Detecting MSP Supply Chain Attack: Sentinel and GuardDuty Detections
Retrospective: this article looks back at events from July 2021, written in 2026 with the benefit of hindsight.
MSP supply-chain attacks use legitimate management tools and access. Detection focuses on unusual use of those tools and partner accounts.
Signals worth watching
- Mass software deployment or script execution via RMM tools outside change windows.
- RMM agents spawning unusual processes (for example, encoded PowerShell, disabling security tools).
- Partner (delegated admin) sign-ins from new locations or at unusual times.
- Partner accounts making high-impact changes: role assignments, Conditional Access, mailbox permissions, app registrations.
- Security tools being disabled on many devices simultaneously.
Where the data lives
- Defender for Endpoint: process and file events showing RMM agent activity.
- Entra ID sign-in and audit logs: partner access appears with the partner's tenant information.
- RMM platform logs if you have access.
A starting query
Processes spawned by common RMM agents that disable protections:
DeviceProcessEvents
| where InitiatingProcessFileName has_any ("AgentMon", "Kaseya", "ScreenConnect", "NinjaRMM", "AteraAgent")
| where ProcessCommandLine has_any ("Set-MpPreference", "DisableRealtimeMonitoring", "vssadmin delete", "bcdedit")
| project Timestamp, DeviceName, InitiatingProcessFileName, ProcessCommandLine
Adjust process names to the RMM tools in your environment.
Response
- Contact the MSP immediately through a known channel.
- If compromise is suspected, disable the MSP's access (RMM agents and partner relationships).
- Isolate affected devices.
- Investigate actions performed by the partner identities.
- Kaseya VSA (July 2021): Ransomware Delivered Through an MSP Tool Incident Teardowns
- How to Restrict and Monitor MSP Access to Your Microsoft 365 Tenant How-To & Hardening
- CIO Brief: Your MSP Has Admin Rights — Are You Watching? CIO Briefings