Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

RMM abuse and first-seen detections: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19663
Topic starter  

TL;DR: Remote monitoring and management abuse remains a high-volume intrusion path, according to Abstract Security’s ASTRO, with Huntress reporting a 277% increase in RMM abuse and Arctic Wolf finding RMM use in 36% of incident response cases and 59% of ransomware cases tied to remote access. The practical shift is from simply knowing which tools exist to correlating first-seen usage, prevalence, and sanctioned access so abuse becomes visible before it blends into normal operations.

NHIMG editorial — based on content published by Abstract Security: Security RMM Hunting: LOLRMM for Detections

By the numbers:

Questions worth separating out

Q: How should security teams govern approved RMM tools without losing visibility?

A: Treat approved RMM tools as governed access paths, not ordinary utilities.

Q: Why do RMM tools create so much detection noise in enterprise environments?

A: Because they are common in legitimate support work and often signed, feature rich, and network-reachable by design.

Q: What breaks when organisations rely only on tool inventories for RMM control?

A: Inventory alone tells you what exists, not whether it was introduced appropriately or used maliciously.

Practitioner guidance

  • Inventory sanctioned RMM tools by user and host Maintain a living list of approved remote access tools, mapped to the users, devices, and support functions that are permitted to run them.
  • Detect first-seen RMM usage as a lifecycle event Alert when a user or host runs an RMM tool that has not appeared before in that identity or device history.
  • Correlate RMM activity with identity and phishing signals Join RMM detections to help desk impersonation, suspicious chat activity, or unusual remote support requests within a short operational window.

What's in the full article

Abstract Security's full article covers the operational detail this post intentionally leaves for the source:

  • The LOLRMM enrichment workflow for turning raw observables into a searchable lookup table
  • The exact first-seen RMM analytics used for user and host baselining
  • Examples of correlation logic that combines RMM activity with Microsoft Teams phishing signals
  • Indicator handling guidance for file paths, registry artefacts, domains, signer metadata, and network ports

👉 Read Abstract Security’s analysis of RMM abuse detection and LOLRMM correlation →

RMM abuse and first-seen detections: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19254
 

RMM abuse is an identity governance problem as much as a detection problem. Once a remote access tool can act with administrative reach, the question becomes who authorised that reach, for which asset, and for how long. That makes the tool itself a governed access path, not a neutral utility. IAM and PAM teams should treat RMM enrolment, approval, and revocation as part of access lifecycle control, especially where support workflows touch sensitive endpoints.

A question worth separating out:

Q: Who is accountable when sanctioned RMM tools are abused for remote access?

A: Accountability should sit with the system or service owner who approved the tool, the security team that defined monitoring expectations, and the operations team that manages access scope. Remote administration software should not be treated as informal convenience tooling. If it can execute commands, it needs named ownership and reviewable controls.

👉 Read our full editorial: RMM abuse is still a detection problem, not just an inventory problem



   
ReplyQuote
Share: