Remote Monitoring and Management (RMM) Tooling Increasingly an Attacker’s First Choice

Listen to this Post

You Should Know:

Remote Monitoring and Management (RMM) tools are increasingly being exploited by threat actors for malicious purposes. These tools, which are typically used for legitimate IT management, can be abused to gain unauthorized access, execute commands, and move laterally across networks. Below are some practical steps, commands, and codes to help you defend against such threats.

1. Application Control

To mitigate the risk of RMM tool abuse, implement application control policies to block unauthorized RMM software. Here’s how you can do it on different platforms:

Windows: