Quick Assist Full Control Sharing Mode Enabled

Identifies when Microsoft Quick Assist sharing mode is set to FullControl on a Windows host. This grants the remote helper full interactive control of the target device and may indicate IT help desk fraud, unauthorized remote access, or lateral movement preparation.

Elastic rule (View on GitHub)

  1[metadata]
  2creation_date = "2026/06/21"
  3integration = ["system", "windows"]
  4maturity = "production"
  5updated_date = "2026/09/18"
  6
  7[rule]
  8author = ["Elastic"]
  9description = """
 10Identifies when Microsoft Quick Assist sharing mode is set to FullControl on a Windows host. This grants the remote
 11helper full interactive control of the target device and may indicate IT help desk fraud, unauthorized remote access,
 12or lateral movement preparation.
 13"""
 14from = "now-9m"
 15index = ["logs-system.application*", "logs-windows.forwarded*", "winlogbeat-*"]
 16language = "kuery"
 17license = "Elastic License v2"
 18name = "Quick Assist Full Control Sharing Mode Enabled"
 19references = [
 20    "https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/",
 21	"https://attack.mitre.org/software/S1209/"
 22]
 23risk_score = 47
 24rule_id = "1b1b4236-175f-4863-89f7-7f0d2da0f0e8"
 25severity = "medium"
 26tags = [
 27    "Domain: Endpoint",
 28    "OS: Windows",
 29    "Use Case: Threat Detection",
 30    "Tactic: Command and Control",
 31    "Tactic: Lateral Movement",
 32    "Data Source: Windows Application Event Logs",
 33    "Resources: Investigation Guide",
 34    "Noise: Unknown",
 35    "Performance: Normal",
 36    "Threat: Remote Management Tool Abuse",
 37    "Rule Type: Custom Query (KQL)",
 38    "Platform: Windows",
 39]
 40timestamp_override = "event.ingested"
 41type = "query"
 42
 43query = '''
 44host.os.type:windows and winlog.channel:"Application" and event.provider:"Quick Assist" and event.code:"0" and
 45  winlog.event_data.param1:(*FullControl* and *setsharingmode*)
 46'''
 47
 48note = """## Triage and analysis
 49
 50### Investigating Quick Assist Full Control Sharing Mode Enabled
 51
 52Microsoft Quick Assist is a built-in remote support tool. When a sharer grants FullControl, the helper can interact with
 53the desktop as if physically present. Adversaries abuse Quick Assist in help desk fraud and social engineering to gain
 54interactive access without deploying separate remote access software.
 55
 56Quick Assist logs these transitions in the Windows Application log under the Quick Assist provider. A `setsharingmode`
 57command with sharing mode `FullControl` is written to `winlog.event_data.param1`, often alongside a JSON payload that
 58includes `"result":"true"` when consent is granted.
 59
 60#### Possible investigation steps
 61
 62- Review `winlog.event_data.param1` and any related Quick Assist Application log events around `@timestamp` for
 63  `beginsharing`, `setsharingmode`, and `endsharing` commands to reconstruct the session timeline.
 64- Identify the local user on `host.id` who initiated or approved the session and determine whether Quick Assist use is
 65  expected for that user, host role, or business unit.
 66- Correlate with process telemetry for `QuickAssist.exe` on the same host and timeframe, including parent process,
 67  command line, and code signature details when available.
 68- Check for related alerts on the same `host.id` or `user.id`, such as credential access, defense evasion, or
 69  additional remote access activity during or shortly after the session.
 70- If the host is a server or privileged workstation, determine whether any follow-on actions occurred during the
 71  FullControl window, such as new logons, service creation, or lateral movement.
 72
 73### False positive analysis
 74
 75- IT help desk, managed service providers, and internal support teams legitimately use Quick Assist with FullControl
 76  during approved troubleshooting. Confirm the session aligns with an open ticket, known support staff, and expected
 77  host and user pairings before closing as benign.
 78- Before creating an exception, anchor it on the minimum confirmed workflow: `host.id`, `user.id`, and recurring
 79  support patterns. Avoid broad exceptions on the Quick Assist provider alone.
 80
 81### Response and remediation
 82
 83- If confirmed malicious, terminate the Quick Assist session, isolate the affected host when feasible, and reset
 84  credentials for accounts used or exposed during the session.
 85- Preserve Application log events containing `winlog.event_data.param1` and related Quick Assist telemetry before
 86  remediation.
 87- Review whether Quick Assist should remain enabled organization-wide or be restricted via policy for high-value hosts.
 88- Hunt for additional hosts where the same remote helper pattern or concurrent Quick Assist FullControl sessions
 89  occurred."""
 90
 91setup = """## Setup
 92
 93Windows Application event log collection must be enabled via the Elastic Agent System integration to ingest Application log events.
 94"""
 95
 96[rule.investigation_fields]
 97field_names = [
 98    "@timestamp",
 99    "host.id",
100    "host.name",
101    "user.id",
102    "user.name",
103    "event.provider",
104    "event.code",
105    "winlog.event_id",
106    "winlog.event_data.param1",
107]
108
109[[rule.threat]]
110framework = "MITRE ATT&CK"
111
112[[rule.threat.technique]]
113id = "T1219"
114name = "Remote Access Tools"
115reference = "https://attack.mitre.org/techniques/T1219/"
116
117[rule.threat.tactic]
118id = "TA0011"
119name = "Command and Control"
120reference = "https://attack.mitre.org/tactics/TA0011/"
121
122[[rule.threat]]
123framework = "MITRE ATT&CK"
124
125[[rule.threat.technique]]
126id = "T1021"
127name = "Remote Services"
128reference = "https://attack.mitre.org/techniques/T1021/"
129
130[rule.threat.tactic]
131id = "TA0008"
132name = "Lateral Movement"
133reference = "https://attack.mitre.org/tactics/TA0008/"

Triage and analysis

Investigating Quick Assist Full Control Sharing Mode Enabled

Microsoft Quick Assist is a built-in remote support tool. When a sharer grants FullControl, the helper can interact with the desktop as if physically present. Adversaries abuse Quick Assist in help desk fraud and social engineering to gain interactive access without deploying separate remote access software.

Quick Assist logs these transitions in the Windows Application log under the Quick Assist provider. A setsharingmode command with sharing mode FullControl is written to winlog.event_data.param1, often alongside a JSON payload that includes "result":"true" when consent is granted.

Possible investigation steps

  • Review winlog.event_data.param1 and any related Quick Assist Application log events around @timestamp for beginsharing, setsharingmode, and endsharing commands to reconstruct the session timeline.
  • Identify the local user on host.id who initiated or approved the session and determine whether Quick Assist use is expected for that user, host role, or business unit.
  • Correlate with process telemetry for QuickAssist.exe on the same host and timeframe, including parent process, command line, and code signature details when available.
  • Check for related alerts on the same host.id or user.id, such as credential access, defense evasion, or additional remote access activity during or shortly after the session.
  • If the host is a server or privileged workstation, determine whether any follow-on actions occurred during the FullControl window, such as new logons, service creation, or lateral movement.

False positive analysis

  • IT help desk, managed service providers, and internal support teams legitimately use Quick Assist with FullControl during approved troubleshooting. Confirm the session aligns with an open ticket, known support staff, and expected host and user pairings before closing as benign.
  • Before creating an exception, anchor it on the minimum confirmed workflow: host.id, user.id, and recurring support patterns. Avoid broad exceptions on the Quick Assist provider alone.

Response and remediation

  • If confirmed malicious, terminate the Quick Assist session, isolate the affected host when feasible, and reset credentials for accounts used or exposed during the session.
  • Preserve Application log events containing winlog.event_data.param1 and related Quick Assist telemetry before remediation.
  • Review whether Quick Assist should remain enabled organization-wide or be restricted via policy for high-value hosts.
  • Hunt for additional hosts where the same remote helper pattern or concurrent Quick Assist FullControl sessions occurred.

References

Related rules

to-top