RMM Tool Hunt Queries
Analytics to hunt for RMM tool usage in the environment
TA0011: Command and Control T1219: Remote Access Software T1133: External Remote Services
DeviceProcessEvents
| where (ProcessVersionInfoProductName contains "SplashTop" and ProcessVersionInfoFileDescription contains "SplashTop") or (ProcessVersionInfoOriginalFileName contains "SplashTop")