diff --git a/thirdparty/InterestingFileSetRules/Remote Monitoring and Management Programs.xml b/thirdparty/InterestingFileSetRules/Remote Monitoring and Management Programs.xml new file mode 100644 index 00000000000..44de1b1692f --- /dev/null +++ b/thirdparty/InterestingFileSetRules/Remote Monitoring and Management Programs.xml @@ -0,0 +1,800 @@ + + + + remote_host.exe + remoting_host.exe + YandexDisk2.exe + ScreenConnect.ClientService.exe + Remote Workforce Client.exe + ScreenConnect.WindowsClient.exe + screenconnect.*\.exe + screenconnect.windowsclient.exe + ConnectWiseControl.*\.exe + connectwise.*\.exe + screenconnect.clientservice.exe + Session.db + User.xml + user.config + winvnc.*\.exe + vncserver.exe + winwvc.exe + winvncsc.exe + vncserverui.exe + vncviewer.exe + winvnc.exe + tsircusr.exe + laplink.exe + NetLock_RMM_Agent_Installer.exe + NetLock_RMM_Agent_Installer + NetLock_RMM_User_Process.exe + NetLock_RMM_User_UAC.exe + server_config.json + netlock-rmm-agent-comm.service + com.netlock.rmm.agentcomm.plist + netlock-rmm-agent-comm.log + kitty.exe + todesk.exe + ToDesk_Service.exe + ToDesk_Setup.exe + zaservice.exe + ZMAgent.exe + ZA_Access.exe + ZohoMeeting.exe + Zohours.exe + zohotray.exe + ZohoURSService.exe + Zaservice.exe + za_connect.exe + connect.exe + auvik.engine.exe + auvik.agent.exe + LMNoIpServer.exe + laplink.exe + laplink-everywhere-setup.*\.exe + laplinkeverywhere.exe + llrcservice.exe + serverproxyservice.exe + OOSysAgent.exe + servereye.*\.exe + ServiceProxyLocalSys.exe + putty.exe + Deskroll.exe + DeskRollUA.exe + zerotier.*\.msi + zerotier.*\.exe + zero-powershell.exe + ninjarmmagent.exe + NinjaRMMAgent.exe + NinjaRMMAgenPatcher.exe + ninjarmm-cli.exe + mstsc.exe + lmnoipserver.exe + ROMFUSClient.exe + romfusclient.exe + romviewer.exe + romserver.exe + ROMServer.exe + Insync.exe + strwinclt.exe + Splashtop-Splashtop Streamer-Status%4Operational.evtx + Splashtop-Splashtop Streamer-Remote Session%4Operational.evtx + FTCLog.txt + agent_log.txt + SPLog.txt + svcinfo.txt + sysinfo.txt + SRService.exe + SRAgent.exe + SSUAgent.exe + SRUtility.exe + SRFeature.exe + SRAgent.sqlite3 + royalserver.exe + royalts.exe + mygreenpc.exe + ManualLauncher.exe + zabbix_agent.*\.exe + Beinsync.*\.exe + quickassist.exe + SecureCRT.EXE + ImperoClientSVC.exe + helpbeam.*\.exe + BASupSrvc.exe + winagent.exe + BASupApp.exe + BASupTSHelper.exe + Agent_.*\_RW.exe + BASEClient.exe + BASupSrvcCnfg.exe + UltraVNC.*\.exe + dwagsvc.exe + dwagent.exe + jumpclient.exe + jumpdesktop.exe + jumpservice.exe + jumpconnect.exe + jumpupdater.exe + can't find this one + tniwinagent.exe + Tsdservice.exe + fleetdeck_agent_svc.exe + fleetdeck_commander_svc.exe + fleetdeck_installer.exe + fleetdeck_commander_launcher.exe + fleetdeck_agent.exe + MobaXterm_installer_12.1.msi + MobaXterm_installer_.*\.msi + aweray_remote.*\.exe + AweSun.exe + p9agent.*\.exe + parsecd.exe + pservice.exe + teams.exe + ARDAgent.app + SolarWinds-Dameware-DRS.*\.exe + DameWare Mini Remote Control.*\.exe + dntus.*\.exe + dwrcs.exe + dwrcst.exe + DameWare Remote Support.exe + SolarWinds-Dameware-MRC.*\.exe + awhost32.exe + awrem32.exe + pcaquickconnect.exe + winaw32.exe + saazapsc.exe + CagService.exe + AEMAgent.exe + action1_agent.exe + action1_log_.*\.log + ezhelpclientmanager.exe + ezHelpManager.exe + ezhelpclient.exe + islalwaysonmonitor.exe + isllight.exe + isllightservice.exe + ISLLightClient.exe + ISL Light.*\ + ISLLight.exe + ultimate_.*\.exe + AnyDesk.app + ad_svc.trace + connection_trace.txt + ad.trace + .*\.txt + user.conf + service.conf + system.conf + AnyDesk.lnk + Uninstall AnyDesk.lnk + .*\.anydesk + AlpemixService.exe + Alpemix.ini + gotoassist.exe + g2a.*\.exe + GoTo Assist Opener.exe + g2mcomm.exe + g2mupdate.com + goto opener.exe + g2ax_comm_customer.exe + nhostsvc.exe + nhstw32.exe + nldrw32.exe + rmserverconsolemediator.exe + IliAS.exe + issuser.exe + landeskagentbootstrap.exe + LANDeskPortalManager.exe + ldinv32.exe + ldsensors.exe + softmon.exe + tmcsvc.exe + Remote Workforce Client.exe + This installs a modified VNC and cannot be blocked by path separate from VNC + EricomConnectRemoteHost.*\.exe + ericomconnnectconfigurationtool.exe + ehorus standalone.exe + AgentSetup-.*\.exe + RDPWInst.exe + RDPCheck.exe + RDPConf.exe + iodihamcpbpeioajjeobimgagajmlibd.*\ + Solar-PuTTY.exe + Kabuto.App.Runner.exe + domotz.exe + Domotz Pro Desktop App.exe + domotz_bash.exe + domotz.*\.exe + Domotz Pro Desktop App Setup.*\.exe + domotz-windows.*\.exe + JumpCloud.*\.exe + cloudflared.exe + rport.exe + hsloader.exe + InstantHousecall.exe + ihcserver.exe + instanthousecall.exe + mwcliun.exe + pcnmgr.exe + webexpcnow.exe + Online Backup.exe + CBBackupPlan.exe + Cloud.Backup.Scheduler.exe + Cloud.Backup.RM.Service.exe + cbb.exe + CloudRaService.exe + CloudRaSd.exe + CloudRaCmd.exe + CloudRaUtilities.exe + Remote Desktop.exe + Connect.exe + simplehelpcustomer.exe + simpleservice.exe + simplegatewayservice.exe + remote access.exe + windowslauncher.exe + spsrv.exe + serviceconfig.xml + pocketcontroller.exe + wysebrowser.exe + XSightService.exe + clientmrinit.exe + mgntsvc.exe + routernt.exe + rutview.exe + rutserv.exe + SRServer.exe + SplashtopSOS.exe + Splashtop_Streamer_Windows.*\.exe + SRManager.exe + guacd.exe + remote-it-installer.exe + remote.it.exe + remoteit.exe + goverrmc.exe + govsrv.*\.exe + GovAgentInstallHelper.exe + GovAgentx64.exe + GovReachClient.exe + GovSrv.exe + Syncro.Installer.exe + Kabuto.App.Runner.exe + Syncro.Overmind.Service.exe + Kabuto.Installer.exe + KabutoSetup.exe + Syncro.Service.exe + Kabuto.Service.Runner.exe + Syncro.App.Runner.exe + SyncroLive.Service.exe + SyncroLive.Agent.exe + alitask.exe + aspia_client.exe + client.ini + aspia_client-.*\.log + qt.conf + ocsinventory.exe + ocsservice.exe + superputty.exe + nvClient.exe + netviewer.exe + ltsvc.exe + dcagentservice.exe + dcagentregister.exe + rfusclient.exe + rutserv.exe + Sorillus-Launcher.*\.exe + Sorillus Launcher.exe + accessserver.*\.exe + accessserver.exe + NTRsupportPro_EN.exe + RemotePCUIU.exe + nhostsvc.exe + nhstw32.exe + ngstw32.exe + Netop Ondemand.exe + nldrw32.exe + rmserverconsolemediator.exe + ImperoInit.exe + Connect.Backdrop.cloud.*\.exe + ImperoClientSVC.exe + gp3.exe + gp4.exe + gp5.exe + nomachine.*\.exe + nxservice.*\.ese + nxd.exe + SMPCSetup.exe + showmypc.*\.exe + showmypc.exe + smpcsetup.exe + IvantiRemoteControl.exe + ArcUI.exe + AgentlessRC.exe + rcengmgru.exe + rcmgrsvc.exe + rxstartsupport.exe + rcstartsupport.exe + raautoup.exe + agentu.exe + remotesupportplayeru.exe + dwrcs.exe + basuptshelper.exe + basupsrvcupdate.exe + BASupApp.exe + BASupSysInf.exe + BASupAppSrvc.exe + TakeControl.exe + BASupAppElev.exe + basupsrvc.exe + RDConsole.exe + RocketRemoteDesktop_Setup.exe + pdq-connect.*\.exe + PDQConnectUpdater-.*\.msi + PDQConnectAgent.db-journal + superopsticket.exe + superops.exe + level-windows-amd64.exe + level.exe + level-remote-control-ffmpeg.exe + mionet.exe + mionetmanager.exe + remoteconsole.exe + pcvisit.exe + pcvisit_client.exe + pcvisit-easysupport.exe + pcvisit_service_client.exe + islalwaysonmonitor.exe + isllight.exe + isllightservice.exe + ngrok.exe + ngrok.zip + ngrok.*\ + aeroadmin.exe + AeroAdmin.exe + bomgar-scc-.*\.exe + bomgar-scc.exe + bomgar-pac-.*\.exe + bomgar-pac.exe + bomgar-rdp.exe + MEGAsyncSetup64.exe + MEGAupdater.exe + rd.exe + rudesktop.*\.exe + tigervnc.*\.exe + winvnc4.exe + tvnserver.exe + PCIVIDEO.EXE + supporttool.exe + ScreenMeetSupport.exe + ScreenMeet.Support.exe + Idrive.File-Transfer + remotepcservice.exe + RemotePC.exe + remotepchost.exe + idrive.RemotePCAgent + rpcsuite.exe + RemotePCService.exe + PCMonitorManager.exe + pcmonitorsrv.exe + tacticalrmm.exe + iit.exe + intouch.exe + I'm InTouch Go Installer.exe + puttytray.exe + DragonDisk.exe + InstallShield Setup.exe + ManageEngine_Remote_Access_Plus.exe + dcagentservice.exe + helpu_install.exe + HelpuUpdater.exe + HelpuManager.exe + G2RDesktopConsole-x64.msi + Radmin.exe + rserver3.exe + FamItrfc + FamItrf2 + Radm_log.htm + .*\.htm + SmarTTY.exe + BvSshClient-Inst.exe + pocketcontroller.exe + pocketcloudservice.exe + wysebrowser.exe + era.exe + einstaller.exe + ezhelp.*\.exe + eratool.exe + ERAAgent.exe + WinSCP.exe + qq.exe + QQProtect.exe + qqpcmgr.exe + xeox-agent_x64.exe + xeox_service_windows.exe + xeox-agent_.*\.exe + xeox-agent_x86.exe + itsmagent.exe + rviewer.exe + rdp.exe + ir_agent.exe + rapid7_agent_core.exe + rapid7_endpoint_broker.exe + echoserver.*\.exe + echoware.dll + GotoHTTP_x64.exe + gotohttp.exe + GotoHTTP.*\.exe + tvnviewer.exe + TightVNCViewerPortable.*\.exe + tvnserver.exe + zoc.exe + SfShellTools.dll.mui + fastclient.exe + fastmaster.exe + FastViewer.exe + Remote Desktop Manager + RemoteDesktopManager.exe + Connections.log + Mru.xml + Connections.db + ExtraPuTTY-0.30-2016-01-28-installer.exe + sysdiag.exe + OTService.exe + OTPowerShell.exe + rdp.exe + Pilixo_Installer.*\.exe + AgentPackageNetworkDiscovery.exe + AgentPackageTaskScheduler.exe + AteraAgent.exe + atera_agent.exe + ateraagent.exe + Atera Networks + syncrosetup.exe + log.txt + AlphaAgent.exe + AgentPackageSTRemote.exe + AgentPackageMonitoring.exe + AgentPackageHeartbeat.exe + AgentPackageFileExplorer.exe + AgentPackageRunCommandInteractive.exe + KHelpDesk.exe + remoteview.exe + rv.exe + rvagent.exe + rvagtray.exe + supremo.exe + supremoservice.exe + supremosystem.exe + supremohelper.exe + neturo.*\.exe + ntrntservice.exe + neturo.exe + nxplayer.exe + FixMeit Client.exe + TiExpertStandalone.exe + FixMeitClient.*\.exe + TiExpertCore.exe + FixMeit Unattended Access Setup.exe + FixMeit Expert Setup.exe + fixmeitclient.exe + TiClientCore.exe + TiClientHelper.*\.exe + 9380CC75B872221A7425D7503565B67580407F60 + wisshell.*\.exe + wmc.exe + wmc_deployer.exe + wmcsvc.exe + support-logmeinrescue.*\.exe + support-logmeinrescue.exe + lmi_rescue.exe + lmi_rescue_srv.exe + Xpra-Launcher.exe + Xpra-x86_64_Setup.exe + webrdp.exe + royalts.exe + pcictlui.exe + pcicfgui.exe + client32.exe + ehorus standalone.exe + ehorus_agent.exe + seetrolcenter.exe + seetrolclient.exe + seetrolmyservice.exe + seetrolremote.exe + seetrolsetting.exe + hoptodesk.exe + HopToDesk.app + HopToDesk.exe + privacyhelper.exe + PrivacyMode.dll + sciter.dll + HopToDesk.toml + hoptodesk_rCURRENT.log + GetScreen.exe + getscreen.exe + TaniumClient.exe + TaniumCX.exe + TaniumExecWrapper.exe + TaniumFileInfo.exe + TPowerShell.exe + psexec.exe + psexecsvc.exe + crossloopservice.exe + CrossLoopConnect.exe + WinVNCStub.exe + pocketcloud.*\.exe + pocketcloudservice.exe + remobo.exe + remobo_client.exe + remobo_tracker.exe + termsrv.exe + mstsc.exe + Microsoft Remote Desktop + rpcnet.exe + ctes.exe + ctespersitence.exe + cteshostsvc.exe + rpcld.exe + level.exe + osqueryi.exe + level.log + remcos.*\.exe + goto.log + ltsvc.exe + ltsvcmon.exe + lttray.exe + remotepass-access.exe + rpaccess.exe + rpwhostscr.exe + addigy-.*\.pkg + iperius.exe + iperiusremote.exe + parallelsaccess-.*\.exe + TSClient.exe + prl_deskctl_agent.exe + prl_deskctl_wizard.exe + prl_pm_service.exe + UVNC_Launch.exe + winvnc.exe + vncviewer.exe + BvSshServer-Inst.exe + Duplicati.Server.exe + AMMYY_Admin.exe + aa_v.*\.exe + access.log + AA_v3.log + requires sign up + myivomgr.exe + myivomanager.exe + UltraViewer_Service.exe + UltraViewer_setup.*\ + UltraViewer_Desktop.exe + ultraviewer.exe + ultraviewer_desktop.exe + ultraviewer_service.exe + apc_host.exe + ddsystem.exe + dd.exe + distant-desktop.exe + rutview.exe + rutserv.exe + xShell.exe + ltsvc.exe + ltsvcmon.exe + lttray.exe + pstlaunch.exe + ptdskclient.exe + ptdskhost.exe + Bluetrait MSP Agent.exe + BluetraitUserAgent.exe + config.db + config.json + paexec.exe + konea.exe + teamviewer_desktop.exe + teamviewer_service.exe + teamviewerhost + TV15Install.log + .log + Connections_incoming.txt + TVNetwork.log + teamviewerqs.exe + tv_w32.exe + tv_w64.exe + tv_x64.exe + teamviewer.exe + tvchatfilecache.db + tvprint.db + TeamViewer.lnk + connections.*\.txt + .*\tvc + termsrv.exe + mstsc.exe + rustdesk.*\.exe + rustdesk.exe + RustDesk + mikogo.exe + mikogo-starter.exe + mikogo-service.exe + mikogolauncher.exe + Mikogo-Service.exe + Mikogo-Screen-Service.exe + OrayRemoteShell.exe + OrayRemoteService.exe + sunlogin.*\.exe + paexec.exe + PAExec-.*\.exe + csexec.exe + remcom.exe + remcomsvc.exe + xcmd.exe + xcmdsvc.exe + desktopnow.exe + beamyourscreen.exe + beamyourscreen-host.exe + AcronisCyberProtectConnectQuickAssist.*\.exe + AcronisCyberProtectConnectAgent.exe + Syncthing.exe + s3browser.*\.exe + meshcentral.*\.exe + meshagent.*\.exe + MeshAgent.exe + MeshAgent.msh + meshagent + meshagent.db + meshagent.msh + grabberEM.*\.msi + grabberTT.*\.msi + oo-syspectr.*\.exe + OOSysAgent.exe + GoTo Opener + ConnectAppSetup.*\.exe + ConnectShellSetup.*\.exe + Connect.exe + ConnectDetector.exe + tailscale-.*\.exe + tailscaled.exe + tailscale-ipn.exe + agentmon.log + system.log + logs.*\ + KASetup.log + logs + makecert.txt + KaseyaEndpoint.*\ + Session_.*\ + strwinclt.exe + Splashtop_Streamer_Windows.*\.exe + SplashtopSOS.exe + sragent.exe + srmanager.exe + srserver.exe + srservice.exe + iadmin.exe + intelliadmin.exe + agent32.exe + agent64.exe + agent_setup_5.exe + pcstarter.exe + turbomeeting.exe + turbomeetingstarter.exe + TeamTaskManager.exe + DSGuest.exe + netviewer.*\.exe + netviewer.exe + weezohttpd.exe + weezo.exe + weezo setup.*\.exe + mionet.exe + mionetmanager.exe + nateon.*\.exe + nateon.exe + nateonmain.exe + connectwisechat-customer.exe + connectwisecontrol.client.exe + screenconnect.windowsclient.exe + tdp2tcp.exe + rdp2tcp.py + SensoClient.exe + SensoService.exe + aadg.exe + mRemoteNG.exe + mRemoteNG + mRemoteNG-Installer-.*\.msi + mRemoteNG.log + confCons.xml + user.config + ctiserv.exe + MEAgentHelper.exe + MonitoringAgent.exe + Site24x7WindowsAgentTrayIcon.exe + Site24x7PluginAgent.exe + quickassist.exe + onionshare.*\.exe + OnionShare-win.*\.msi + ITSMAgent.exe + RViewer.exe + ItsmRsp.exe + RAccess.exe + RmmService.exe + ITarianRemoteAccessSetup.exe + RDesktop.exe + ComodoRemoteControl.exe + ITSMService.exe + RHost.exe + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +