Skip to main content
Skip to main content
Published Nov 04, 2020 | Updated Jan 06, 2024

VirTool:Win32/RemoteExec

Detected by Microsoft Defender Antivirus

Aliases: No associated aliases

Summary

This is a detection of a hack tool used for remote shell launch. This may cover variants of the open-source software RemCom, which has been integrated into various malware and attacks.

Tamper protection should be turned on in Microsoft Defender for Endpoint to help prevent antivirus tampering and misconfiguration by malicious apps and actors. Conditional Access policies also help in evaluating and enforcing security policies every time a user attempts to sign in. 

You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.

Follow us