Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
20 rules
Antivirus Remote Access Tool Signature Matches Known RAT Names
Alerts on antivirus detections referencing multiple known RAT family signature names in the event signature field.
sigmacritical2026-06-15OpenCanary RDP New Connection Attempt on Application Logtype 14001
Alerts on OpenCanary logging a new RDP connection attempt (logtype 14001), indicating remote access probing.
sigmahigh2026-01-06Windows MeshAgent Remote Access Tool Command Line Execution Indicators
Flags Windows processes invoking MeshAgent with --meshServiceName, indicating potential remote access tool execution.
sigmaWindowsmedium2025-05-19macOS Process Creation: MeshAgent renamed execution via --meshServiceName
Identifies macOS executions of MeshAgent instances that include --meshServiceName, indicating potential renamed remote access tooling.
sigmamacOShigh2025-05-19macOS Process Creation: MeshAgent Remote Access via --meshServiceName
Alerts on macOS process executions containing --meshServiceName, indicating potential MeshAgent remote access usage.
sigmamacOSmedium2025-05-19OpenCanary Telnet Login Attempt Recorded in Application Logs
Alerts on OpenCanary Telnet login attempt events to highlight potential remote access probing.
sigmahigh2024-03-08Windows SimpleService Execution via Remote Access Tool Wrapper Paths
Flags Windows processes running SimpleService.exe from remote access tool wrapper directories.
sigmaWindowsmedium2024-02-23Windows Network Connections to *.devtunnels.ms
Alerts on initiated Windows network connections to .devtunnels.ms hostnames, which may indicate remote access use.
sigmaWindowsmedium2023-11-20Windows System Service Installation of Remote Access Tool Services (Event 7045/7036)
Flags Windows service installation or updates for remote access tool services using Service Control Manager events.
sigmaWindowsmedium2022-12-23Windows Security Event 4697 Service Install of Remote Access Tools
Alerts on Windows service creation (EID 4697) where the service name matches known remote access tool indicators.
sigmaWindowsmedium2022-12-23Windows RDP Registry Settings Modified to Zero
Alerts when RDP-related registry values are set to 0, potentially weakening remote access controls.
sigmaWindowsmedium2022-09-29Windows DNS Queries to Remote Support and Remote Access Domains From Non-Browser Processes
Alert on DNS lookups for remote access service domains from non-browser executables, including RustDesk subdomains.
sigmaWindowsmedium2022-07-11Windows AnyDesk Executed from Suspicious Directory
Alerts on AnyDesk execution from non-standard folders on Windows, indicating potential remote access abuse.
sigmaWindowshigh2022-05-20Windows Process Creation: ScreenConnect Service Execution
Alerts on Windows executions identified as ScreenConnect service/product/company strings, indicating potential remote access C2 activity.
sigmaWindowsmedium2022-02-13Windows: Process creation matching GoTo Opener (LogMeIn) for remote access tooling
Alerts on Windows process execution identified as “GoTo Opener” by LogMeIn, which may indicate remote access tool use.
sigmaWindowsmedium2022-02-13Windows LogMeIn LMIGuardianSvc Execution Associated with Remote Access Tools
Flags Windows process launches identified as LogMeIn LMIGuardianSvc by Description/Product/Company attributes.
sigmaWindowsmedium2022-02-11Windows HackTool Activity: Evil-WinRM Ruby Process with -i, -u, -p Arguments
Flags Ruby processes launched with Evil-WinRM parameters (-i, -u, -p), indicative of WinRM remote access attempts.
sigmaWindowsmedium2022-01-07Windows PowerShell script enabling WinRM via Enable-PSRemoting
Alerts on PowerShell scripts that include Enable-PSRemoting, a common step to activate WinRM for remote access.
sigmaWindowsmedium2022-01-07Windows ScreenConnect Installation Execution via Remote Access Parameters
Flags Windows executions of ScreenConnect with remote access command-line parameters indicating remote session setup.
sigmaWindowsmedium2021-02-11WinRM Remote Access to LSASS via wsmprovhost.exe (Windows Process Access)
Flags remote WinRM (wsmprovhost.exe) process-access to lsass.exe, a high-risk credential-access behavior.
sigmaWindowshigh2019-05-20