Locking Down Remote Support Tools Before They're Abused
RMM tools like ScreenConnect are a top attacker entry point. Here's why, and what to do about it. Remote monitoring and management (RMM) tools like ScreenConnect get abused precisely because they're supposed to be on the network. Banning them isn't practical for most businesses. Restricting what each connection can do, and watching for the few behaviors that separate a technician from an…
Remote support tools like ScreenConnect are often targeted by attackers because they are trusted and widely used on corporate networks. These tools make it easy for attackers to gain access with a simple session, as they don't require custom malware. Traditional antivirus software is not effective in detecting RMM abuse, as the software is considered legitimate. Remote monitoring and management tools are often given broad privileges, making them attractive targets.
To spot misuse early, look for unfamiliar RMM software appearing on endpoints, sessions outside normal support hours or vendor lists, new installs on servers, and rapid deployments across many machines in a short time frame. Limit the blast radius by applying least-privilege access, separating the RMM admin console from everyday user accounts, and requiring approval for new device enrollment. Review standing remote access regularly to catch any old or unused accounts.
Build alerting to catch abuse by focusing on key signals such as new RMM installations on servers, sessions initiated from unusual geographies or IP ranges, sessions that install additional software or create new user accounts, and any communication with unknown domains or IPs. If you find an unaccounted RMM session, isolate the affected endpoint and investigate without waiting for certainty.
Implement these measures before Friday to reduce the risk of RMM abuse. Audit your RMM admin accounts to ensure they are separated from daily-use logins, turn on enrollment approval, or set up an alert for new RMM installs on servers.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.