Skip to content
CIM-083 Cyber Incidents & Offender Methods

What is remote monitoring and management software?

Remote monitoring and management software, often called RMM software, allows administrators or service providers to manage devices remotely.

Avoid the dangerous assumption

The dangerous assumption is that RMM software is suspicious simply because it gives broad control.

It is commonly used legitimately by internal IT teams and managed service providers.

RMM platforms may allow:

  • software deployment
  • command execution
  • patching
  • monitoring
  • file transfer
  • remote shell access
  • screen control
  • scheduled tasks
  • device inventory
  • credentialed administration.

Offenders may abuse existing RMM accounts, deploy new agents or use compromised service-provider access to reach several organisations.

Investigators should identify:

  • the RMM product
  • the managing organisation
  • the tenant or account
  • the device agent
  • the operator account
  • session and command history
  • deployment records
  • configuration changes
  • authentication and recovery events.

A single RMM platform may control many devices. This makes tenant, device and account identifiers important.

Do not assume that the managed service provider or named technician performed the suspicious action. Their account may have been compromised, shared or automated.

Likewise, an RMM command may be legitimate maintenance unless timing, target, content and authority indicate otherwise.

Preserve the provider-held logs quickly because retention and access may depend on licence or contract.

Where many customers are affected, the RMM environment itself may be the point of compromise.

Where a provider supports audit exports, obtain the native export rather than relying only on screenshots. Product dashboards may summarise several actions and may omit command detail or historical context.

Operational takeaway

Map the RMM tenant, operator account, managed devices and command history, and distinguish legitimate administration from misuse of trusted management access.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.