{
  "Name": "Access Remote PC",
  "Category": "RMM",
  "Description": "Access Remote PC is a remote monitoring and management (RMM) tool. More information will be added as it becomes available.",
  "Author": "",
  "Created": "2024-08-02",
  "LastModified": "2024-08-02",
  "Details": {
    "Website": "https://www.remotedesktop.com/",
    "PEMetadata": {
      "Filename": null,
      "OriginalFileName": null,
      "Description": null
    },
    "Privileges": null,
    "Free": true,
    "Verification": true,
    "SupportedOS": [
      "Windows",
      "Mac",
      "Linux",
      "Android",
      "iOS"
    ],
    "Capabilities": [],
    "Vulnerabilities": [],
    "InstallationPaths": [
      "C:\\Program Files (x86)\\RemotePC\\*"
    ]
  },
  "Artifacts": {
    "Disk": [
      {
        "File": "C:\\Program Files (x86)\\RemotePC\\RemotePCUIU.exe",
        "Description": "RemotePC service binary",
        "OS": "Windows"
      },
      {
        "File": "C:\\Program Files (x86)\\RemotePC\\*",
        "Description": "Multiple files and binaries related to RemotePC installation",
        "OS": "Windows"
      }
    ],
    "EventLog": [
      {
        "EventID": 7045,
        "ProviderName": "Service Control Manager",
        "LogFile": "System.evtx",
        "ServiceName": "RemotePC Performance Service",
        "ImagePath": "\"C:\\\\Program Files (x86)\\\\RemotePC\\\\RemotePCPerformance\\\\RPCPerformanceService.exe\"",
        "Description": "Service installation event as result of RemotePC installation."
      },
      {
        "EventID": 4688,
        "ProviderName": "Microsoft-Security-Auditing",
        "LogFile": "Security.evtx",
        "CommandLine": "sc  create RPCService start=auto binpath=\"C:\\\\Program Files (x86)\\\\RemotePC\\\\RemotePCService.exe\"",
        "Description": "Executing command to install RemotePC service."
      },
      {
        "EventID": 4688,
        "ProviderName": "Microsoft-Security-Auditing",
        "LogFile": "Security.evtx",
        "CommandLine": "C:\\\\Windows\\\\system32\\\\schtasks /create /SC DAILY /st 12:00 /TN \"RPCPerformanceHealthCheck\" /TR \"C:\\\\Program Files (x86)\\\\RemotePC\\\\RemotePCPerformance\\\\RPCPerformanceDownloader.exe\" /rl HIGHEST /ru system",
        "Description": "Executing command to create RemotePC HealthCheck scheduled task."
      },
      {
        "EventID": 4688,
        "ProviderName": "Microsoft-Security-Auditing",
        "LogFile": "Security.evtx",
        "CommandLine": "C:\\Windows\\regedit.exe /s C:\\Program Files (x86)\\RemotePC\\Register.reg",
        "Description": "Executing command to install various registry changes related to RemotePC."
      },
      {
        "EventID": 4688,
        "ProviderName": "Microsoft-Security-Auditing",
        "LogFile": "Security.evtx",
        "CommandLine": "netsh  advfirewall firewall add rule name=\"RemotePCDesktop\" enable=yes dir=in action=allow profile=any program=\"C:\\Program Files (x86)\\RemotePC\\RemotePCDesktop.exe\" description=\"This program is used for File Transfer and is part of RemotePC product.\"",
        "Description": "Executing command to add local firewall rule to allow inbound traffic for RemotePC."
      }
    ],
    "Registry": [],
    "Network": []
  },
  "Detections": [
    {
      "Sigma": "https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/access_remote_pc_files_sigma.yml",
      "Description": "Detects potential files activity of Access Remote PC RMM tool"
    }
  ],
  "References": [],
  "Acknowledgement": [
    {
      "Person": "Daniel Koifman",
      "Handle": "@koifsec"
    }
  ]
}