1200KM / simulation
T1219 Remote Access Tools — Attack Simulation
An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and…
Technique description
An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Ammyy Admin Software Execution
Procedure 0ae9e327-3251-465a-a53b-485d4e3f58fa; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- UltraViewer - RAT Execution
Procedure 19acf63b-55c4-4b6a-8552-00a8865105c8; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Microsoft App Quick Assist Execution
Procedure 1aea6d15-70f1-4b4e-8b02-397b5d5ffe75; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- GoToAssist Files Detected Test on Windows
Procedure 1b72b3bd-72f8-4b63-a30b-84e91b9c3578; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Splashtop Streamer Execution
Procedure 3e1858ee-3550-401c-86ec-5e70ed79295b; elevation required; cleanup not declared. Not executed or individually validated.
- UltraVNC Execution
Procedure 42e51815-a6cc-4c75-b970-3f0ff54b610e; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- ScreenConnect Application Download and Install on Windows
Procedure 4a18cc4e-416f-4966-9a9d-75731c4684c0; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- AnyDesk Files Detected Test on Windows
Procedure 6b8b7391-5c0a-4f8c-baee-78d8ce0ce330; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- TeamViewer Files Detected Test on Windows
Procedure 8ca3b96d-8983-4a7f-b125-fc98cc0a2aa0; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Splashtop Execution
Procedure b025c580-029e-4023-888d-a42710d76934; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- MSP360 Connect Execution
Procedure b1b8128b-c5d4-4de9-bf70-e60419274562; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- LogMeIn Files Detected Test on Windows
Procedure d03683ec-aae0-42f9-9b4c-534780e0f8e1; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- NetSupport - RAT Execution
Procedure ecca999b-e0c8-40e8-8416-ad320b146a75; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- RustDesk Files Detected Test on Windows
Procedure f1641ba9-919a-4323-b74f-33372333bf0e; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- RemotePC Software Execution
Procedure fbff3f1f-b0bf-448e-840f-7e1687affdce; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.