Why App Control Fails Most Teams and How Managed ESPM Fixes It
Cybersecurity Classified by Officially
Attackers increasingly abuse legitimate RMM tools, turning phishing clicks into persistent access.
Traditional app control is effective but too complex and resource-intensive for most lean IT teams.
Huntress Managed ESPM brings pragmatic, managed app control, starting with blocking rogue RMMs, within reach of the 99% who can't run a full app control program themselves.
Suppose an employee gets an email about a "pay increase" meeting. The link looks routine enough, the page feels familiar, and they're understandably excited. Unfortunately, it's a phishing email. With one click, they download and run a malicious attachment.
Behind the scenes, that single action quietly installs a Remote Monitoring and Management (RMM) tool: LogMeIn Resolve. This is the kind of thing that keeps defenders up at night, because the attacker now has persistent access into their environment. It didn't even require a novel exploit. LogMeIn Resolve is a legitimate tool that's regularly used by IT admins, so the attacker can hide in plain sight.
This isn't a hypothetical example. It's a real incident that happened recently. Thankfully, the device was secured by Huntress Managed Endpoint Detection and Response (EDR), and the combination of endpoint telemetry and a 24/7 Security Operations Center (SOC) made the difference. The activity was detected, investigated, and contained before the attacker could turn that foothold into something far worse. That's a success story.
What if that remote access tool had never been allowed to run in the first place?
Especially since RMM-based attacks increased 277% over the last year.
Huntress found in 2025, RMM-based attacks increased 277% from 2024
Proactively blocking unknown, unwanted, and malicious tools from running is exactly what application control promises to do. But unfortunately, most solutions that offer this capability have been designed with enterprise teams and budgets in mind, leaving MSPs and lean IT teams underprotected.
This is an extract. The publication continues at the source.
Read the original at the source: https://www.huntress.com/blog/managed-espm-app-control-rmm-protection
Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Huntress — imported from official source
- Official source
- https://www.huntress.com/blog/rss.xml RSS
- Imported
- September 20, 2026 19:55
- Versions
- 1 recorded
- Identity
https://www.huntress.com/blog/managed-espm-app-control-rmm-protection