1200KM / tool
Imminent Monitor — Attack Tool
Imminent Monitor was a commodity remote access tool (RAT) offered for sale from 2012 until 2019, when an operation was conducted to take down the Imminent Monitor infrastructure. Various cracked versions and variations of this RAT are still in circulation.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: Imminent Monitor
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- APT-C-36 · G0099 · Pinned relationship source (relationship--3f010259-666c-403b-b5c7-603b319583da)
- TA2541 · G1018 · Pinned relationship source (relationship--8fa8c5c2-4891-49a7-88a6-f0ca4387008a)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1021.001 · Remote Desktop Protocol · Detection rules & anomalies
- T1027 · Obfuscated Files or Information · Detection rules & anomalies
- T1041 · Exfiltration Over C2 Channel · Detection rules & anomalies
- T1056.001 · Keylogging · Detection rules & anomalies
- T1057 · Process Discovery · Detection rules & anomalies
- T1059 · Command and Scripting Interpreter · Detection rules & anomalies
- T1070.004 · File Deletion · Detection rules & anomalies
- T1083 · File and Directory Discovery · Detection rules & anomalies
- T1106 · Native API · Detection rules & anomalies
- T1123 · Audio Capture · Detection rules & anomalies
- T1125 · Video Capture · Detection rules & anomalies
- T1140 · Deobfuscate/Decode Files or Information · Detection rules & anomalies
- T1496.001 · Compute Hijacking · Detection rules & anomalies
- T1555.003 · Credentials from Web Browsers · Detection rules & anomalies
- T1564.001 · Hidden Files and Directories · Detection rules & anomalies
- T1685 · Disable or Modify Tools · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Cloud Service Modification · DC0069
- Command Execution · DC0064
- Container Creation · DC0072
- File Access · DC0055
- File Creation · DC0039
- File Deletion · DC0040
- File Metadata · DC0059
- File Modification · DC0061
- Firmware Modification · DC0004
- Host Status · DC0018
- Instance Start · DC0080
- Logon Session Creation · DC0067
- Logon Session Metadata · DC0088
- Module Load · DC0016
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- OS API Execution · DC0021
- Process Access · DC0035
- Process Creation · DC0032
- Process Metadata · DC0034
- Process Termination · DC0033
- Scheduled Job Creation · DC0001
- Service Creation · DC0060
- Service Metadata · DC0041
- Service Modification · DC0065
- User Account Authentication · DC0002
- Windows Registry Key Modification · DC0063
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.