Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

RMM abuse: are your detections keeping up with attacker tradecraft?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: Noisy remote monitoring and management tooling is difficult to detect because the same software has legitimate and malicious uses, according to Expel, so it built five new detections to improve context, cut false positives, and flag suspicious combinations such as multiple RMMs on one host. The real lesson is that detection quality now depends on correlation and environment-specific baselines, not simple allowlists.

NHIMG editorial — based on content published by Expel: LLMjacking: How Attackers Hijack AI Using Compromised NHIs

By the numbers:

  • This alone has closed 80% of alerts, making the remaining volume manageable for the SOC.

Questions worth separating out

Q: What breaks when remote monitoring and management tools are not baselined properly?

A: Teams lose the ability to tell legitimate support activity from attacker-controlled remote access.

Q: Why do attackers use multiple RMM tools on the same host?

A: They are testing which tool can bypass controls or survive blocking.

Q: How can security teams tell whether RMM detections are actually working?

A: Look for fewer noisy alerts, higher-confidence escalations, and faster analyst decisions on suspicious remote access events.

Practitioner guidance

  • Build an RMM allowlist by business context Classify approved remote administration tools by host group, support team, and use case, then flag any RMM that appears outside its normal environment.
  • Correlate process and network signals before escalating Combine source-process alerts, outbound connections to RMM domains, and multi-tool presence on the same host to raise confidence.
  • Review non-standard port usage as an evasion indicator Treat RMMs running over unusual ports as a higher-risk signal because legitimate administrators rarely change that configuration.

What's in the full article

Expel's full article covers the operational detail this post intentionally leaves for the source:

  • The exact five-detection logic used to distinguish benign from suspicious RMM activity across process, host, and network signals.
  • Examples of how alert context changed severity and helped analysts triage a customer pen-testing scenario.
  • The threshold logic behind auto-closing high-frequency alerts and why that reduced SOC noise.
  • How Expel uses weekly review cycles to iterate on detection quality and tune suppression decisions.

👉 Read Expel's analysis of malicious RMM detection and alert context →

RMM abuse: are your detections keeping up with attacker tradecraft?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

Dual-use administration tooling creates a governance gap, not just a detection gap. RMM abuse succeeds because defenders often classify tools by legitimacy rather than by session intent, host rarity, and privilege context. That means an attacker can hide inside an approved technology category while still exercising interactive control. Practitioners should treat RMM visibility as part of privileged access governance, not only endpoint monitoring.

A question worth separating out:

Q: Who is accountable when sanctioned RMM tools are abused for remote access?

A: Accountability should sit with the system or service owner who approved the tool, the security team that defined monitoring expectations, and the operations team that manages access scope. Remote administration software should not be treated as informal convenience tooling. If it can execute commands, it needs named ownership and reviewable controls.

👉 Read our full editorial: Malicious RMM detection is shifting from noise to contextual triage



   
ReplyQuote
Share: