Multi-CloudDetection & ResponseRetrospectives

Detecting MSP Supply Chain Attack: Sentinel and GuardDuty Detections

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2021, written in 2026 with the benefit of hindsight.

MSP supply-chain attacks use legitimate management tools and access. Detection focuses on unusual use of those tools and partner accounts.

Signals worth watching

  • Mass software deployment or script execution via RMM tools outside change windows.
  • RMM agents spawning unusual processes (for example, encoded PowerShell, disabling security tools).
  • Partner (delegated admin) sign-ins from new locations or at unusual times.
  • Partner accounts making high-impact changes: role assignments, Conditional Access, mailbox permissions, app registrations.
  • Security tools being disabled on many devices simultaneously.

Where the data lives

  • Defender for Endpoint: process and file events showing RMM agent activity.
  • Entra ID sign-in and audit logs: partner access appears with the partner's tenant information.
  • RMM platform logs if you have access.

A starting query

Processes spawned by common RMM agents that disable protections:

DeviceProcessEvents
| where InitiatingProcessFileName has_any ("AgentMon", "Kaseya", "ScreenConnect", "NinjaRMM", "AteraAgent")
| where ProcessCommandLine has_any ("Set-MpPreference", "DisableRealtimeMonitoring", "vssadmin delete", "bcdedit")
| project Timestamp, DeviceName, InitiatingProcessFileName, ProcessCommandLine

Adjust process names to the RMM tools in your environment.

Response

  1. Contact the MSP immediately through a known channel.
  2. If compromise is suspected, disable the MSP's access (RMM agents and partner relationships).
  3. Isolate affected devices.
  4. Investigate actions performed by the partner identities.
detect msp supply chain attackKaseya2021

More on this story