Map abused RMM / ScreenConnect installers to relay hosts and campaign clusters.
Legitimate remote monitoring tools (ScreenConnect / ConnectWise Control, and friends) are heavily abused as phishing second stages. The relay host often sits in plain sight on the client command line (h=…) or in /Bin/ installer URLs — but defenders lack a small, open tool to parse → cluster → pivot.
Built by Cipher Cortex · Case methodology from Intercept Cell.
git clone https://github.com/CipherCortex/rmm-abuse-map.git
cd rmm-abuse-map
pip install -e .
# Parse sample command lines and cluster by relay
rmm-abuse-map parse -f fixtures/sample_cmdlines.txt --clusterrmm-abuse-map parse -s 'ScreenConnect.Client.exe "?e=Access&h=evil.example&p=443"'| Field | Source |
|---|---|
relay_host |
h= query/cmdline param, or hostname of /Bin/ MSI URL |
relay_port |
p= |
mode |
e= (Access / Support / Guest / …) |
urls / msi_names |
Embedded HTTP(S) and .msi names |
binary_hint |
ScreenConnect.Client.exe / Control client |
| Tool | Role |
|---|---|
| hijacked-infra-hunt | Aged / compromised web infra hosting lures |
| lure-lineage | Fingerprint the HTML that drops the MSI |
| evidence-pack | Hash-verified capture of installers & pages |
MIT © Cipher Cortex