This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious Mstsc.EXE Execution With Local RDP File
Original Source:
[Sigma source]
Title:
Suspicious Mstsc.EXE Execution With Local RDP File
Status:
test
Description:
Detects potential RDP connection via Mstsc using a local ".rdp" file located in suspicious locations.
References:
-https://www.blackhillsinfosec.com/rogue-rdp-revisiting-initial-access-methods/
-https://web.archive.org/web/20230726144748/https://blog.thickmints.dev/mintsights/detecting-rogue-rdp/
Author:
Nasreddine Bencherchali (Nextron Systems)
Date:
2023-04-18
modified:
None
Tags:
-'attack.command-and-control'
-'attack.t1219.002'
Logsource:
category: process_creation
product: windows
Detection:
selection_img:
Image|endswith
:
'\mstsc.exe'
OriginalFileName
:
'mstsc.exe'
selection_extension:
CommandLine|endswith
:
-'.rdp'
-'.rdp"'
selection_paths:
CommandLine|contains
:
-':\Users\Public\'
-':\Windows\System32\spool\drivers\color'
-':\Windows\System32\Tasks_Migrated '
-':\Windows\Tasks\'
-':\Windows\Temp\'
-':\Windows\Tracing\'
-'\AppData\Local\Temp\'
-'\Downloads\'
condition
:
all of selection_*
Falsepositives:
-Likelihood is related to how often the paths are used in the environment
Level:
high