Locking Down Remote Support Tools Before They're Abused
Locking Down Remote Support Tools Before They’re Abused
在远程支持工具被滥用前加强管控
RMM tools like ScreenConnect are a top attacker entry point. Here’s why, and what to do about it. Remote monitoring and management (RMM) tools like ScreenConnect get abused precisely because they’re supposed to be on the network. Banning them isn’t practical for most businesses. Restricting what each connection can do, and watching for the few behaviors that separate a technician from an intruder, is. These tools are on an approved list, signed by a trusted vendor, and usually exempt from the scrutiny given to unfamiliar software. An attacker who gets access to one doesn’t need custom malware. They just need a session. That’s what makes RMM abuse hard to catch with traditional antivirus, and why it keeps showing up in real-world intrusions. 像 ScreenConnect 这类远程监控与管理(RMM)工具是攻击者最主要的切入点。以下是原因及应对措施。RMM 工具之所以被滥用,恰恰是因为它们本就应该存在于网络中。对于大多数企业而言,禁用它们并不现实。切实可行的方法是限制每个连接的权限,并监控那些能将技术人员与入侵者区分开来的细微行为。这些工具通常在白名单内,由受信任的供应商签名,且往往免于像陌生软件那样的严格审查。攻击者一旦获得访问权限,无需定制恶意软件,只需一个会话即可。这就是为什么传统的杀毒软件难以发现 RMM 滥用,也是它在现实入侵中频频出现的原因。
Why RMM Tools Are a Favorite Entry Point
为什么 RMM 工具是攻击者的首选切入点
Three things make remote support software attractive to attackers: 远程支持软件对攻击者具有吸引力的三个原因:
- Trust by default. Security tools are often configured to allow known RMM software rather than flag it. 默认信任。 安全工具通常被配置为允许已知的 RMM 软件,而不是将其标记为威胁。
- Legitimate use as cover. A remote session at 2am can look identical to a scheduled maintenance window if no one is checking context. 以合法使用为掩护。 如果无人核实背景,凌晨两点的远程会话看起来与预定的维护窗口并无二致。
- Standing access. Many RMM deployments run with high privileges on every endpoint they touch, all the time. That’s convenient for support, and equally convenient for an attacker who compromises one credential. 常驻访问权限。 许多 RMM 部署在所触及的每个终端上始终以高权限运行。这对技术支持很方便,对窃取了凭据的攻击者来说同样方便。
The takeaway: treat RMM software as a privileged access path, not just another app on the endpoint list. 核心结论:应将 RMM 软件视为一种特权访问路径,而不仅仅是终端列表中的普通应用程序。
How to Spot Misuse Early
如何及早发现滥用行为
You don’t need a full SOC (security operations center) to catch the early signs. Most abuse patterns show up in a small set of behaviors. This week, check whether any of these are happening, and whether you’d even notice if they were: 你不需要一个完整的安全运营中心(SOC)来捕捉早期迹象。大多数滥用模式都表现为少数几种行为。本周,请检查是否发生了以下情况,以及如果发生了,你是否能察觉到:
- Unfamiliar RMM software appearing at all. If your business uses one remote support tool, any other RMM binary showing up on an endpoint is a red flag, full stop. 出现陌生的 RMM 软件。 如果你的企业只使用一种远程支持工具,那么终端上出现的任何其他 RMM 二进制文件都是明确的危险信号。
- Sessions outside your normal support hours or vendor list. Legitimate IT support has a rhythm. A session initiated by an account or vendor you don’t recognize, at a time no one scheduled, deserves a phone call before it deserves a shrug. 在正常支持时间或供应商列表之外的会话。 合法的 IT 支持是有规律的。如果会话是由你不认识的账户或供应商在未预定的时间发起的,在忽略它之前,请务必先打个电话核实。
- New installs on servers rather than user devices. RMM tools are usually deployed to manage end-user machines. An install on a domain controller or database server that wasn’t planned is worth investigating immediately. 在服务器而非用户设备上进行新安装。 RMM 工具通常用于管理终端用户机器。如果域控制器或数据库服务器上出现了计划外的安装,应立即进行调查。
- Rapid deployment across many machines in a short window. Attackers who gain admin access often push the RMM agent to as many endpoints as possible to establish persistence. A burst of new installs is a stronger signal than any single one. 短时间内在多台机器上快速部署。 获得管理员权限的攻击者通常会将 RMM 代理推送到尽可能多的终端以建立持久性。突发的大量新安装比单一安装更具警示意义。
Decision rule: if you can’t answer “who installed this, and why” within a few minutes of checking, treat the install as suspicious until proven otherwise. 决策准则:如果你在检查后的几分钟内无法回答“谁安装了这个,以及为什么安装”,请将其视为可疑安装,直到证明其合法为止。
Limit the Blast Radius With Least-Privilege
通过最小权限原则限制影响范围
You can’t always stop a stolen credential from being used. You can control what that credential is allowed to do once it’s inside an RMM session. 你无法总是阻止被盗凭据的使用,但你可以控制该凭据在 RMM 会话内被允许执行的操作。
- Scope access to what the job needs. A technician resolving a printer issue doesn’t need domain admin rights during that session. Map your RMM roles to the narrowest permission set that still lets people do their job. 将访问权限限制在工作所需范围内。 解决打印机问题的技术人员在会话期间不需要域管理员权限。请将 RMM 角色映射到能够完成工作所需的最小权限集。
- Separate the RMM admin console from everyday user accounts. The account that manages your RMM platform should not be the same account someone uses for email. If it’s phished, the blast radius shouldn’t include your entire remote access fleet. 将 RMM 管理控制台与日常用户账户分离。 管理 RMM 平台的账户不应与用于电子邮件的账户相同。如果该账户被钓鱼,影响范围不应波及整个远程访问系统。
- Require approval for new device enrollment. If any device can join your RMM tenant without a human checking, that’s an open door. Turn on enrollment approval if your platform supports it. 要求新设备注册审批。 如果任何设备无需人工审核即可加入你的 RMM 租户,那等于敞开了大门。如果你的平台支持,请开启注册审批功能。
- Review who has standing remote access quarterly, not annually. Contractors, former employees, and old vendor relationships accumulate access that no one remembers to remove. A short quarterly review catches this before it becomes an incident. 每季度(而非每年)审查常驻远程访问权限。 承包商、前员工和旧的供应商关系会积累无人清理的访问权限。短期的季度审查可以在其演变成安全事件前发现问题。
If your current setup gives broad, always-on access “because it’s easier,” that’s the exact configuration attackers rely on. Least-privilege access matters here: it’s the difference between one compromised session and a full network breach. 如果你的当前设置因为“更方便”而提供了广泛的常驻访问权限,那正是攻击者所依赖的配置。最小权限访问在此至关重要:它决定了是仅有一个会话被入侵,还是整个网络被攻破。
Build Alerting That Actually Catches Abuse
构建真正能捕捉滥用的警报
Alerts only help if someone sees them and knows what to do. Start with a short, high-signal list rather than trying to monitor everything: 警报只有在有人看到并知道如何处理时才有用。从一个简短、高价值的列表开始,而不是试图监控一切:
- New RMM software installation on any server. 任何服务器上安装了新的 RMM 软件。
- RMM session initiated from a geography or IP range you don’t normally see. 从你通常未见的地理位置或 IP 段发起的 RMM 会话。
- A remote session that installs additional software or creates new user accounts. 安装额外软件或创建新用户账户的远程会话。
- Any RMM agent communicating with a domain or IP that isn’t your known vendor infrastructure. 任何与非已知供应商基础设施的域名或 IP 通信的 RMM 代理。
If your team doesn’t have the bandwidth to watch these signals around the clock, that’s a resourcing gap worth admitting rather than ignoring. A managed security arrangement exists to keep eyes on this kind of alert stream so it doesn’t sit unread in a dashboard no one opens. 如果你的团队没有精力全天候监控这些信号,这是一个值得承认而非忽视的资源缺口。托管安全服务可以持续监控此类警报流,确保它们不会在无人问津的仪表板中被遗忘。
When It Doesn’t Get Caught in Time
当未能及时发现时
Even with good controls, a determined attacker with valid credentials can slip through. If you find an RMM session you can’t account for, don’t wait for certainty. Isolate the affected endpoint from the network first, then investigate. The cost of disconnecting a legitimate technician for ten minutes is far lower than the cost of an attacker having another hour inside your environment. 即使有良好的控制措施,拥有有效凭据的顽固攻击者仍可能潜入。如果你发现了一个无法解释的 RMM 会话,不要等待确认。先将受影响的终端从网络中隔离,然后再进行调查。让一名合法技术人员断开连接十分钟的代价,远低于攻击者在你的环境中多停留一小时的代价。
If you don’t have an established process for that moment — who makes the call, who isolates the machine, who reviews the logs afterward — that’s worth fixing before an incident forces the question. Our incident response service exists for exactly this: acting fast when something looks wrong, and confirming afterward what actually happened. 如果你还没有针对这种情况建立流程(谁来决策、谁来隔离机器、谁来事后审查日志),那么在事件发生前解决这些问题是非常值得的。我们的事件响应服务正是为此而生:在发现异常时迅速行动,并在事后确认实际发生了什么。
For general guidance on remote access risks, the Cybersecurity and Infrastructure Security Agency (CISA) has published advisories on the malicious use of remote monitoring and management software. Worth a read if you want the wider threat picture. 关于远程访问风险的一般性指导,美国网络安全与基础设施安全局(CISA)已发布了关于恶意使用远程监控与管理软件的建议。如果你想了解更广泛的威胁态势,值得一读。
What to Do This Week
本周行动建议
Pick one action from this list and do it before Friday: audit your RMM admin accounts for separation from daily-use logins, turn on enrollment approval, or set up an alert for new RMM installs on servers. 从以下列表中选择一项并在周五前完成:审计你的 RMM 管理员账户以确保其与日常登录账户分离、开启注册审批,或为服务器上的新 RMM 安装设置警报。