2026 Critical Enterprise Intrusion Chain Detection: RMM Tool Deployment Following Cloud Identity Compromise Alert

This rule detects the execution of common Remote Monitoring and Management (RMM) and remote access tools (e.g., ScreenConnect, AnyDesk, Atera, Splashtop, NinjaOne, Action1) when the command line includes silent install or installation flags. The detection correlates this activity with recent (within 72 hours) identity-related alerts (e.g., impossible travel, anomalous sign-in, credential compromise) for the same user, suggesting a potential high-risk scenario where an adversary is establishing remote access following a credential compromise.