RATs Race: Detecting remote access tools beyond pattern-based indicators

Alex Teixeira
11 min readApr 26

This is a post to highlight the importance of rich telemetry and how it serves well for strengthening alert signals when coupling static pattern with behavioral & anomaly based indicators to detect RAT and RMM tools.

TL;DR: for practical detection engineering, skip to "Tracking Patterns".

Midjourney's take on a Cyber RATs Army


I design and build threat detection models and triage/hunting interfaces for Enterprise #SecOps teams #DetectionEngineering http://opstune.com

