Potential RDP Session Hijacking Activity

Detects potential RDP Session Hijacking activity on Windows systems

Sigma rule (View on GitHub)

 1title: Potential RDP Session Hijacking Activity
 2id: 224f140f-3553-4cd1-af78-13d81bf9f7cc
 3status: test
 4description: Detects potential RDP Session Hijacking activity on Windows systems
 5references:
 6    - https://twitter.com/Moti_B/status/909449115477659651
 7author: '@juju4'
 8date: 2022-12-27
 9tags:
10    - attack.execution
11logsource:
12    category: process_creation
13    product: windows
14detection:
15    selection_img:
16        - Image|endswith: '\tscon.exe'
17        - OriginalFileName: 'tscon.exe'
18    selection_integrity:
19        IntegrityLevel: SYSTEM
20    condition: all of selection_*
21falsepositives:
22    - Administrative activity
23level: medium

References

Related rules

to-top