Remote Desktop AppAware tools
Bobby King
One of our clients had a successful social engineering attack that used the Microsoft QuickAssist app to allow a malicious actor to do a few things. That were stopped pretty quickly with no exfiltration of data, for those of you keeping score.
Having this feature would be great at preventing attacks like these. We would allow DNS resolution only for the apps we actually support and block the rest. Chrome Remote Desktop is one that is easily installed, along with many of the others.
E
Eli B
To note if including screen connect we would need a way to exclude an instance