Advisory

6 min read

Locking Down Remote Support Tools Before They're Abused

Remote monitoring and management (RMM) tools like ScreenConnect get abused precisely because they're supposed to be on the network. Banning them isn't practical for most businesses. Restricting what each connection can do, and watching for the few behaviors that separate a technician from an intruder, is.

These tools are on an approved list, signed by a trusted vendor, and usually exempt from the scrutiny given to unfamiliar software. An attacker who gets access to one doesn't need custom malware. They just need a session. That's what makes RMM abuse hard to catch with traditional antivirus, and why it keeps showing up in real-world intrusions.

Why RMM Tools Are a Favorite Entry Point

Three things make remote support software attractive to attackers:

  • Trust by default. Security tools are often configured to allow known RMM software rather than flag it.

  • Legitimate use as cover. A remote session at 2am can look identical to a scheduled maintenance window if no one is checking context.

  • Standing access. Many RMM deployments run with high privileges on every endpoint they touch, all the time. That's convenient for support, and equally convenient for an attacker who compromises one credential.

The takeaway: treat RMM software as a privileged access path, not just another app on the endpoint list.

How to Spot Misuse Early

You don't need a full SOC to catch the early signs. Most abuse patterns show up in a small set of behaviors. This week, check whether any of these are happening, and whether you'd even notice if they were:

  • Unfamiliar RMM software appearing at all. If your business uses one remote support tool, any other RMM binary showing up on an endpoint is a red flag, full stop.

  • Sessions outside your normal support hours or vendor list. Legitimate IT support has a rhythm. A session initiated by an account or vendor you don't recognize, at a time no one scheduled, deserves a phone call before it deserves a shrug.

  • New installs on servers rather than user devices. RMM tools are usually deployed to manage end-user machines. An install on a domain controller or database server that wasn't planned is worth investigating immediately.

  • Rapid deployment across many machines in a short window. Attackers who gain admin access often push the RMM agent to as many endpoints as possible to establish persistence. A burst of new installs is a stronger signal than any single one.

Decision rule: if you can't answer "who installed this, and why" within a few minutes of checking, treat the install as suspicious until proven otherwise.

Limit the Blast Radius With Least-Privilege

You can't always stop a stolen credential from being used. You can control what that credential is allowed to do once it's inside an RMM session.

  • Scope access to what the job needs. A technician resolving a printer issue doesn't need domain admin rights during that session. Map your RMM roles to the narrowest permission set that still lets people do their job.

  • Separate the RMM admin console from everyday user accounts. The account that manages your RMM platform should not be the same account someone uses for email. If it's phished, the blast radius shouldn't include your entire remote access fleet.

  • Require approval for new device enrollment. If any device can join your RMM tenant without a human checking, that's an open door. Turn on enrollment approval if your platform supports it.

  • Review who has standing remote access quarterly, not annually. Contractors, former employees, and old vendor relationships accumulate access that no one remembers to remove. A short quarterly review catches this before it becomes an incident.

If your current setup gives broad, always-on access "because it's easier," that's the exact configuration attackers rely on. Least-privilege access matters here: it's the difference between one compromised session and a full network breach.

Build Alerting That Actually Catches Abuse

Alerts only help if someone sees them and knows what to do. Start with a short, high-signal list rather than trying to monitor everything:

  • New RMM software installation on any server.

  • RMM session initiated from a geography or IP range you don't normally see.

  • A remote session that installs additional software or creates new user accounts.

  • Any RMM agent communicating with a domain or IP that isn't your known vendor infrastructure.

If your team doesn't have the bandwidth to watch these signals around the clock, that's a resourcing gap worth admitting rather than ignoring. A managed security arrangement exists to keep eyes on this kind of alert stream so it doesn't sit unread in a dashboard no one opens.

When It Doesn't Get Caught in Time

Even with good controls, a determined attacker with valid credentials can slip through. If you find an RMM session you can't account for, don't wait for certainty. Isolate the affected endpoint from the network first, then investigate. The cost of disconnecting a legitimate technician for ten minutes is far lower than the cost of an attacker having another hour inside your environment.

If you don't have an established process for that moment (who makes the call, who isolates the machine, who reviews the logs afterward), that's worth fixing before an incident forces the question. Our incident response service exists for exactly this: acting fast when something looks wrong, and confirming afterward what actually happened.

For general guidance on remote access risks, CISA has published advisories on the malicious use of remote monitoring and management software. Worth a read if you want the wider threat picture: cisa.gov.

What to Do This Week

Pick one action from this list and do it before Friday: audit your RMM admin accounts for separation from daily-use logins, turn on enrollment approval, or set up an alert for new RMM installs on servers. Any one of these closes a real gap.

If you're not sure where your remote access exposure actually stands, a free security review is a low-friction way to find out. No commitment, just a clear picture of what needs attention first.

Want this looked at for real?

Get a free security review and we will show you where you actually stand.