RDP Connection Allowed Via Netsh.EXE

 Original Source: [Sigma source]
Title: RDP Connection Allowed Via Netsh.EXE
Status: test
Description:Detects usage of the netsh command to open and allow connections to port 3389 (RDP). As seen used by Sarwent Malware
References:
  -https://labs.sentinelone.com/sarwent-malware-updates-command-detonation/
Author: Sander Wiebing
Date: 2020-05-23
modified:2023-12-11
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1686.003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\netsh.exe' OriginalFileName:'netsh.exe'   selection_cli:
    CommandLine|contains|all:
      -'firewall '
      -'add '
      -'tcp '
      -'3389'

    CommandLine|contains:
      -'portopening'
      -'allow'

  condition:all of selection_*
Falsepositives:
  -Legitimate administration activity
Level: high