Adversaries may leverage remote services to move between assets and network segments. These services are often used to allow operators to interact with systems remotely within the network, some examples are RDP, SMB, SSH, and other similar mechanisms. (Citation: Blake Johnson, Dan Caban, Marina Krotofil, Dan Scali, Nathan Brubaker, Christopher Glyer December 2017) (Citation: Dragos December 2017) (Citation: Joe Slowik April 2019) Remote services could be used to support remote access, data transmission, authentication, name resolution, and other remote functions. Further, remote services may be necessary to allow operators and administrators to configure systems within the network from their engineering or management workstations. An adversary may use this technique to access devices which may be dual-homed (Citation: Blake Johnson, Dan Caban, Marina Krotofil, Dan Scali, Nathan Brubaker, Christopher Glyer December 2017) to multiple network segments, and can be used for [Program Download](https://attack.mitre.org/techniques/T0843) or to execute attacks on control devices directly through [Valid Accounts](https://attack.mitre.org/techniques/T0859). Specific remote services (RDP & VNC) may be a precursor to enable [Graphical User Interface](https://attack.mitre.org/techniques/T0823) execution on devices such as HMIs or engineering workstation software. Based on incident data, CISA and FBI assessed that Chinese state-sponsored actors also compromised various authorized remote access channels, including systems designed to transfer data and/or allow access between corporate and ICS networks. (Citation: CISA AA21-201A Pipeline Intrusion July 2021)

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is related to Control Server
is related to Switch
is related to Distributed Control System (DCS) Controller
is related to Application Server
is related to Human-Machine Interface (HMI)
is related to Virtual Private Network (VPN) Server
is related to Data Historian
is related to Jump Host
is related to Data Gateway
is part of Lateral Movement
is blocked by Software Process and Device Authentication
is blocked by Authorization Enforcement
is blocked by Network Segmentation
is blocked by Password Policies
is blocked by Human User Authentication
is blocked by Network Allowlists
is blocked by Detection of Remote Services
is blocked by User Account Management
is blocked by Access Management
is blocked by Filter Network Traffic
Impressum German English