1200KM / detection
T1219 Remote Access Tools — Detection Rules
Detection workspace for T1219 Remote Access Tools: 6 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Potentially Suspicious File Creation by OpenEDR's ITSMService · experimental · medium · {"product":"windows","category":"file_event"}
- OpenEDR Spawning Command Shell · experimental · medium · {"product":"windows","category":"process_creation"}
- Remote Access Tool - TacticalRMM Agent Registration to Potentially Attacker-Controlled Server · experimental · medium · {"category":"process_creation","product":"windows"}
- Suspicious Velociraptor Child Process · experimental · high · {"category":"process_creation","product":"windows"}
- Visual Studio Code Tunnel Execution · test · medium · {"category":"process_creation","product":"windows"}
- Renamed Visual Studio Code Tunnel Execution · test · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0496 Behavior-Chain Detection for Remote Access Tools (Tool-Agnostic)
AN1366 Analytic 1366
Chain of remote access tool behavior: (1) initial execution of remote-control/assist agent or GUI under user context; (2) persistence via service or autorun; (3) long-lived outbound connection/tunnel to external infrastructure; (4) interactive control signals such as shell or file-manager child processes spawned by the RAT parent.
AN1367 Analytic 1367
Sequence of RAT agent execution, systemd persistence, and long-lived external egress; optional interactive shells spawned from the agent.
AN1368 Analytic 1368
Electron/GUI or headless RAT execution followed by LaunchAgent/Daemon persistence and persistent external connections; interactive children (osascript/sh/curl) spawned by parent.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- File Creation · DC0039
- Network Connection Creation · DC0082
- Process Creation · DC0032
- Service Creation · DC0060
- Windows Registry Key Creation · DC0056
- Windows Registry Key Modification · DC0063
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.