Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsDetect remote access abuse by comparing endpoint activity with an explicit inventory of approved remote access and remote monitoring and management (RMM) tools, accounts, devices and access routes. Investigate deviations—such as an unapproved or portable tool, an unexpected execution context, memory-only activity, use outside the required VPN or virtual desktop route, or unusual connections to other hosts. A familiar product name is not proof of compromise: legitimate tools are dual-use, so assess who used the tool, on which endpoint, how it ran and whether the activity matches an approved support workflow.
Why legitimate remote access tools need contextual monitoring
Organizations use remote access software for administration and support, but attackers can use the same capabilities to blend into ordinary system and network activity. CISA notes that legitimate use is frequently not flagged as malicious by security tools or processes in its Guide to Securing Remote Access Software, published June 6, 2023. RMM tools can support unattended administration, elevated permissions and management of multiple devices, so unauthorized use may have significant reach.
That dual-use nature cuts both ways: alerting on a program name alone can produce false positives, while allowing a known tool without checking its execution and connections can miss misuse. The goal is to establish what is authorized, monitor how it is being used and investigate activity that falls outside expected practice.
Build an inventory before writing detections
Record the authorized remote access and RMM software in your environment, including tools used by outside support providers. CISA’s #StopRansomware Guide recommends auditing network tools to identify which RMM software is in use and authorized. For the inventory to support investigations, document the operational context too:
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- SonicWall TZ270W Appliance Only - No Service Subscription (02-SSC-2823) - Combines enterprise-grade firewalling with integrated 802.11ac Wave 2 Wi-Fi to deliver secure wired and wireless connectivity in one compact device for small offices and clinics.
- Blocks zero-day threats and ransomware with Capture ATP sandboxing enhanced by RTDMI, plus IPS and anti-malware scanning for layered protection.
- Eliminates the need for separate access points in smaller spaces thanks to built-in high-speed wireless that is simple to deploy and manage.
- Supports VPN, SD-WAN, and TLS 1.3 decryption to secure hybrid cloud access and remote workers while maintaining usability and performance.
- Delivers gigabit performance with up to 750,000 concurrent connections to handle growth in users, devices, and SaaS applications.
- Tool and deployment: product, managed or installed instances, and any approved temporary support or trial use.
- Owner: internal business or IT owner, or the responsible service provider.
- Scope: endpoints the tool is permitted to manage and expected user or service accounts.
- Access route: required VPN, virtual desktop interface (VDI) or other approved route, plus expected support workflows.
These ownership and scope details are practical ways to make the audit useful during triage; they are not a universal CISA scoring model. Review the inventory when support arrangements, products or approved endpoints change.
What endpoint activity should prompt investigation?
Prioritize deviations from the inventory and the normal support workflow. The cues below are investigation leads, not proof of malicious activity or an exhaustive list of indicators.
Rank #2
- Watchguard Tech WG50021 Firebox X20e-Wireless
- Unapproved or newly introduced software: an RMM or remote access program absent from the inventory, including a portable executable that may not appear in an ordinary installed-software list. CISA recommends application controls to manage execution and prevent unauthorized portable versions.
- Unexpected execution context: a known program launched from an unusual path, by an unexpected account, outside its normal support window or on a host beyond its approved scope. Compare each observation with your own documented workflow; these are contextual checks, not a published CISA alert formula.
- Memory-only activity: an RMM instance that appears to run only in memory. The 2023 joint CISA, NSA and MS-ISAC advisory, Protecting Against Malicious Use of Remote Monitoring and Management Software, recommends using security software to detect this case.
- Use outside the approved route: an authorized tool being used without the organization’s required VPN or VDI path. CISA recommends requiring authorized RMM solutions to be used from within the network over approved remote access solutions.
- Unusual connections from the endpoint: unexpected lateral connections or an unusual sequence of remote connections after a tool launches. CISA’s ransomware guidance says EDR can provide insight into common and uncommon host connections, which can help identify lateral activity.
Interpret these signals together. A launch at an unusual time might be scheduled maintenance; a legitimate tool contacting unexpected hosts may be more concerning when the account, endpoint and route are also outside approved practice.
Correlate endpoint and network evidence
Endpoint monitoring is more useful when it records process execution alongside account, host and connection details. Correlate a remote tool launch with subsequent connections from that endpoint and with relevant network defense monitoring. Check whether the destination hosts and access route fit the authorized support workflow, and preserve relevant logs for investigation.
Rank #3
- XGS 88 with 3 Years Standard Protection - Next-generation firewall appliance with Standard Protection subscription providing firewall, VPN, intrusion prevention, web security, and application control, managed through Sophos Central for unified policies and reporting.
- Equipped with 4 x 2.5 GE copper ports, supporting up to 9.9 Gbps firewall performance for small offices and branch deployments.
- Protects users from ransomware, malware, phishing, and intrusion attempts before they reach endpoints or applications.
- SD-WAN features deliver reliable, optimized application performance and intelligent multi link failover.
- Includes Standard Protection – Comprehensive security package with firewall, intrusion prevention, VPN, web security, and application control to defend against everyday threats and keep business operations safe.
EDR and network telemetry can improve visibility, but CISA’s guidance does not establish that a particular product or combination catches every abuse case. It also does not provide vendor rankings, controlled product tests or a universal alert threshold. Choose controls for the evidence they expose and the policies they can enforce, rather than treating a tool label or product claim as a guarantee.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to triage an alert without mistaking it for a confirmed incident
- Identify the activity: review the endpoint’s process and execution details, the account involved, and the time and path of execution.
- Check authorization: compare the software, user and host with the approved-tool inventory and the endpoint’s permitted scope.
- Verify the support context: look for a ticket or support request, confirm the vendor or managed service provider relationship, and check whether the observed access route was approved.
- Review connections: inspect destination hosts and the sequence of remote connections for activity that does not fit the expected task.
- Preserve evidence and escalate as warranted: retain relevant endpoint and network logs, then investigate further when multiple contextual signals or other suspicious activity support concern.
An uncommon execution can have a legitimate maintenance explanation, just as familiar software can be misused. Treat the alert as a lead until the evidence supports a stronger conclusion.
Reduce exposure while preserving legitimate support
Use application controls or allowlisting to manage which remote access tools can execute, and prevent installation or execution of unauthorized portable RMM versions. Require approved tools to use the organization’s designated VPN or VDI route, and keep endpoint and network telemetry available to investigate activity. CISA also recommends blocking common RMM ports and protocols at the network perimeter where appropriate; account for approved operations before applying blocks so legitimate support is not unintentionally disrupted.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

