Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is remote monitoring and management software?

Remote monitoring and management software - usually shortened to RMM - allows an organisation or service provider to administer many devices from a central platform. It is normal enterprise tooling, but compromised RMM access can give an offender trusted, large-scale control.

An RMM platform may deploy software, run commands, patch devices, transfer files, open remote shells or screens, schedule tasks and collect device inventories. Those capabilities explain why both administrators and offenders value it.

PlatformRMM serviceHolds the management environment.
TenantCustomer or provider spaceDefines which managed estate is in scope.
Operator / automationAccount, policy or jobExplains what authority issued the action.
EndpointManaged deviceShows what actually executed locally.

Map the management hierarchy

Do not stop at finding an agent on one endpoint. Identify the platform, managing organisation, tenant, device identifier and operator account. Then obtain session, command, deployment, authentication and configuration records that connect those layers.

This mapping matters because one tenant can manage many customers and devices. A command appearing locally as authorised management activity may originate from a compromised operator account, an automated policy or a malicious upstream job. The named technician or provider should not be treated as the actor without evidence of account control.

Compare suspicious commands with normal maintenance windows, approved jobs and targeted devices. Native exports are preferable to dashboard screenshots because dashboards may summarise actions, omit command detail or change as retention rolls forward.

Consider the provider as an access route

An offender might abuse an existing agent, deploy a new one or compromise the service provider itself. If several customer environments show related activity, the RMM tenant or provider identity system may be the common point of entry.

Provider-held data may depend on subscription and retention settings, so preserve it promptly with precise tenant, account, device and time identifiers. Keep platform compromise, operator-account compromise and deliberate technician action as separate hypotheses until the records distinguish them.

Key takeaway

Treat RMM as a management hierarchy: connect tenant, operator, job and endpoint evidence before deciding whether an action was routine administration or misuse of trusted access.

Reference: CIM-083Cyber Incidents & Offender Methods