+34 900 840 407
support@cytomic.ai

Advanced EPDR/EDR identifies legitimate ScreenConnect installations as malware

Related Products_
  • Advanced EPDR
  • Advanced EDR
Description_

Remote monitoring and management (RMM) tools, including ScreenConnect, are increasingly abused by threat actors to establish remote access and maintain persistence on compromised systems.

To reduce the risk associated with unauthorized remote access tools, Advanced EPDR/EDR introduced a detection rule to identify and block ScreenConnect installations initiated outside of approved corporate deployment mechanisms.

As a result, users will no longer be able to download and install ScreenConnect directly from the Internet or other non-approved sources.

What will be blocked?

  • Manual ScreenConnect installations performed by end users.
  • ScreenConnect installers downloaded from external websites or unapproved sources.
  • Installation methods that do not originate from authorized corporate software deployment tools.

What is allowed?

  • ScreenConnect installations deployed through approved corporate software distribution platforms and IT-managed deployment processes.
Solution_

False Positives

Legitimate installations launched directly from a web browser when the connection source is identified as external could be blocked. If your organization relies on this installation method, you can enable an exception in the Advanced EPDR/EDR console in either of these locations:

  • Incident details page
  • Malware detection details page

Enable Exceptions from the Incident Details Page

To allow execution of ScreenConnect when it is identified as an incident, in the console:

  1. Select Status > Security.
  2. Click the Incident Status tile.
  3. Filter the list of incidents to show only Malicious File incidents.
  4. From the list, select the incident that includes the signal detection you want to allow to run.
  5. In the Signals pane, select the signal you want to exclude (BHV/RMM.ScrCon).
  6. Click  . Select Do Not Detect Again.
  7. In the confirmation dialog box, click Do Not Detect Again.
    The rule removes all signals that meet the criteria defined in the rule. Signal exceptions show in the Detected Items Allowed by Administrator tile and list. The Incidents list shows the status of automatically deleted signals as Automatically Closed.

Enable Exceptions from Malware Detections Details Page

To allow execution of ScreenConnect when it is classified as malware, in the management UI or console:

  1. Select Status > Security.
  2. Click the Malware Activity tile.
  3. From the list, select the threat that you want to allow to run (BHV/RMM.ScrCon)..
  4. On the details page, click the info icon next to the action.
    A pop-up dialog box describes the action taken by  Advanced EPDR/EDR.
  5. Click Do Not Detect Again.

For more information, go to Allow Blocked Items to Run in the online help.