iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
To audit remote monitoring and management (RMM) tools for unauthorized access, compare what your organization has approved with what is actually running, who can sign in, and what the logs show. Start with an inventory of authorized tools, users, vendors, and access paths; then check endpoint execution and network telemetry as well as installed-software lists. Portable or memory-only RMM clients can run without appearing in a conventional software inventory, and a legitimate product can still be used without authorization.
What counts as an unauthorized RMM access path?
RMM software lets administrators or service providers remotely monitor and manage endpoints. An audit should therefore cover more than product names: an approved tool may have an unapproved account, role, session, deployment, or network route. Include other remote-access and remote-support tools in scope, even when they are not marketed as RMM.
CISA, NSA, and MS-ISAC documented a campaign in which attackers used legitimate RMM software following help-desk-themed phishing. The advisory described portable AnyDesk and ScreenConnect (now ConnectWise Control) executables that did not require installation or administrative privileges. These are examples from a particular campaign, not a complete list of risky products: legitimate RMM software of any brand can be abused. Read joint advisory AA23-025A.
Free tools Windows power users keep installed
One-click scans. No signup required.
Establish the authorized baseline
Before looking for anomalies, define which systems and relationships the audit covers and what approved access should look like. Record the source and date of each inventory or authorization record so that findings can be checked against the state in effect at the time.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Systems, endpoints, cloud environments, RMM tenants, and MSP or other third-party relationships in scope.
- Each approved RMM and remote-access product, its owner, business purpose, version where available, expected endpoints, and approved network path.
- Named administrators, service accounts, API or service identities where supported, third-party accounts, and each identity’s permitted role.
- Authoritative change records or business owners who can confirm an unfamiliar deployment or account.
Confirm who is authorized to conduct the review, how suspected unauthorized access is escalated, and how relevant evidence must be preserved under your incident-response and retention procedures. The baseline should make clear not just which tools are allowed, but who may use them, from where, and for what purpose.
Audit RMM tools, identities, sessions, and logs
- Find actual execution, not just installations. Compare the approved list with endpoint and software inventories, application-control events, process or execution telemetry, and network observations. Look for unexpected or renamed binaries, portable executables, activity from temporary or user-writable locations, memory-only loading, and connections to unapproved services. An installed-software inventory alone can miss a client that runs without installation. CISA recommends reviewing execution logs for abnormal RMM use and using security software to detect memory-only instances.
- Reconcile accounts and permissions. Review RMM users, administrator roles, service accounts, API or service identities where supported, MSP and other third-party accounts, MFA status, and recent access changes. Match each identity to a current owner and business need. Disable or remove stale or unauthorized access through your change-control process. CISA specifically recommends auditing accounts, with attention to publicly accessible RMM accounts and third-party/MSP access.
- Review session and administrative activity. Examine available authentication successes and failures, session starts and ends, remote command or file-transfer events, privilege and role changes, and configuration changes. Record which events and time range you reviewed; available fields and event types vary by product.
- Correlate across sources. Compare RMM records with identity, endpoint, application-control, and network events. Where available, establish the user or process, timestamp, event, outcome, and source or destination. A timeline assembled from independent repositories is more informative than a single unfamiliar process or login. NIST SP 800-171 Rev. 3 calls for reviewing and analyzing selected audit events, correlating records across repositories, and protecting audit information. See NIST SP 800-171 Rev. 3.
- Check log coverage and integrity. Verify that relevant logging is enabled, retention follows organizational policy, timestamps allow a coherent sequence, and access to log administration is limited. Check for logging failures or unexplained gaps. Where possible, ensure RMM administrators under review cannot silently alter or delete the evidence. NIST requires protection of audit information and logging tools from unauthorized access, modification, and deletion, and recommends limiting audit-log management to a subset of privileged roles. CISA’s logging guide also recommends centralizing, protecting, and regularly monitoring logs. Read CISA’s logging guidance.
- Document the result. Record scope, systems and tenants reviewed, inventory sources, dates, accounts and tools checked, evidence sources, exceptions, remediation owners, and deadlines. Note limits such as unavailable session logs or incomplete endpoint coverage: a clean result is less conclusive when visibility is incomplete.
How to judge suspicious findings
An unknown agent may be an approved but undocumented deployment, while a known product may be used by an unauthorized person. Validate unfamiliar tools and accounts against owners, authorization records, and change history before labeling them malicious. Portable execution, memory-only loading, an unexplained third-party account, an unexpected privilege change, or a log gap merits investigation; none alone proves compromise.
Rank #2
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Confidence improves when separate sources support the same timeline—for example, an unfamiliar account’s successful login, an unexpected endpoint process, a role change, and a related network connection. Preserve relevant evidence and follow the organization’s incident-response process if the combined evidence suggests compromise. Treat gaps as a visibility problem to resolve, not as proof that no access occurred.
Reduce the chance of repeat access
- Use application controls to allow approved RMM and restrict unauthorized tools and portable versions; controls should address execution as well as installation.
- Require authorized RMM access to use approved VPN or virtual desktop infrastructure (VDI) paths, and restrict common RMM ports and protocols at the network perimeter where appropriate.
- Apply least privilege and separation of duties to third-party access. Require phishing-resistant MFA for services and accounts that can reach critical systems.
- Review inactive and unauthorized user and administrator accounts at least quarterly as a practical baseline from CISA guidance, prioritizing publicly accessible RMM accounts and MSP access. Set other review intervals according to risk and organizational policy.
- Centralize and regularly review logs from endpoints, servers, firewalls, and cloud services; alert on high-risk events such as failed logins and privilege escalation, and protect log storage and administration.
These measures follow CISA’s RMM and logging guidance and NIST audit controls; they are preventive controls, not substitutes for investigating evidence of prior access.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What to compare when evaluating audit capabilities
If you are assessing an RMM platform, identity system, or log-management service, compare these capabilities against your audit requirements. This is a control checklist, not a comparative product test.
| Capability | What to verify |
|---|---|
| Audit-event coverage | Can you review and export identity, session, command, and configuration events needed for your audit? |
| Identity controls | Can roles be scoped to least privilege, MFA be applied, and third-party accounts be limited appropriately? |
| Log protection | Are retention and tamper resistance adequate, and can log administration be separated from audited administration? |
| Monitoring and correlation | Can alerts and records be correlated across RMM, identity, endpoints, and network sources? |
| Portable-client visibility | Can the environment detect or control portable clients and integrate with application controls? |
| Network-path fit | Can authorized access follow the organization’s approved VPN/VDI and network policies? |
Product interfaces, event fields, retention defaults, and MFA support vary and change over time. Verify current product documentation and your organization’s authorization records before conducting a product-specific review.
Quick Recap
Rank #4
- Reversible insert tool for can wrenches.
- One end for SLC Cabinets. Other end for pin in head screws found in most Network Interface boxes.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools

