title: Generic RMM Tool Detection
id: ba1e3a37-6751-48e8-9f7a-73d9062f137c
status: experimental
description: Detects processes associated with common Remote Monitoring and Management
  (RMM) tools that could be used for lateral movement
references:
- https://github.com/magicsword-io/LOLRMM
author: LOLRMM Project
date: '2025-03-18'
modified: '2026-10-05'
tags:
- attack.command-and-control
- attack.t1219
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    Image|endswith:
    - '*\\AppData\\Roaming\\Microsoft\\DeviceSync\\svchost.exe'
    - '*\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\svchost.exe'
    - '*\\AppData\\Roaming\\Overlord\\agent.exe'
    - \\aa_v*.exe
    - \\aadg.exe
    - \\accessserver*.exe
    - \\accessserver.exe
    - \\AcronisCyberProtectConnectAgent.exe
    - \\AcronisCyberProtectConnectQuickAssist*.exe
    - \\AEMAgent.exe
    - \\AeroAdmin.exe
    - \\agent-installer-any.exe
    - \\agent-windows-amd64-*.exe
    - \\agent32.exe
    - \\agent64.exe
    - \\Agent_*_RW.exe
    - \\agent_setup_5.exe
    - \\AgentlessRC.exe
    - \\AgentMaint.exe
    - \\AgentMonitor.exe
    - \\AgentPackageNetworkDiscovery.exe
    - \\AgentPackageTaskScheduler.exe
    - \\AgentSetup-*.exe
    - \\agentu.exe
    - \\alitask.exe
    - \\allocentra-agent.exe
    - \\AlpemixService.exe
    - \\AMMYY_Admin.exe
    - \\amon.exe
    - \\AnyDesk-*.exe
    - \\AnyDesk.exe
    - \\apc_host.exe
    - \\ArcUI.exe
    - \\aspia_client.exe
    - \\atera_agent.exe
    - \\AteraAgent.exe
    - \\auvik.agent.exe
    - \\auvik.engine.exe
    - \\aweray_remote*.exe
    - \\AweSun.exe
    - \\awhost32.exe
    - \\awrem32.exe
    - \\BASEClient.exe
    - \\BASupApp.exe
    - \\BASupAppElev.exe
    - \\BASupAppSrvc.exe
    - \\BASupSrvc.exe
    - \\BASupSrvcCnfg.exe
    - \\basupsrvcupdate.exe
    - \\BASupSysInf.exe
    - \\BASupTSHelper.exe
    - \\bbl.exe
    - \\beacon-agent.exe
    - \\beamyourscreen-host.exe
    - \\beamyourscreen.exe
    - \\Beinsync*.exe
    - \\bomgar-pac-*.exe
    - \\bomgar-pac.exe
    - \\bomgar-rdp.exe
    - \\bomgar-scc-*.exe
    - \\bomgar-scc.exe
    - \\BvSshClient-Inst.exe
    - \\BvSshServer-Inst.exe
    - \\CagService.exe
    - \\cbb.exe
    - \\CBBackupPlan.exe
    - \\client32.exe
    - \\clientmrinit.exe
    - \\Cloud.Backup.RM.Service.exe
    - \\Cloud.Backup.Scheduler.exe
    - \\cloudflared.exe
    - \\CloudRaCmd.exe
    - \\CloudRaSd.exe
    - \\CloudRaService.exe
    - \\CloudRaUtilities.exe
    - \\CloudWksInstall.exe
    - \\ComodoRemoteControl.exe
    - \\Connect.Backdrop.cloud*.exe
    - \\Connect.exe
    - \\ConnectAppSetup*.exe
    - \\ConnectDetector.exe
    - \\ConnectShellSetup*.exe
    - \\connectwise*.exe
    - \\connectwisechat-customer.exe
    - \\ConnectWiseControl*.exe
    - \\connectwisecontrol.client.exe
    - \\ControlR.Agent.exe
    - \\ControlR.DesktopClient.exe
    - \\CoreAgentService.exe
    - \\CrossLoopConnect.exe
    - \\crossloopservice.exe
    - \\csexec.exe
    - \\ctes.exe
    - \\cteshostsvc.exe
    - \\ctespersistence.exe
    - \\ctiserv.exe
    - \\DameWare Mini Remote Control*.exe
    - \\DameWare Remote Support.exe
    - \\dashboard-windows-amd64.exe
    - \\dcagentregister.exe
    - \\dcagentservice.exe
    - \\dd.exe
    - \\ddsystem.exe
    - \\DepHlp.exe
    - \\Deskroll.exe
    - \\DeskRollUA.exe
    - \\desktopnow.exe
    - \\DFC.exe
    - \\DFInst.exe
    - \\DFServ.exe
    - \\DFServEx.exe
    - \\DFStd.exe
    - \\DFStdInstall.exe
    - \\DFWks.exe
    - \\distant-desktop.exe
    - \\dntus*.exe
    - \\DocConnect.Agent.exe
    - \\Domotz Pro Desktop App Setup*.exe
    - \\Domotz Pro Desktop App.exe
    - \\domotz*.exe
    - \\domotz-windows*.exe
    - \\domotz.exe
    - \\domotz_bash.exe
    - \\DragonDisk.exe
    - \\DSGuest.exe
    - \\duet.exe
    - \\DuetDisp.exe
    - \\DuetSetup.exe
    - \\Duplicati.Server.exe
    - \\dwagent.exe
    - \\dwaglnc.exe
    - \\dwagsvc.exe
    - \\dwrcs.exe
    - \\dwrcst.exe
    - \\echoserver*.exe
    - \\ehorus standalone.exe
    - \\ehorus_agent.exe
    - \\ehorus_cmd.exe
    - \\ehorus_launcher.exe
    - \\ehorus_uit.exe
    - \\einstaller.exe
    - \\era.exe
    - \\ERAAgent.exe
    - \\eratool.exe
    - \\ericomconnectconfigurationtool.exe
    - \\EricomConnectRemoteHost*.exe
    - \\ExtraPuTTY-0.30-2016-01-28-installer.exe
    - \\ezhelp*.exe
    - \\ezhelpclient.exe
    - \\ezhelpclientmanager.exe
    - \\ezHelpManager.exe
    - \\FaronicsCoreAgent.exe
    - \\FaronicsDeployAgent.exe
    - \\FaronicsSA.exe
    - \\fastclient.exe
    - \\fastmaster.exe
    - \\FastViewer.exe
    - \\FIStudentAgent.exe
    - \\FIStudentSvc.exe
    - \\FIStudentUI.exe
    - \\FixMeit Client.exe
    - \\FixMeit Expert Setup.exe
    - \\FixMeit Unattended Access Setup.exe
    - \\FixMeitClient*.exe
    - \\fixmeitclient.exe
    - \\fleetdeck-agent.exe
    - \\fleetdeck_agent.exe
    - \\fleetdeck_agent_svc.exe
    - \\fleetdeck_commander_launcher.exe
    - \\fleetdeck_commander_svc.exe
    - \\fleetdeck_installer.exe
    - \\FRCServer.exe
    - \\Freshservice.DiscoveryProbe.ScanService.exe
    - \\Freshservice.DiscoveryProbe.Window.exe
    - \\FSAgentAutoUpdate.exe
    - \\FSAgentService.exe
    - \\FSSInstaller.exe
    - \\FSWmiScanner.exe
    - \\FWA_UI_Agent.exe
    - \\FWAService.exe
    - \\FWAWebInstaller_*.exe
    - \\g2a*.exe
    - \\g2ax_comm_customer.exe
    - \\G2M.exe
    - \\g2mcomm.exe
    - \\getscreen-x86.exe
    - \\getscreen.upd.exe
    - \\GoTo Assist Opener.exe
    - \\goto opener.exe
    - \\gotoassist.exe
    - \\GotoHTTP*.exe
    - \\gotohttp.exe
    - \\GotoHTTP_x64.exe
    - \\GoToResolveExternalModuleHandler.exe
    - \\GoToResolveFileManager.exe
    - \\GoToResolveLoggerProcess.exe
    - \\GoToResolveNetworkChecker.exe
    - \\GoToResolveProcessChecker.exe
    - \\GoToResolveQuickView.exe
    - \\GoToResolveRegistryEditor.exe
    - \\GoToResolveRemoteControl.exe
    - \\GoToResolveService.exe
    - \\GoToResolveServiceManager.exe
    - \\GoToResolveTerminal.exe
    - \\GoToResolveTools32.exe
    - \\GoToResolveTools64.exe
    - \\GoToResolveUi.exe
    - \\GoToResolveUnattended.exe
    - \\GoToResolveUnattendedRemover.exe
    - \\GoToResolveUnattendedUi.exe
    - \\GovAgentInstallHelper.exe
    - \\GovAgentx64.exe
    - \\goverrmc.exe
    - \\GovReachClient.exe
    - \\govsrv*.exe
    - \\GovSrv.exe
    - \\gp3.exe
    - \\gp4.exe
    - \\gp5.exe
    - \\guacd.exe
    - \\GxM.Agent.exe
    - \\hbrm-updater-x64.exe
    - \\hbrm-x64.exe
    - \\helpbeam*.exe
    - \\helpu_install.exe
    - \\HelpuManager.exe
    - \\HelpuUpdater.exe
    - \\HelpWire Quick.exe
    - \\helpwire.exe
    - \\HopToDesk-Standalone.exe
    - \\HopToDesk.exe
    - \\hsloader.exe
    - \\I'm InTouch Go Installer.exe
    - \\iadmin.exe
    - \\id_tray.exe
    - \\IDriveEClassic.exe
    - \\IDriveWinSetup.exe
    - \\ihcserver.exe
    - \\iit.exe
    - \\IliAS.exe
    - \\ImmyAgent.exe
    - \\ImmyBot.Agent.Ephemeral.exe
    - \\ImmyUpdater.exe
    - \\ImperoClientSVC.exe
    - \\ImperoInit.exe
    - \\InsightInstaller.exe
    - \\InsightInstallerStudent.exe
    - \\InsightInstallerTeacher.exe
    - \\InstallCore.exe
    - \\InstallShield Setup.exe
    - \\InstantHousecall.exe
    - \\Insync.exe
    - \\intelliadmin.exe
    - \\intouch.exe
    - \\InvGate-ED.exe
    - \\InvGateAssetsRD.exe
    - \\InvGateRD.exe
    - \\iperius.exe
    - \\iperiusremote.exe
    - \\ir_agent.exe
    - \\islalwaysonmonitor.exe
    - \\ISLLight.exe
    - \\ISLLightClient.exe
    - \\isllightservice.exe
    - \\issuser.exe
    - \\ITAgentRMMSender.exe
    - \\ITAgentRMMSenderSL.exe
    - \\ITAgentRMMSenderUpdater.exe
    - \\ITarianRemoteAccessSetup.exe
    - \\ITSMAgent.exe
    - \\ItsmRsp.exe
    - \\ITSMService.exe
    - \\IvantiRemoteControl.exe
    - \\jumpclient.exe
    - \\JumpCloud*.exe
    - \\jumpconnect.exe
    - \\jumpdesktop.exe
    - \\jumpservice.exe
    - \\jumpupdater.exe
    - \\Kabuto.App.Runner.exe
    - \\Kabuto.Installer.exe
    - \\Kabuto.Service.Runner.exe
    - \\KabutoSetup.exe
    - \\KHelpDesk.exe
    - \\kitty.exe
    - \\konea.exe
    - \\landeskagentbootstrap.exe
    - \\LANDeskPortalManager.exe
    - \\laplink-everywhere-setup*.exe
    - \\laplink.exe
    - \\laplinkeverywhere.exe
    - \\LavawallWin.exe
    - \\ldinv32.exe
    - \\ldsensors.exe
    - \\level-remote-control-ffmpeg.exe
    - \\level-windows-amd64.exe
    - \\level.exe
    - \\llrcservice.exe
    - \\lmi_rescue.exe
    - \\lmi_rescue_srv.exe
    - \\LMNoIpServer.exe
    - \\loclx.exe
    - \\LS RMM Worker.exe
    - \\LS RMM.exe
    - \\ltsvc.exe
    - \\ltsvcmon.exe
    - \\lttray.exe
    - \\Lunixar.exe
    - \\LunixarRemote.exe
    - \\LunixarUpdater.exe
    - \\ManageEngine_Remote_Access_Plus.exe
    - \\ManageEngine_ServiceDesk_Plus.exe
    - \\ManualLauncher.exe
    - \\MEAgentHelper.exe
    - \\MEGAsyncSetup64.exe
    - \\MEGAupdater.exe
    - \\meshagent*.exe
    - \\meshcentral*.exe
    - \\mgntsvc.exe
    - \\MigrationHelper_32.exe
    - \\MigrationHelper_64.exe
    - \\Mikogo-Screen-Service.exe
    - \\Mikogo-Service.exe
    - \\mikogo-starter.exe
    - \\mikogo.exe
    - \\mikogolauncher.exe
    - \\MiniRmmAgent.exe
    - \\mionet.exe
    - \\mionetmanager.exe
    - \\ModulesUpgradeMgr.exe
    - \\MonitoringAgent.exe
    - \\mRemoteNG.exe
    - \\msp-agent-core.exe
    - \\mstsc.exe
    - \\mwcliun.exe
    - \\mygreenpc.exe
    - \\myivomanager.exe
    - \\myivomgr.exe
    - \\nateon*.exe
    - \\nateon.exe
    - \\nateonmain.exe
    - \\netbird-ui.exe
    - \\netbird.exe
    - \\NetLock_RMM_Agent_Installer.exe
    - \\NetLock_RMM_User_Process.exe
    - \\NetLock_RMM_User_UAC.exe
    - \\NetMaster_Client.exe
    - \\Netop Ondemand.exe
    - \\neturo*.exe
    - \\neturo.exe
    - \\netviewer*.exe
    - \\NetViewer.exe
    - \\nexusrmm.exe
    - \\nezha-agent.exe
    - \\ngrok.exe
    - \\ngstw32.exe
    - \\nhostsvc.exe
    - \\nhstw32.exe
    - \\Ninite.exe
    - \\NiniteAgent.exe
    - \\NiniteOne.exe
    - \\NinitePro.exe
    - \\ninjarmm-cli.exe
    - \\NinjaRMMAgent.exe
    - \\NinjaRMMAgentPatcher.exe
    - \\nldrw32.exe
    - \\nmep_agtconfig.exe
    - \\nmep_ctrlagent.exe
    - \\nmep_ctrlagentsvc.exe
    - \\nomachine*.exe
    - \\NotificationHelper.exe
    - \\ntrntservice.exe
    - \\NTRsupportPro_EN.exe
    - \\nvClient.exe
    - \\nvConsole.exe
    - \\nvda.exe
    - \\nvda_*.exe
    - \\nvda_service.exe
    - \\nxd.exe
    - \\nxplayer.exe
    - \\nxservice*.exe
    - \\obliance-agent.exe
    - \\obliance-tray.exe
    - \\obliance-watchdog.exe
    - \\ocsinventory.exe
    - \\ocsservice.exe
    - \\onionshare*.exe
    - \\Online Backup.exe
    - \\oolocker.exe
    - \\OOSysAgent.exe
    - \\oosyspectr.exe
    - \\opale-agent.exe
    - \\OpenDesk-RMM-Agent.exe
    - \\OpsBridgeAgent.exe
    - \\OrayRemoteService.exe
    - \\OrayRemoteShell.exe
    - \\OTPowerShell.exe
    - \\OTService.exe
    - \\ovd_*.exe
    - \\p9agent*.exe
    - \\PAExec-*.exe
    - \\paexec.exe
    - \\parallelsaccess-*.exe
    - \\parsecd.exe
    - \\pcaquickconnect.exe
    - \\PcHelpWare_viewer.exe
    - \\pcicfgui.exe
    - \\pcictlui.exe
    - \\PCIVIDEO.EXE
    - \\PCMonitorManager.exe
    - \\pcmonitorsrv.exe
    - \\pcnmgr.exe
    - \\pcstarter.exe
    - \\pcvisit-easysupport.exe
    - \\pcvisit.exe
    - \\pcvisit_client.exe
    - \\pcvisit_service_client.exe
    - \\pdq-connect*.exe
    - \\Pilixo_Installer*.exe
    - \\PixoIT-agent.exe
    - \\plink.exe
    - \\pocketcloud*.exe
    - \\pocketcloudservice.exe
    - \\pocketcontroller.exe
    - \\prl_deskctl_agent.exe
    - \\prl_deskctl_wizard.exe
    - \\prl_pm_service.exe
    - \\proxiport.exe
    - \\pservice.exe
    - \\psexec.exe
    - \\psexec64.exe
    - \\psexecsvc.exe
    - \\pstlaunch.exe
    - \\ptdskclient.exe
    - \\ptdskhost.exe
    - \\putty.exe
    - \\puttytray.exe
    - \\qq.exe
    - \\qqpcmgr.exe
    - \\QQProtect.exe
    - \\quickassist.exe
    - \\raautoup.exe
    - \\RAccess.exe
    - \\Radmin.exe
    - \\rapid7_agent_core.exe
    - \\rapid7_endpoint_broker.exe
    - \\rcengmgru.exe
    - \\rcmgrsvc.exe
    - \\rcstartsupport.exe
    - \\rd.exe
    - \\rdclient.exe
    - \\RdClientInstaller.exe
    - \\RDCMan-x86.exe
    - \\RDCMan.exe
    - \\RDConsole.exe
    - \\RDesktop.exe
    - \\rdp.exe
    - \\rdp2tcp.exe
    - \\RDPCheck.exe
    - \\RDPConf.exe
    - \\RDPWInst.exe
    - \\remcmdstub.exe
    - \\remcom.exe
    - \\remcomsvc.exe
    - \\remcos*.exe
    - \\remmon.exe
    - \\remobo.exe
    - \\remobo_client.exe
    - \\remobo_tracker.exe
    - \\remote access.exe
    - \\Remote Desktop.exe
    - \\Remote Workforce Client.exe
    - \\remote-it-installer.exe
    - \\remote.it.exe
    - \\RemoteAgentAgent.exe
    - \\remoteconsole.exe
    - \\RemoteDesktopManager.exe
    - \\remoteit.exe
    - \\Remotely_Agent.exe
    - \\Remotely_Desktop.exe
    - \\remotepass-access.exe
    - \\RemotePC.exe
    - \\remotepchost.exe
    - \\RemotePCService.exe
    - \\RemoteRipple.exe
    - \\remotesupportplayeru.exe
    - \\remoteview.exe
    - \\remoting_host.exe
    - \\RemSupp.exe
    - \\rfusclient.exe
    - \\RHost.exe
    - \\RMM.Agent.exe
    - \\RMMmaxAgentService.exe
    - \\RMMmaxAgentSetup.exe
    - \\RmmService.exe
    - \\rmserverconsolemediator.exe
    - \\RocketRemoteDesktop_Setup.exe
    - \\RodexAgent.exe
    - \\ROMFUSClient.exe
    - \\ROMServer.exe
    - \\romviewer.exe
    - \\routernt.exe
    - \\royalserver.exe
    - \\royalts.exe
    - \\rpaccess.exe
    - \\rpcld.exe
    - \\rpcnet.exe
    - \\rpcsuite.exe
    - \\rport.exe
    - \\rpwhostscr.exe
    - \\rserver3.exe
    - \\rudesktop*.exe
    - \\rustdesk*.exe
    - \\RustDesk.exe
    - \\rutserv.exe
    - \\rutview.exe
    - \\rv.exe
    - \\rvagent.exe
    - \\rvagtray.exe
    - \\RViewer.exe
    - \\rxstartsupport.exe
    - \\s3browser*.exe
    - \\saazapsc.exe
    - \\screenconnect*.exe
    - \\ScreenConnect.ClientService.exe
    - \\ScreenConnect.WindowsClient.exe
    - \\ScreenMeet.Support.exe
    - \\ScreenMeetSupport.exe
    - \\SecureCRT.EXE
    - \\seetrolcenter.exe
    - \\seetrolclient.exe
    - \\seetrolmyservice.exe
    - \\seetrolremote.exe
    - \\seetrolsetting.exe
    - \\SensoClient.exe
    - \\SensoService.exe
    - \\sentinel-agent.exe
    - \\servereye*.exe
    - \\serverproxyservice.exe
    - \\ServiceProxyLocalSys.exe
    - \\SetMe_Client.exe
    - \\showmypc*.exe
    - \\showmypc.exe
    - \\si.exe
    - \\simplegatewayservice.exe
    - \\simplehelpcustomer.exe
    - \\simpleservice.exe
    - \\Site24x7PluginAgent.exe
    - \\Site24x7WindowsAgentTrayIcon.exe
    - \\SmarTTY.exe
    - \\SMPCSetup.exe
    - \\softmon.exe
    - \\Solar-PuTTY.exe
    - \\SolarWinds-Dameware-DRS*.exe
    - \\SolarWinds-Dameware-MRC*.exe
    - \\Sorillus Launcher.exe
    - \\Sorillus-Launcher*.exe
    - \\Splashtop_Streamer_Windows*.exe
    - \\SplashtopSOS.exe
    - \\spsrv.exe
    - \\sragent.exe
    - \\SRManager.exe
    - \\SRServer.exe
    - \\srservice.exe
    - \\STAHelper.exe
    - \\strwinclt.exe
    - \\StudentSvc.exe
    - \\sunlogin*.exe
    - \\superops.exe
    - \\superopsticket.exe
    - \\superputty.exe
    - \\support-logmeinrescue*.exe
    - \\support-logmeinrescue.exe
    - \\SupportTool.exe
    - \\supremo.exe
    - \\supremohelper.exe
    - \\supremoservice.exe
    - \\SupremoSystem.exe
    - \\svchost-windows-amd64-*.exe
    - \\Syncro.App.Runner.exe
    - \\Syncro.Installer.exe
    - \\Syncro.Overmind.Service.exe
    - \\Syncro.Service.exe
    - \\SyncroLive.Agent.exe
    - \\SyncroLive.Service.exe
    - \\syncrosetup.exe
    - \\Syncthing.exe
    - \\sysdiag.exe
    - \\syspectr.exe
    - \\tacticalrmm.exe
    - \\tailscale-*.exe
    - \\tailscale-ipn.exe
    - \\tailscaled.exe
    - \\TakeControl.exe
    - \\TaniumClient.exe
    - \\TaniumCX.exe
    - \\TaniumExecWrapper.exe
    - \\TaniumFileInfo.exe
    - \\TeamTaskManager.exe
    - \\teamviewer_desktop.exe
    - \\teamviewer_service.exe
    - \\Teleport Connect Setup-*.exe
    - \\TiAgent.exe
    - \\TiClientCore.exe
    - \\TiClientHelper*.exe
    - \\TiExpertCore.exe
    - \\TiExpertStandalone.exe
    - \\tigervnc*.exe
    - \\TightVNCViewerPortable*.exe
    - \\tinUnattendedModule.exe
    - \\TiService.exe
    - \\TiUpdateService.exe
    - \\tmagentsvc.exe
    - \\tmcsvc.exe
    - \\tniwinagent.exe
    - \\todesk.exe
    - \\ToDesk_Service.exe
    - \\ToDesk_Setup.exe
    - \\toolsiq.exe
    - \\topiad.exe
    - \\TPowerShell.exe
    - \\TrustConnectAgent.exe
    - \\TSClient.exe
    - \\Tsdservice.exe
    - \\tsircusr.exe
    - \\turbomeeting.exe
    - \\turbomeetingstarter.exe
    - \\tvnserver.exe
    - \\tvnviewer.exe
    - \\ultimate_*.exe
    - \\ultraviewer.exe
    - \\UltraViewer_Desktop.exe
    - \\UltraViewer_Service.exe
    - \\UltraVNC*.exe
    - \\Uninstall RemSupp.exe
    - \\UniRMM.exe
    - \\UserNotificationHelper.exe
    - \\UVNC_Launch.exe
    - \\veyon-master.exe
    - \\veyon-server.exe
    - \\veyon-service.exe
    - \\veyon-wcli.exe
    - \\veyon-worker.exe
    - \\vhost.exe
    - \\vncserver.exe
    - \\vncserverui.exe
    - \\vncviewer.exe
    - \\webexpcnow.exe
    - \\webrdp.exe
    - \\wec_launcher_[a-Z0-9]*_.exe
    - \\weCliboardListener.exe
    - \\weezo setup*.exe
    - \\weezo.exe
    - \\weezohttpd.exe
    - \\weInstSvc.exe
    - \\wemonc.exe
    - \\weprtct.exe
    - \\wesvc.exe
    - \\winagent.exe
    - \\winaw32.exe
    - \\windowslauncher.exe
    - \\winpty-agent.exe
    - \\winpty-agent64.exe
    - \\WinSCP.exe
    - \\winvnc*.exe
    - \\winvnc.exe
    - \\winvnc4.exe
    - \\winvncsc.exe
    - \\WinVNCStub.exe
    - \\winwvc.exe
    - \\wisshell*.exe
    - \\wmc.exe
    - \\wmc_deployer.exe
    - \\wmcsvc.exe
    - \\wysebrowser.exe
    - \\xcmd.exe
    - \\xcmdsvc.exe
    - \\xeox-agent_*.exe
    - \\xeox-agent_x64.exe
    - \\xeox-agent_x86.exe
    - \\xeox_service_windows.exe
    - \\Xpra-Launcher.exe
    - \\Xpra-x86_64_Setup.exe
    - \\xShell.exe
    - \\XSightService.exe
    - \\YandexDisk2.exe
    - \\ZA_Access.exe
    - \\za_connect.exe
    - \\zabbix_agent*.exe
    - \\zaservice.exe
    - \\ZecuritAgentAssetMgr.exe
    - \\ZecuritAgentRegister.exe
    - \\ZecuritAgentService.exe
    - \\ZecuritAgentTray.exe
    - \\ZecuritAgentUpgrader.exe
    - \\ZecuritApplicationControlService.exe
    - \\ZecuritCommandProcessor.exe
    - \\ZecuritLiveNotifier.exe
    - \\ZecuritRemoteTools.exe
    - \\ZecuritScreenReaderApp.exe
    - \\ZecuritScreenReaderAppUI.exe
    - \\ZecuritScreenReaderService.exe
    - \\zero-powershell.exe
    - \\zerotier*.exe
    - \\ZMAgent.exe
    - \\zoc.exe
    - \\ZohoMeeting.exe
    - \\zohotray.exe
    - \\Zohours.exe
    - \\ZohoURSService.exe
    - C:\\Program Files (x86)\\N-able Technologies\\Windows Agent\\bin\\agent.exe
    - C:\\Program Files\\Monitic\\agent.exe
    - C:\\Users\\*\\AppData\\Local\\remsupp-updater\\installer.exe
  condition: selection
falsepositives:
- Legitimate usage of remote management tools
level: medium
