M ManySignal
T1021 MITRE ATT&CK

T1021 Remote Services — Detection & Response

Adversaries may use Valid Accounts to log into a service specifically designed to accept remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user.

Coverage at a glance

Detections shipped
4
Avg. verdict time
< 5 min
Data sources
4+

Threat context

How adversaries use T1021 Remote Services — Detection & Response

Adversaries may use Valid Accounts to log into a service specifically designed to accept remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user.

RDP (T1021.001) and SMB (T1021.002) lateral movement are standard techniques in Windows enterprise environments. Attackers use Pass-the-Hash (PtH) or Pass-the-Ticket (PtT) attacks to authenticate to remote systems without knowing the cleartext password after credential dumping. In cloud environments, T1021.007 and T1021.008 involve using compromised cloud credentials or SSH keys to access VMs and cloud services directly — bypassing perimeter controls entirely.

Detections ManySignal ships

Ready-to-deploy detection rules

Rule name Severity Data source

Pass-the-Hash Lateral Movement — NTLM authentication without interactive logon

Authentication using NTLM hash without a preceding interactive or network credential entry, consistent with Pass-the-Hash.

Critical Windows Event Log / CrowdStrike

RDP Login to Atypical Host — User RDPs to host they have not previously accessed

A user authenticates via RDP to a server that is not in their normal access pattern.

High Windows Event Log

AWS Systems Manager Session to Production — SSM session started by non-ops user

An AWS Systems Manager Session Manager connection is started by an IAM principal that does not normally access production instances.

High AWS CloudTrail

SMB Admin Share Access — Connection to ADMIN$, C$, or IPC$ share

Access to administrative SMB shares (ADMIN$, C$) from a workstation, commonly used for lateral movement tools like PsExec.

High Windows Event Log / Network Flow

T1021 Remote Services — Detection & Response: frequently asked questions

How does ManySignal detect Pass-the-Hash when the hash was obtained externally?

ManySignal detects PtH by the authentication event pattern on the target host: NTLM network authentication (logon type 3) to administrative shares without a corresponding interactive logon on the source. This pattern is highly anomalous for normal user activity and generates high-confidence alerts.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.