RMM
Action1
Action1 is a powerful Remote Monitoring and Management(RMM) tool that enables users to execute commands, scripts, and binaries. Through the web interface of action1, the administrator must create a new policy or an app to establish remote execution and then points that the agent is installed.
Tool overview
- Category
- RMM
- Research authors
- @kostastsale
- Created
- 2024-08-03
- Last modified
- 2024-08-03
- Privileges
- SYSTEM
- Free / availability
- Yes
- Verification required
- Corporate email required although temporary email services are accepted
- Supported platforms
Windows
Capabilities
Executables & installation paths
- Filename
- action1_connector.exe
- Filename
- action1_remote.exe
- Filename
- action1_update.exe
- Filename
- action1_agent.exe
- OriginalFileName
- action1_agent.exe
- Description
- Endpoint Agent
Installation paths
C:\Windows\Action1\*
Code signing
- signer name
- Action1 Corporation
- certificate thumbprint
- 59CE0A286FBDF3F600235A8B7513AE1DC2243A20
- src file sha256
- ab6804a23ab76fff5ab63d7be8c3f179fca4154b56759590c27e6fa203e5d1c4
- src file path
- downloaded_files/action1/ab6804a23ab76fff5ab63d7be8c3f179fca4154b56759590c27e6fa203e5d1c4
- src file company
- Action1 Corporation
FORENSIC EVIDENCE
Disk artifacts
- File
- C:\Windows\Action1\action1_agent.exe
- Description
- Action1 service binary
- OS
- Windows
- File
- C:\Windows\Action1\*
- Description
- Multiple files and binaries related to Action1 installation
- OS
- Windows
- File
- C:\Windows\Action1\scripts\*
- Description
- Multiple scripts related to Action1 installation
- OS
- Windows
- File
- C:\Windows\Action1\rule_data\*
- Description
- Files related to Action1 rules
- OS
- Windows
- File
- C:\Windows\Action1\action1_log_*.log
- Description
- Contains history, errors, system notifications. Incoming and outgoing connections.
- OS
- Windows
FORENSIC EVIDENCE
Event log artifacts
- EventID
- 7045
- ProviderName
- Service Control Manager
- LogFile
- System.evtx
- ServiceName
- A1Agent
- ImagePath
- "C:\\Windows\\Action1\\action1_agent.exe"
- Description
- Service installation event as result of Action1 installation.
- EventID
- 4697
- ProviderName
- Microsoft-Security-Auditing
- LogFile
- Security.evtx
- ServiceName
- A1Agent
- CommandLine
- C:\Windows\Action1\action1_agent.exe service
- Description
- Service installation event as result of Action1 installation.
- EventID
- 4688
- ProviderName
- Microsoft-Security-Auditing
- LogFile
- Security.evtx
- CommandLine
- C:\Windows\Action1\action1_agent.exe loggedonuser
- Description
- Executing command to get logged on user.
FORENSIC EVIDENCE
Registry artifacts
- Path
- HKLM\System\CurrentControlSet\Services\A1Agent
- Description
- Service installation event as result of Action1 installation.
- Path
- HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\Windows Error Reporting\LocalDumps\action1_agent.exe
- Description
- Ensures that detailed crash information is available for analysis, which aids in maintaining the stability and reliability of the software.
- Path
- HKLM\SOFTWARE\WOW6432Node\Action1
- Description
- Storing its configuration settings and other relevant information
FORENSIC EVIDENCE
Network artifacts
- Description
- N/A
- Domains
- *.action1.com
- Ports
- 443
- Description
- N/A
- Domains
- a1-backend-packages.s3.amazonaws.com
- Ports
- 443
Detections
- Name
- Arbitrary code execution and remote sessions via Action1 RMM
- Description
- Threat hunting rule for detecting the execution of arbitrary code and remote sessions via Action1 RMM
- author
- @kostastsale
- Link
- https://github.com/tsale/Sigma_rules/blob/ea87e4fc851207ca0f002ec043624f2b3bf1b2da/Threat%20Hunting%20Queries/Action1_RMM.yml
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/action1_registry_sigma.yml
- Description
- Detects potential registry activity of Action1 RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/action1_network_sigma.yml
- Description
- Detects potential network activity of Action1 RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/action1_files_sigma.yml
- Description
- Detects potential files activity of Action1 RMM tool
References
Acknowledgements
- Person
- Kostas
- Handle
- @kostastsale