Skip to content

remote_access_tracing#6

Merged
tonmoy0010 merged 1 commit intoRegSeek:mainfrom
psexecsvc:main
Aug 28, 2025
Merged

remote_access_tracing#6
tonmoy0010 merged 1 commit intoRegSeek:mainfrom
psexecsvc:main

Conversation

@psexecsvc
Copy link
Copy Markdown
Contributor

title: "Remote Access Service"
category: "remote-access"

description: Two registry keys named <executable_name>_RASAPI32 and <executable_name>_RASMANCS are created the first time an application interacts with the Remote Access Service by loading rasapi32.dll and rasman.dll. This behavior allows analysts to confirm that a specific application has made an internet connection and to identify the timestamp of that connection

paths:

  • "HKLM\Software\Microsoft\Tracing\<executable_name>_RASAPI32"
  • "HKLM\Software\Microsoft\Tracing\<executable_name>_RASMANCS"

Ref:

@tonmoy0010 tonmoy0010 self-assigned this Aug 17, 2025
@tonmoy0010 tonmoy0010 self-requested a review August 17, 2025 02:02
@tonmoy0010
Copy link
Copy Markdown
Contributor

Validating the artifact, might take a while.

@tonmoy0010 tonmoy0010 merged commit 10d3fb9 into RegSeek:main Aug 28, 2025
3 checks passed
@tonmoy0010
Copy link
Copy Markdown
Contributor

Thank you for contributing!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants