logo

How we built it: Expel’s latest RMM detections

ID: c06edf0c-25f3-5a1e-83f9-bbcf1c3a9c96

STIX ID: report--c06edf0c-25f3-5a1e-83f9-bbcf1c3a9c96

Feed Name: Expel Blog

Date Published: 2026-02-13

Date Updated: 2026-04-27

Author: Malachi Woodlee; Chris Wagner

...
...

This post describes how a security team developed and tuned five layered detections to identify malicious use of remote monitoring and management (RMM) tools—covering detection of known-but-uncommon RMMs, multiple RMMs on one host, correlated RMM network connections, detections for RMMs considered always malicious, and RMMs using non-standard ports—and shows example alerting and tuning (including auto-closing frequent benign RMM alerts) that reduced noise and helped surface suspicious activity such as customer pen tests.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.