We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
VirTool:Win32/RemoteExec
Aliases: No associated aliases
Summary
This is a detection of a hack tool used for remote shell launch. This may cover variants of the open-source software RemCom, which has been integrated into various malware and attacks.
Tamper protection should be turned on in Microsoft Defender for Endpoint to help prevent antivirus tampering and misconfiguration by malicious apps and actors. Conditional Access policies also help in evaluating and enforcing security policies every time a user attempts to sign in.
You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.