// MITRE ATT&CK
T1021 · Remote Services
Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to log into a service that accepts remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user. In an enterprise environment, servers and workstations can be organized ...
¿Cómo detectarlo y mitigarlo?
La detección de Remote Services parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.
Sub-técnicas (8)
T1021.001
Remote Desktop Protocol T1021.002
SMB/Windows Admin Shares T1021.003
Distributed Component Object Model T1021.004
SSH T1021.005
VNC T1021.006
Windows Remote Management T1021.007
Cloud Services T1021.008
Direct Cloud VM Connections
Remote Desktop Protocol T1021.002
SMB/Windows Admin Shares T1021.003
Distributed Component Object Model T1021.004
SSH T1021.005
VNC T1021.006
Windows Remote Management T1021.007
Cloud Services T1021.008
Direct Cloud VM Connections
Técnicas relacionadas
T1021.005
VNC T1080
Taint Shared Content T1021.004
SSH T1091
Replication Through Removable Media T1021.008
Direct Cloud VM Connections T1563.001
SSH Hijacking T1021.002
SMB/Windows Admin Shares T1550
Use Alternate Authentication Material
VNC T1080
Taint Shared Content T1021.004
SSH T1091
Replication Through Removable Media T1021.008
Direct Cloud VM Connections T1563.001
SSH Hijacking T1021.002
SMB/Windows Admin Shares T1550
Use Alternate Authentication Material
Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.