Suspicious Child Processes Spawned by LogMeIn

Rule Info

Name
Suspicious Child Processes Spawned by LogMeIn
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects suspicious child processes spawned by LogMeIn process. This could indicate the presence of a remote management tool (RMM) or remote access tool (RAT) on the system. Threat actors may use these tools to gain unauthorized access to systems and networks and perform malicious activities.
Reference
Internal Research
Date
2026-02-11 00:00:00
Modified
None
Id
5800bab6-b260-418b-9483-3788172e533a
Tags
attack.command-and-control attack.t1219.002
Type
Nextron Sigma feed only (private)

Rule History