Malicious RMM Tool Deployment via Scripting Engine Parents
Detects the execution of Remote Monitoring and Management (RMM) software initiated by common Windows script interpreters. This pattern is indicative of unauthorized deployment of remote access tools, often used by adversaries to establish persistence and command-and-control channels following initial compromise.
SentinelOne

