Ticket Discounts for Cyber Events

GET ALERTS!

Recommended Event: Gartner Security & Risk Management Summit | 22 - 24 Sep 2026

Trusted Tools in Untrusted Hands: RMM Abuse Hiding in Plain Sight

Solution Category Operations
Type Webinar
Organization Huntress
Event Format Company Webinar

Webinar Description

Key Takeaways

  • Examines the growing threat of Remote Monitoring and Management tool abuse, which has increased 277% year-over-year
  • Addresses how attackers exploit legitimate IT administration tools to evade detection and deliver ransomware
  • Designed for IT managers, security analysts, SOC teams, MSP staff and threat hunters
  • Covers lateral movement, privilege escalation and techniques for disabling security controls
  • Provides actionable mitigation strategies that extend beyond visibility improvements

Introduction

Trusted Tools in Untrusted Hands: RMM Abuse Hiding in Plain Sight is a cybersecurity webinar examining how Remote Monitoring and Management tools have become a favoured attack vector for threat actors. Organised by Huntress, the session targets IT and security professionals responsible for endpoint protection, threat detection and network defence. The webinar addresses a critical operational security challenge: the tools organisations rely on for legitimate remote administration are increasingly being weaponised to bypass security controls, move laterally through networks and deploy ransomware—all while appearing as normal administrative activity.

About This Event

This 60-minute virtual webinar runs across two sessions to accommodate different global time zones. The format includes interactive elements such as live Q&A, polls and chat functionality, enabling participants to engage directly with the presenters. The session is structured to deliver both technical depth and practical guidance, moving beyond theoretical discussion to provide concrete defensive strategies.

The Growing Threat of RMM Tool Exploitation

Remote Monitoring and Management tools occupy a unique position in enterprise environments. Designed to give IT teams efficient remote access for system administration, software deployment and troubleshooting, these tools operate with elevated privileges and broad network access by design. This legitimate functionality creates an attractive target for attackers seeking to blend malicious activity with normal operations.

The webinar highlights a stark statistic: RMM abuse has jumped 277% year-over-year. This dramatic increase reflects a broader shift in attacker methodology toward living-off-the-land techniques, where adversaries leverage existing tools rather than deploying custom malware that might trigger security alerts. When an attacker gains access to an RMM platform, they inherit the same capabilities IT administrators use daily—executing commands, transferring files, modifying configurations and accessing endpoints across the network.

Attack Techniques and Ransomware Delivery

The session explores specific attack techniques that exploit RMM infrastructure. Lateral movement becomes significantly easier when attackers can use trusted administrative channels rather than deploying additional tools that might be flagged by endpoint detection systems. Privilege escalation often follows naturally, as RMM tools typically operate with administrative credentials.

Perhaps most concerning is the use of RMM tools to disable security controls before launching the primary attack. Attackers can leverage administrative access to stop endpoint protection services, modify security policies or exclude malicious payloads from scanning—creating what the webinar describes as the perfect setup for ransomware deployment. Because these actions occur through legitimate management channels, they may not generate the alerts that similar actions through other vectors would trigger.

Who Should Attend

The webinar is designed for technical professionals with responsibility for endpoint security and threat detection. This includes IT managers, security analysts, SOC analysts, IT directors, detection engineers and threat hunters working within internal IT departments or managed service providers. The content is particularly relevant for MSP staff, given that managed service providers often deploy RMM tools across multiple client environments, creating concentrated risk if those platforms are compromised.

Organisations across sectors with significant IT infrastructure—including education, finance, healthcare, manufacturing and government—will find the content applicable to their security operations. The session targets mid-level to senior technical staff and decision-makers who can influence security architecture and operational procedures.

Moving Beyond Visibility

A central theme of the webinar is that improved visibility alone cannot address RMM abuse. While detection capabilities matter, the session emphasises closing operational security gaps through a combination of architectural controls, policy enforcement and procedural changes. Attendees can expect actionable guidance on hardening RMM deployments, monitoring for abuse indicators and implementing controls that limit the blast radius when compromise occurs.