Most Significant TTP 2026: RMM Tool Silent Install Shortly After Browser-Spawned Script Host
Detects the silent installation or execution of Remote Monitoring and Management (RMM) tools when launched by script hosts (wscript.exe, mshta.exe, powershell.exe) which themselves were spawned by browser processes or explorer.exe. This pattern is characteristic of social engineering delivery chains, such as 'ClickFix', where a user is tricked into executing a script that subsequently fetches and runs RMM payloads for persistent remote access.
Sigma

