Detecting Stolen API Key: Sentinel and GuardDuty Detections
Retrospective: this article looks back at events from December 2024, written in 2026 with the benefit of hindsight.
Stolen API keys for remote support tools grant access without user sign-ins. These detections focus on unusual key use and remote sessions.
Signals worth watching
- API calls from IP addresses outside your expected ranges.
- Password resets of local accounts within the remote support tool.
- Remote sessions started outside business hours or without associated tickets.
- Remote sessions to unusual numbers of endpoints.
- New remote support agents installed on endpoints unexpectedly.
- Vendor security notices.
Where the data lives
- Remote support tool audit logs (forwarded via API or syslog to your SIEM).
- Endpoint telemetry showing remote support processes and child processes.
- Network logs for connections to vendor infrastructure.
A starting query
Remote support tool processes spawning command shells on endpoints:
DeviceProcessEvents
| where InitiatingProcessFileName has_any ("bomgar", "beyondtrust", "ScreenConnect", "TeamViewer", "AnyDesk", "Splashtop")
| where FileName in~ ("cmd.exe", "powershell.exe", "pwsh.exe")
| project Timestamp, DeviceName, AccountName, InitiatingProcessFileName, ProcessCommandLine
Remote support legitimately runs commands; compare against ticket records and technician schedules.
Unexpected installation
DeviceFileEvents
| where FileName has_any ("ScreenConnect", "AnyDesk", "TeamViewer")
| where ActionType == "FileCreated"
| project Timestamp, DeviceName, FolderPath, InitiatingProcessAccountName
Response
- Revoke and rotate API keys.
- Terminate active sessions.
- Review session logs for actions taken.
- Investigate endpoints accessed.
- US Treasury Breached via a BeyondTrust API Key (Dec 2024) Incident Teardowns
- How to Inventory and Rotate API Keys for Remote Support Tools How-To & Hardening
- CIO Brief: Remote Support Vendors and Nation-State Risk CIO Briefings