Remote Monitoring and Management (RMM) Software Usage Detected
This rule detects the execution of known Remote Monitoring and Management (RMM) tools across the environment. RMM tools are frequently used by IT administrators for legitimate support, but are also commonly abused by threat actors to establish persistence and gain remote access to systems. The rule tracks the first instance of these processes appearing on any device within a 30-day window.
Microsoft Sentinel (KQL)

