RAT
Parsec
Parsec is a remote desktop streaming tool for remote access and monitoring, mainly used for gaming and collaboration. Remote desktop reimagined – a seamless 4k experience at up to 60 frames per second with near-zero latency. Secure, flexible, effortless access to whatever you do, at any time, from wherever you go. Parsec focuses on real-time graphical interaction rather than system administration but can still be abused for lateral movement and initial access.
Tool overview
- Category
- RAT
- Research authors
- Luca Di Bartolomeo & Matt Green
- Created
- 2025-03-16
- Last modified
- 2025-03-16
- Privileges
- Current User
- Free / availability
- Yes
- Verification required
- No
- Supported platforms
Android
Linux
Windows
macOS
Capabilities
Executables & installation paths
- Filename
- parsecd.exe
- OriginalFileName
- Not recorded
- Description
- Parsec
- Product
- Parsec
Installation paths
C:\Program Files\Parsec\*
parsecd.exe
pservice.exe
Code signing
- signer name
- Unity Technologies SF
- certificate thumbprint
- B73664F2AF5A8EF4529F03DB4B2CCD8275A6EC91
- src file sha256
- cc62d22bf8a082621fa25fdeee3150c17b09dbc09c9371e3dcdd6ec83967770c
- src file path
- downloaded_files/parsec/cc62d22bf8a082621fa25fdeee3150c17b09dbc09c9371e3dcdd6ec83967770c
- src file company
- Parsec
FORENSIC EVIDENCE
Disk artifacts
- File
- C:\Program Files\Parsec\parsecd.exe
- Description
- Main parsec executable
- OS
- Windows
- Example
- SHA256: 38011E713B4BE8577576062754CAD03E9899859488932AE4C9C83E5FBB5CB7D2
- File
- C:\Program Files\Parsec\pservice.exe
- Description
- Background service managing input devices
- OS
- Windows
- Example
- SHA256: CC62D22BF8A082621FA25FDEEE3150C17B09DBC09C9371E3DCDD6EC83967770C
- File
- C:\Program Files\Parsec\teams.exe
- Description
- Parsec for teams collaboration and user session management
- OS
- Windows
- Example
- SHA256: 6DC71B2E92B770DCFECA4A32C8F1787210311F731F1124754DF193EC22D5D13E
FORENSIC EVIDENCE
Event log artifacts
- EventID
- 7045
- ProviderName
- Service Control Manager
- LogFile
- System.evtx
- ServiceName
- parsecvirtualds
- ImagePath
- "\SystemRoot\System32\drivers\parsecvirtualds.sys"
- ServiceType
- kernel mode driver
- StartType
- demand start
- AccountName
- System
- Description
- Parsec service installation event
- Example
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event"><System><Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}"EventSourceName="Service Control Manager" /><EventID Qualifiers="16384">7045</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x8080000000000000</Keywords><TimeCreated SystemTime="2025-03-16T23:16:53.5897766Z" /><EventRecordID>596</EventRecordID><Correlation /><Execution ProcessID="804" ThreadID="912" /><Channel>System</Channel><Computer>Computer</Computer><Security UserID="S-1-5-18" /></System><EventData><Data Name="ServiceName">parsecvirtualds</Data><Data Name="ImagePath">\SystemRoot\System32\drivers\parsecvirtualds.sys</Data><Data Name="ServiceType">kernel mode driver</Data><Data Name="StartType">demand start</Data><Data Name="AccountName"></Data></EventData></Event>
FORENSIC EVIDENCE
Network artifacts
- Description
- Known domains used by Parsec
- Domains
- parsec.app
- parsec.gg
- *.parsec.app
- Ports
- 443
- 3478
Detections
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/parsec_network_sigma.yml
- Description
- Detects potential network activity of Parsec RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/parsec_files_sigma.yml
- Description
- Detects potential files activity of Parsec RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/parsec_processes_sigma.yml
- Description
- Detects potential processes activity of Parsec RMM tool
References
Acknowledgements
- Person
- Luca Di Bartolomeo
- Handle
- @LucaInfoSec
- Person
- Matt Green
- Handle
- @mgreen27