Skip to content

About

Map abused RMM / ScreenConnect installers to relay hosts and campaign clusters

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

1 Commit

Folders and files

Repository files navigation

RMM Abuse Map

License: MIT Python 3.10+

Map abused RMM / ScreenConnect installers to relay hosts and campaign clusters.

Legitimate remote monitoring tools (ScreenConnect / ConnectWise Control, and friends) are heavily abused as phishing second stages. The relay host often sits in plain sight on the client command line (h=…) or in /Bin/ installer URLs — but defenders lack a small, open tool to parse → cluster → pivot.

Built by Cipher Cortex · Case methodology from Intercept Cell.


Quick start

git clone https://github.com/CipherCortex/rmm-abuse-map.git
cd rmm-abuse-map
pip install -e .

# Parse sample command lines and cluster by relay
rmm-abuse-map parse -f fixtures/sample_cmdlines.txt --cluster
rmm-abuse-map parse -s 'ScreenConnect.Client.exe "?e=Access&h=evil.example&p=443"'

What it extracts

Field Source
relay_host h= query/cmdline param, or hostname of /Bin/ MSI URL
relay_port p=
mode e= (Access / Support / Guest / …)
urls / msi_names Embedded HTTP(S) and .msi names
binary_hint ScreenConnect.Client.exe / Control client

Related tools

Tool Role
hijacked-infra-hunt Aged / compromised web infra hosting lures
lure-lineage Fingerprint the HTML that drops the MSI
evidence-pack Hash-verified capture of installers & pages

License

MIT © Cipher Cortex

About

Map abused RMM / ScreenConnect installers to relay hosts and campaign clusters

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages