RDP Port Forwarding Rule Added Via Netsh.EXE

 Original Source: [Sigma source]
Title: RDP Port Forwarding Rule Added Via Netsh.EXE
Status: test
Description:Detects the execution of netsh to configure a port forwarding of port 3389 (RDP) rule
References:
  -https://www.fireeye.com/blog/threat-research/2019/01/bypassing-network-restrictions-through-rdp-tunneling.html
Author: Florian Roth (Nextron Systems), oscd.community
Date: 2019-01-29
modified:2023-02-13
Tags:
  • -'attack.lateral-movement'
  • -'attack.command-and-control'
  • -'attack.t1090'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\netsh.exe' OriginalFileName:'netsh.exe'   selection_cli:
    CommandLine|contains|all:
      -' i'
      -' p'
      -'=3389'
      -' c'

  condition:all of selection_*
Falsepositives:
  -Legitimate administration activity
Level: high