Ransomware Deployment Following RMM Tool Installation via Social Engineering

Detects the execution of known remote monitoring and management (RMM) software often abused by threat actors following social engineering attempts, such as helpdesk impersonation, to establish persistence and remote access prior to deploying ransomware.