Loading interactive filters…
1200KM / detection
T1021 Remote Services — Detection Rules
Detection workspace for T1021 Remote Services: 10 Sigma sources, 0 Atlas concepts and 1 anomaly models. No live detection validation.
Source-backed rule directory
- OpenCanary - FTP Login Attempt · test · high · {"category":"application","product":"opencanary"}
- OpenCanary - SMB File Open Request · test · high · {"category":"application","product":"opencanary"}
- OpenCanary - SNMP OID Request · test · high · {"category":"application","product":"opencanary"}
- OpenCanary - SSH Login Attempt · test · high · {"category":"application","product":"opencanary"}
- OpenCanary - SSH New Connection Attempt · test · high · {"category":"application","product":"opencanary"}
- OpenCanary - VNC Connection Attempt · test · high · {"category":"application","product":"opencanary"}
- HackTool - NetExec Execution · experimental · high · {"category":"process_creation","product":"windows"}
- Privilege Escalation via Named Pipe Impersonation · test · high · {"category":"process_creation","product":"windows"}
- Potential Remote Desktop Tunneling · test · medium · {"category":"process_creation","product":"windows"}
- Psexec Execution · test · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
Remote administrative service used between systems — T1021 Remote Services
Comparison unit: user-source-destination graph.
Expected behavior: administrative connections follow recurring paths.
Deviation: new edge, unusual path, or broad fan-out from one source.
ATT&CK analytic guidance
Logon via RDP or WMI by a user account followed by uncommon command execution, file manipulation, or lateral network connections.
SSH session from new source IP followed by interactive shell or privilege escalation (e.g., sudo, su) and outbound lateral connection.
Remote login via ARD or SSH followed by screensharingd process activity or modification of TCC-protected files.
Use of cloud-based bastion or VM console session followed by commands that initiate outbound SSH or RDP sessions from the cloud instance to other environments.
vSphere API logins (vimService) or SSH to ESXi host followed by unauthorized shell commands or lateral remote logins from the ESXi host.
Connected ecosystem references
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.