T1133 External Remote Services — ATT&CK Technique
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally. Access to Valid Accounts to use the service is often a requirement, which could be obtained through credential pharming or by obtaining the credentials from users after compromising the enterprise network. Access to remote services may be used as a redundant or persistent access mechanism during an operation. Access may also be gained through an exposed service that doesn’t require authentication. In containerized environments, this may include an exposed Docker API, Kubernetes API server, kubelet, or web application such as the Kubernetes dashboard. Adversaries may also establish persistence on network by configuring a Tor hidden service on a compromised system. Adversaries may utilize the tool `ShadowLink` to facilitate the installation and configuration of the Tor hidden service. Tor hidden service is then accessible via the Tor network because `ShadowLink` sets up a .onion address on the compromised system. `ShadowLink` may be used to forward any inbound connections to RDP, allowing the adversaries to have remote access. Adversaries may get `ShadowLink` to persist on a system by masquerading it as an MS Defender application.
Detection coverage (50)
- Remote Access Tool - Team Viewer Session Started On Linux Host low
- Potential Exploitation of GoAnywhere MFT Vulnerability high
- OpenCanary - RDP New Connection Attempt high
- OpenCanary - SSH Login Attempt high
- OpenCanary - SSH New Connection Attempt high
- OpenCanary - Telnet Login Attempt high
- FortiGate - VPN SSL Settings Modified medium
- Remote Access Tool - Team Viewer Session Started On MacOS Host low
- FortiGate - New VPN SSL Web Portal Added medium
- Failed Logon From Public IP medium
- External Remote SMB Logon from Public IP high
- External Remote RDP Logon from Public IP medium
- Unusual File Modification by dns.exe high
- Unusual File Deletion by Dns.exe high
- Suspicious File Created by ArcSOC.exe high
- Remote Access Tool - ScreenConnect Installation Execution medium
- Unusual Child Process of dns.exe high
- Remote Access Tool - Team Viewer Session Started On Windows Host low
- User Added to Remote Desktop Users Group high
- Running Chrome VPN Extensions via the Registry 2 VPN Extension high
- Detect Exchange Web Shell
- Exchange PowerShell Abuse via SSRF
- Java Writing JSP File
- Living Off The Land Detection
- Log4Shell CVE-2021-44228 Exploitation
- MS Exchange Mailbox Replication service writing Active Server Pages
- Outbound Network Connection from Java Using Default Ports
- PaperCut NG Suspicious Behavior Debug Log
- Web or Application Server Spawning a Shell
- Windows MOVEit Transfer Writing ASPX
- Windows PaperCut NG Spawn Shell
- Windows RDPClient Connection Sequence Events
- Cisco Network Interface Modifications
- F5 BIG-IP iControl REST Vulnerability CVE-2022-1388
- Exploit Public-Facing Fortinet FortiNAC CVE-2022-39952
- Confluence Unauthenticated Remote Code Execution CVE-2022-26134
- Detect attackers scanning for vulnerable JBoss servers
- Ivanti EPMM Remote Unauthenticated API Access CVE-2023-35082
- Exploit Public Facing Application via Apache Commons Text
- Hunting for Log4Shell
- Fortinet Appliance Auth bypass
- Ivanti EPMM Remote Unauthenticated API Access CVE-2023-35078
- Log4Shell JNDI Payload Injection with Outbound Connection
- ProxyShell ProxyNotShell Behavior Detected
- Log4Shell JNDI Payload Injection Attempt
- PaperCut NG Remote Web Access Attempt
- Supernova Webshell
- Spring4Shell Payload URL Request
- VMWare Aria Operations Exploit Attempt
- Web JSP Request via URL