"\\\\\\\\Secure Preferences$\" OR tgt.file.path matches:anycase \"\\\\\\\\Preferences$\") NOT(src.process.name contains:anycase (\"chrome\",\"edege\",\"spotify\",\"opera\",\"brave\",\"msedgewebview2\",\"HPWPD.exe\"))\n| group _FirstSeenMs=min(event.time), _LastSeenMs=max(event.time), Count=count() by endpoint.name, src.process.user, src.process.parent.name, src.process.name, src.process.cmdline, tgt.file.path\n| let _firstSeenNs = _FirstSeenMs * 1000000\n| let _lastSeenNs = _LastSeenMs * 1000000\n| columns \"first.timestamp\" = _firstSeenNs, \"last.timestamp\" = _lastSeenNs, endpoint.name, src.process.user, src.process.parent.name, src.process.name, src.process.cmdline, tgt.file.path, Count\n| sort -Count\n| limit 100000"
392+
},
393+
{
394+
"category" : "Installation & Persistence",
395+
"name": "RMM Process detected",
396+
"query": "(src.process.name contains:anycase (\"TeamViewer.exe\", \"AnyDesk.exe\", \"ScreenConnect.Client.exe\", \"LogMeIn.exe\", \"SRManager.exe\", \"SplashtopRemoteService.exe\", \"g2comm.exe\", \"g2tray.exe\", \"winvnc.exe\", \"DWRCS.exe\", \"DWRCSMS.exe\", \"rfusclient.exe\", \"rutserv.exe\", \"ZohoAssistService.exe\", \"KaUsrTsk.exe\", \"AgentMon.exe\", \"AteraAgent.exe\", \"pulsewayagent.exe\", \"NinjaRMMAgent.exe\", \"ncentralagent.exe\", \"MWAgent.exe\", \"ITSMService.exe\", \"CloudBerryRemoteAssistant.exe\", \"DomotzAgent.exe\", \"rasagent.exe\", \"client32.exe\", \"pciclient.exe\", \"vncserver.exe\", \"vncviewer.exe\", \"tvnviewer.exe\", \"tvnserver.exe\", \"AA_v3.exe\", \"rpclient.exe\", \"dwagent.exe\", \"isl_light_client.exe\", \"RemoteDesktopManager.exe\", \"Bomgar-scc.exe\", \"bomgar-rep.exe\", \"AweSun.exe\", \"wtserver.exe\", \"Action1Agent.exe\", \"Addigy.app\", \"AeroAdmin.exe\", \"Alpemix.exe\", \"apc_admin.exe\", \"AnyViewer.exe\", \"AuvikAgentService.exe\", \"BYS.exe\", \"BASupSrvc.exe\", \"remoting_host.exe\", \"CrossLoopConnect.exe\", \"CrossTecRemote.exe\", \"CagService.exe\", \"DesktopNow.exe\", \"DistantDesktop.exe\", \"ehorusclientctl.exe\", \"fleetdeck_agent_svc\", \"getscreen.exe\", \"IperiusRemote.exe\", \"JumpCloud.exe\", \"server.exe\", \"MeshAgent.exe\", \"mRemoteNG.exe\", \"naveriskagent.exe\", \"OptiTuneAgent.exe\", \"Panorama9.exe\", \"parsecd.exe\", \"PDQInventory.exe\", \"rserver3.exe\", \"rustdesk.exe\", \"ScreenMeetSupport.app\", \"ScreenMeetSupport.exe\", \"ServerEye.Client.exe\", \"wShowMyPC.exe\", \"simplehelp.exe\", \"Supremo.exe\", \"Syncro.exe\", \"SyspectrAgent.exe\", \"TacticalAgent.exe\", \"techinline.exe\", \"winvnc4.exe\", \"UltraViewer.exe\", \"XMReality.exe\"))\nOR\n(src.process.parent.name contains:anycase (\"TeamViewer\", \"AnyDesk\", \"ScreenConnect.Client\", \"LogMeIn\", \"SRManager\", \"SplashtopRemoteService\", \"g2comm\", \"g2tray\", \"winvnc\", \"DWRCS\", \"DWRCSMS\", \"rfusclient\", \"rutserv\", \"ZohoAssistService\", \"KaUsrTsk\", \"AgentMon\", \"AteraAgent\", \"pulsewayagent\", \"NinjaRMMAgent\", \"ncentralagent\", \"MWAgent\", \"ITSMService\", \"CloudBerryRemoteAssistant\", \"DomotzAgent\", \"rasagent\", \"client32\", \"pciclient\", \"vncserver\", \"vncviewer\", \"tvnviewer\", \"tvnserver\", \"AA_v3\", \"rpclient\", \"dwagent\", \"isl_light_client\", \"RemoteDesktopManager\", \"Bomgar-scc\", \"bomgar-rep\", \"AweSun\", \"wtserver\", \"Action1Agent\", \"Addigy.app\", \"AeroAdmin\", \"Alpemix\", \"apc_admin\", \"AnyViewer\", \"AuvikAgentService\", \"BYS\", \"BASupSrvc\", \"remoting_host\", \"CrossLoopConnect\", \"CrossTecRemote\", \"CagService\", \"DesktopNow\", \"DistantDesktop\", \"ehorusclientctl\", \"fleetdeck_agent_svc\", \"getscreen.exe\", \"IperiusRemote\", \"JumpCloud\", \"server\", \"MeshAgent\", \"mRemoteNG\", \"naveriskagent\", \"OptiTuneAgent\", \"Panorama9\", \"parsecd\", \"PDQInventory\", \"rserver3\", \"rustdesk.exe\", \"ScreenMeetSupport.app\", \"ScreenMeetSupport.exe\", \"ServerEye.Client\", \"wShowMyPC\", \"simplehelp\", \"Supremo\", \"Syncro\", \"SyspectrAgent\", \"TacticalAgent\", \"techinline\", \"winvnc4\", \"UltraViewer\", \"XMReality\"))\nAND\nNOT src.process.cmdline contains:anycase (\"Microsoft.DesktopAppInstaller\",\"Microsoft Azure AD Sync\",\"SAP BusinessObjects\")\n| group _FirstSeenMs=min(event.time), _LastSeenMs=max(event.time), Count=count() by endpoint.name, src.process.user, src.process.parent.name, src.process.name, src.process.cmdline, tgt.process.cmdline, event.dns.request\n| let _firstSeenNs = _FirstSeenMs * 1000000\n| let _lastSeenNs = _LastSeenMs * 1000000\n| columns \"first.timestamp\" = _firstSeenNs, \"last.timestamp\" = _lastSeenNs, endpoint.name, src.process.user, src.process.parent.name, src.process.name, src.process.cmdline, tgt.process.cmdline, event.dns.request, Count\n| sort -Count\n| limit 100000"
392397
}
393398
]

0 commit comments

Comments
 (0)