RMM tools like ScreenConnect are a top attacker entry point. Here's why, and what to do about it.
Remote monitoring and management (RMM) tools like ScreenConnect get abused precisely because they're supposed to be on the network. Banning them isn't practical for most businesses. Restricting what each connection can do, and watching for the few behaviors that separate a technician from an intruder, is.
These tools are on an approved list, signed by a trusted vendor, and usually exempt from the scrutiny given to unfamiliar software. An attacker who gets access to one doesn't need custom malware. They just need a session. That's what makes RMM abuse hard to catch with traditional antivirus, and why it keeps showing up in real-world intrusions.
Why RMM Tools Are a Favorite Entry Point
Three things make remote support software attractive to attackers:









