• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    NetSupport Manager Multi-Mechanism Persistence Installation

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 23 days ago•0•0•2

    This rule detects various persistence mechanisms associated with the NetSupport Manager remote access tool. It monitors for the creation of services, scheduled tasks, registry modifications (such as Run keys, Winlogon Notify packages, and keyboard filter drivers), and process executions related to NetSupport Manager (specifically client32.exe).

    YARA-L

    Tags

    T1547.001 - Registry Run Keys / Startup FolderT1547.004 - Winlogon Helper DLLT1053.005 - Scheduled TaskT1543.003 - Windows ServiceTA0003 - PersistenceTA0002 - ExecutionProcess CreationRegistry Value SetService CreatedScheduled Task CreatedWindowsWindows Eventlog SecurityWindows Eventlog SystemWindows Task Scheduler Service

    Found in

    • Google Doc Sidebar Delivers Cross-Platform Stealer MalwareLast updated 23 days ago
    • Google Doc Sidebar Delivers Cross-Platform Stealer MalwareLast updated 23 days ago
    • Google Doc Sidebar Delivers Cross-Platform Stealer MalwareLast updated 23 days ago
    • Google Doc Sidebar Delivers Cross-Platform Stealer MalwareLast updated 23 days ago
    • Google Doc Sidebar Delivers Cross-Platform Stealer MalwareLast updated 23 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?