Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

RansomHub – Unapproved RMM Tool Install on Server Assets

Ransomhub Command and Control Sentinel
MITRE ATT&CK
Remote Access Tools
Data Source
DeviceProcessEvents
Date Added
2026-07-23
Last Updated
2026-07-23
Source
ransomware.live group_tools dataset (ransomhub)
What This Detects
RansomHub affiliates rely heavily on legitimate RMM software (ScreenConnect, Atera, N-Able, TightVNC, Splashtop) for persistent C2. Flags first-seen installs of these tools on servers – tune the DeviceName filter/allowlist to your own naming convention and approved RMM baseline.
Query
DeviceProcessEvents
| where Timestamp > ago(1d)
| where FileName has_any ("screenconnect.clientservice.exe","aterasagent.exe","ateraagent.exe","n-central.exe","splashtop.exe","tightvnc.exe","anydesk.exe")
| where DeviceName has_any ("srv","dc","sql","fs")  // adjust to your server naming convention
| project Timestamp, DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName, AccountName

Hunting queries are starting points for threat hunting & detection engineering — validate table/column names against your own workspace schema and tune thresholds before turning any of these into a production alert rule.