// MITRE ATT&CK
T1021 · Remote Services
Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to log into a service that accepts remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user. In an enterprise environment, servers and workstations can be organized ...
How to detect & mitigate it
Detecting Remote Services starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Sub-techniques (8)
T1021.001
Remote Desktop Protocol T1021.002
SMB/Windows Admin Shares T1021.003
Distributed Component Object Model T1021.004
SSH T1021.005
VNC T1021.006
Windows Remote Management T1021.007
Cloud Services T1021.008
Direct Cloud VM Connections
Remote Desktop Protocol T1021.002
SMB/Windows Admin Shares T1021.003
Distributed Component Object Model T1021.004
SSH T1021.005
VNC T1021.006
Windows Remote Management T1021.007
Cloud Services T1021.008
Direct Cloud VM Connections
Related techniques
T1021.005
VNC T1080
Taint Shared Content T1021.004
SSH T1091
Replication Through Removable Media T1021.008
Direct Cloud VM Connections T1563.001
SSH Hijacking T1021.002
SMB/Windows Admin Shares T1550
Use Alternate Authentication Material
VNC T1080
Taint Shared Content T1021.004
SSH T1091
Replication Through Removable Media T1021.008
Direct Cloud VM Connections T1563.001
SSH Hijacking T1021.002
SMB/Windows Admin Shares T1550
Use Alternate Authentication Material
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.