Loading interactive filters…
1200KM / detection
T1133 External Remote Services — Detection Rules
Detection workspace for T1133 External Remote Services: 19 Sigma sources, 1 Atlas concepts and 1 anomaly models. No live detection validation.
Source-backed rule directory
- OpenCanary - RDP New Connection Attempt · experimental · high · {"category":"application","product":"opencanary"}
- OpenCanary - SSH Login Attempt · test · high · {"category":"application","product":"opencanary"}
- OpenCanary - SSH New Connection Attempt · test · high · {"category":"application","product":"opencanary"}
- OpenCanary - Telnet Login Attempt · test · high · {"category":"application","product":"opencanary"}
- Remote Access Tool - Team Viewer Session Started On Linux Host · test · low · {"category":"process_creation","product":"linux"}
- Remote Access Tool - Team Viewer Session Started On MacOS Host · test · low · {"category":"process_creation","product":"macos"}
- FortiGate - New VPN SSL Web Portal Added · experimental · medium · {"product":"fortigate","service":"event"}
- FortiGate - VPN SSL Settings Modified · experimental · medium · {"product":"fortigate","service":"event"}
- External Remote RDP Logon from Public IP · test · medium · {"product":"windows","service":"security"}
- External Remote SMB Logon from Public IP · test · high · {"product":"windows","service":"security"}
- Failed Logon From Public IP · test · medium · {"product":"windows","service":"security"}
- Unusual File Modification by dns.exe · test · high · {"category":"file_change","product":"windows"}
- Unusual File Deletion by Dns.exe · test · high · {"category":"file_delete","product":"windows"}
- Suspicious File Created by ArcSOC.exe · experimental · high · {"category":"file_event","product":"windows"}
- Unusual Child Process of dns.exe · test · high · {"category":"process_creation","product":"windows"}
- Remote Access Tool - ScreenConnect Installation Execution · test · medium · {"category":"process_creation","product":"windows"}
- Remote Access Tool - Team Viewer Session Started On Windows Host · test · low · {"category":"process_creation","product":"windows"}
- User Added to Remote Desktop Users Group · test · high · {"category":"process_creation","product":"windows"}
- Running Chrome VPN Extensions via the Registry 2 VPN Extension · test · high · {"category":"registry_set","product":"windows"}
Atlas deterministic concepts
T1133 External Remote Services
MATCH(successful_remote_access) AND source_ip NOT_IN approved_networks -> ALERT
Anomaly models
External remote-service session — T1133 External Remote Services
Comparison unit: user-device-service relationship.
Expected behavior: remote access follows established source, device, and destination relationships.
Deviation: a new edge, unusual session duration, or access outside the entity's temporal context.
ATT&CK analytic guidance
Unusual or unauthorized external remote access attempts (e.g., RDP, VPN, Citrix) → repeated failed logins followed by a successful session from uncommon geolocations or outside business hours → subsequent internal lateral movement or data exfiltration activities.
Repeated SSH, VPN, or RDP gateway authentication attempts from external IPs → subsequent successful logon → remote shell or lateral movement activity (e.g., scp/sftp).
Unexpected inbound or outbound VNC/SSH/Screen Sharing connections from external sources → repeated failed logins followed by success → remote interactive sessions or abnormal file transfers.
Connections to exposed container services (e.g., Docker API, Kubernetes API server) from unauthorized external IPs → abnormal container creation/start → lateral activity within cluster nodes.
Connected ecosystem references
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.