RMM Tool Abuse for Ransomware Lateral Movement
This rule detects the execution of known Remote Monitoring and Management (RMM) or remote access tools on devices where they have not been observed within the previous 90-day baseline (excluding the most recent 7 days). This pattern is often indicative of an adversary introducing unauthorized remote access capabilities for persistence or lateral movement.
Microsoft Sentinel (KQL)

