FORENSIA

ATT&CK · T1133

External Remote Services

Tactics: persistence, initial-access

About

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally. Access to Valid Accounts to use the service is often a requirement, which could be obtained through credential pharming or by obtaining the credentials from users after compromising the enterprise network. Access to remote services may be used as a redundant or persistent access mechanism during an operation. Access may also be gained through an exposed service that doesn’t require authentication. In containerized environments, this may include an exposed Docker API, Kubernetes API server, kubelet, or web application such as the Kubernetes dashboard. Adversaries may also establish persistence on network by configuring a Tor hidden service on a compromised system. Adversaries may utilize the tool `ShadowLink` to facilitate the installation and configuration of the Tor hidden service. Tor hidden service is then accessible via the Tor network because `ShadowLink` sets up a .onion address on the compromised system. `ShadowLink` may be used to forward any inbound connections to RDP, allowing the adversaries to have remote access. Adversaries may get `ShadowLink` to persist on a system by masquerading it as an MS Defender application.

Platforms: Containers, Linux, macOS, WindowsMITRE ATT&CK ↗

Corpus indicators tagged with this technique

207 indicators in the corpus carry T1133.

IndicatorTypeFamilySevSrc
cve-2025-34054cve854
cve-2016-0638cvephishing851
cve-2021-27137cve858
cve-2016-15047cve854
cve-2022-47945cve851
00e195d94d3b1f7092eb9ed132f89d1bhash803
b1b7aaa5bd4408a4d3003a9fabcdd041hash803
e952c18272efa1c3d73d0a5381bcf443c02743fehash803
2654c08491a0f7c4a3dfc6282de5638bhash803
479ae5fd7274439ddfa27bc03298ebfdfc5ff17f6412acccf74d4dbd90d94218sha256phishing801
95fc58dc321b07ecc99d95359bcdee08a5beb519ead8e70e40f33928533a1b14hashphishing803
84ad78b2bab946c3677fdc28ebd8a774hash803
51d39aa39478beeac94f2d12f682eccehashransomware802
52fda5c1b9704544f32ee98d9060e689hashransomware802
ebcf977806f68af3147e0b78b55f6aedhash802
38353f95fff270f4e3a9d7add8c64666020dd668ce66e15969a736ec48cadc59sha256phishing801
b8eed63ab9cbdca494f26a6f66bfd4a0a693b3f0hash803
4253dd1a4c0867b0be7732f75b2f630cebfb7fed94270e15fb3b12ae40546d01sha256phishing801
9c44bc9373377831c45dd0ac2661a28ehash803
a30a9779079dc897a15fed27f27f614fab77a20e953368808ba99ac6c6a3375bsha256phishing801
b82936f37648518425c7d3cf9e09eaffa41d7cdb3840f6a40287e3a108880f7bsha256802
eead44c0af7ddb12cece1a6125cf213bab3c22511cd59aff9d63dcfddb7d4386hash804
123e80a34508c4dede7cc70e76931fcchash803
874bcb1c3d050a5b5b333a2198f504fcb27927c2abdd43b07440188a380c52d5sha256phishing801
625b6535321d58bb5c613e85332bf731hash803
686213cc11d36af764de824801bced9366dfca3823fe0d51b752f74149bcf1f4sha256ransomware801
873f1277a42de5c82f869459e7fb7c94554a642bhash803
9eaa577c8ba71646928c1c34c3145536b0498f65f26060a6ba00744bcef57644sha256phishing801
681075027553546c119ec447eb8df84633dcffcehash803
f4d77958a12a0778283d3e679b24b18f82e332c4hash803

Showing the top 30 by severity of 207.