Suspicious Mstsc.EXE Execution With Local RDP File

 Original Source: [Sigma source]
Title: Suspicious Mstsc.EXE Execution With Local RDP File
Status: test
Description:Detects potential RDP connection via Mstsc using a local ".rdp" file located in suspicious locations.
References:
  -https://www.blackhillsinfosec.com/rogue-rdp-revisiting-initial-access-methods/
  -https://web.archive.org/web/20230726144748/https://blog.thickmints.dev/mintsights/detecting-rogue-rdp/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2023-04-18
modified:None
Tags:
  • -'attack.command-and-control'
  • -'attack.t1219.002'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\mstsc.exe' OriginalFileName:'mstsc.exe'   selection_extension:
    CommandLine|endswith:
      -'.rdp'
      -'.rdp"'

  selection_paths:
    CommandLine|contains:
      -':\Users\Public\'
      -':\Windows\System32\spool\drivers\color'
      -':\Windows\System32\Tasks_Migrated '
      -':\Windows\Tasks\'
      -':\Windows\Temp\'
      -':\Windows\Tracing\'
      -'\AppData\Local\Temp\'
      -'\Downloads\'

  condition:all of selection_*
Falsepositives:
  -Likelihood is related to how often the paths are used in the environment
Level: high