Remote Access Tool Credential Files

Detects passwords and credentials stored in remote access configuration files including RDCMan .rdg files (logonCredentials blocks), mRemoteNG confCons.xml (Node Password attributes), and OpenVPN .ovpn files with embedded auth directives. MobaXterm .ini files are a Snaffler filename target only — passwords are stored obfuscated (proprietary XOR cipher) with no plaintext fingerprint detectable by content regex. Mirrors Snaffler rules KeepRemoteAccessConfByExtension and KeepRemoteAccessConfByName.

Type
regex
Engine
boost_regex
Confidence
high
Confidence justification
High confidence: RDCMan logonCredentials/password and mRemoteNG Node Password attribute patterns are highly specific to remote access management tools. The OpenVPN directive form is weak and gated strictly with contextual evidence.
Jurisdictions
global
Regulations
Criminal Code Act 1995 (Cth)
Frameworks
CIS Controls, ISO 27001, NIST CSF
Data categories
credentials, security, network
Scope
specific
Platform compatibility
Purview: Compatible, GCP DLP: Compatible, Macie: Compatible, Zscaler: Compatible, Palo Alto: Compatible, Netskope: Compatible

Pattern

<logonCredentials[\s\S]{0,150}<password>[\s\S]{0,200}</password>

Corroborative evidence keywords

RDCMan, RDGManager, mRemoteNG, OpenVPN, logonCredentials, confCons, rdg, ovpn

Proximity: 300 characters

Should match

Should not match

Known false positives

Collections