RMM
Access Remote PC
Access Remote PC is a remote monitoring and management (RMM) tool. More information will be added as it becomes available.
Tool overview
- Category
- RMM
- Research authors
- Not recorded
- Created
- 2024-08-02
- Last modified
- 2024-08-02
- Privileges
- Not recorded
- Free / availability
- Yes
- Verification required
- Yes
- Supported platforms
Android
Linux
Windows
iOS
macOS
Executables & installation paths
- Filename
- Not recorded
- OriginalFileName
- Not recorded
- Description
- Not recorded
Installation paths
C:\Program Files (x86)\RemotePC\*
FORENSIC EVIDENCE
Disk artifacts
- File
- C:\Program Files (x86)\RemotePC\RemotePCUIU.exe
- Description
- RemotePC service binary
- OS
- Windows
- File
- C:\Program Files (x86)\RemotePC\*
- Description
- Multiple files and binaries related to RemotePC installation
- OS
- Windows
FORENSIC EVIDENCE
Event log artifacts
- EventID
- 7045
- ProviderName
- Service Control Manager
- LogFile
- System.evtx
- ServiceName
- RemotePC Performance Service
- ImagePath
- "C:\\Program Files (x86)\\RemotePC\\RemotePCPerformance\\RPCPerformanceService.exe"
- Description
- Service installation event as result of RemotePC installation.
- EventID
- 4688
- ProviderName
- Microsoft-Security-Auditing
- LogFile
- Security.evtx
- CommandLine
- sc create RPCService start=auto binpath="C:\\Program Files (x86)\\RemotePC\\RemotePCService.exe"
- Description
- Executing command to install RemotePC service.
- EventID
- 4688
- ProviderName
- Microsoft-Security-Auditing
- LogFile
- Security.evtx
- CommandLine
- C:\\Windows\\system32\\schtasks /create /SC DAILY /st 12:00 /TN "RPCPerformanceHealthCheck" /TR "C:\\Program Files (x86)\\RemotePC\\RemotePCPerformance\\RPCPerformanceDownloader.exe" /rl HIGHEST /ru system
- Description
- Executing command to create RemotePC HealthCheck scheduled task.
- EventID
- 4688
- ProviderName
- Microsoft-Security-Auditing
- LogFile
- Security.evtx
- CommandLine
- C:\Windows\regedit.exe /s C:\Program Files (x86)\RemotePC\Register.reg
- Description
- Executing command to install various registry changes related to RemotePC.
- EventID
- 4688
- ProviderName
- Microsoft-Security-Auditing
- LogFile
- Security.evtx
- CommandLine
- netsh advfirewall firewall add rule name="RemotePCDesktop" enable=yes dir=in action=allow profile=any program="C:\Program Files (x86)\RemotePC\RemotePCDesktop.exe" description="This program is used for File Transfer and is part of RemotePC product."
- Description
- Executing command to add local firewall rule to allow inbound traffic for RemotePC.
Detections
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/access_remote_pc_files_sigma.yml
- Description
- Detects potential files activity of Access Remote PC RMM tool
References
Not recordedAcknowledgements
- Person
- Daniel Koifman
- Handle
- @koifsec