Rule Info
Name
Suspicious Child Processes Spawned by TeamViewer
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects suspicious child processes spawned by TeamViewer process. This could indicate the presence of a remote management tool (RMM) or remote access tool (RAT) on the system.
Threat actors may use these tools to gain unauthorized access to systems and networks and perform malicious activities.
Reference
Internal Research
Date
2026-02-11 00:00:00
Modified
None
Id
1ff88fd8-3f07-4b97-8b44-93153bd1f805
Tags
attack.command-and-control attack.t1219.002
Type
Nextron Sigma feed only (private)
