Potential MSTSC Shadowing Activity

 Original Source: [Sigma source]
Title: Potential MSTSC Shadowing Activity
Status: test
Description:Detects RDP session hijacking by using MSTSC shadowing
References:
  -https://twitter.com/kmkz_security/status/1220694202301976576
  -https://github.com/kmkz/Pentesting/blob/47592e5e160d3b86c2024f09ef04ceb87d204995/Post-Exploitation-Cheat-Sheet
Author: Florian Roth (Nextron Systems)
Date: 2020-01-24
modified:2023-02-05
Tags:
  • -'attack.lateral-movement'
  • -'attack.t1563.002'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains|all:
      -'noconsentprompt'
      -'shadow:'

  condition:selection
Falsepositives:
  -Unknown
Level: high