RMM Tool Installation via PowerShell - Unauthorized Remote Access

Detects the execution of known Remote Monitoring and Management (RMM) agent installers or binaries via PowerShell. This activity may indicate an attempt to establish unauthorized remote access to a system, a common technique used by threat actors to maintain persistence or conduct post-compromise activities.