External Remote Services, Technique T1133 - Enterprise | MITRE ATT&CK®
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.[1] Access to Valid Accounts to use the service is often a requirement, which could be obtained through credential pharming or by obtaining the credentials from users after compromising the enterprise network.[2] Access to remote services may be used as a redundant or persistent access mechanism during an operation. Access may also be gained through an exposed service that doesn’t require authentication. In containerized environments, this may include an exposed Docker API, Kubernetes API server, kubelet, or web application such as the
External Remote Services, Technique T1133 - Enterprise | MITRE ATT&CK® ATT&CKcon 7.0 is coming October 27-28, 2026. Learn more about ATT&CKcon 7.0 . Home Techniques Enterprise External Remote Services External Remote Services Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these s
related reading
- Remote Services, Technique T1021 - Enterprise | MITRE ATT&CK®attack.mitre.org
- D3FEND Matrix | MITRE D3FEND™d3fend.mitre.org
- Valid Accounts, Technique T1078 - Enterprise | MITRE ATT&CK®attack.mitre.org
- Initial Access, Tactic TA0001 - Enterprise | MITRE ATT&CK®attack.mitre.org
- Hacker wipes Romania's entire land registry databasenews.risky.biz
- Shodanshodan.io
- PerfectData Software Abuse and Account Takeover Risksdarktrace.com
- 【資安週報】2022年7月11日到7月15日ithome.com.tw
- Persistence, Tactic TA0003 - Enterprise | MITRE ATT&CK®attack.mitre.org
- Common Oauth Apps Used in Business Email Compromise - Syne's Cyber Cornercybercorner.tech
- Email Compromise To Mass Phishing Campaigndarktrace.com
- Firewalls | Computer Securitytextbook.cs161.org