Remote Access Tool - AnyDesk Piped Password Via CLI

 Original Source: [Sigma source]
Title: Remote Access Tool - AnyDesk Piped Password Via CLI
Status: test
Description:Detects piping the password to an anydesk instance via CMD and the '--set-password' flag.
References:
  -https://redcanary.com/blog/misbehaving-rats/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-09-28
modified:2023-03-05
Tags:
  • -'attack.command-and-control'
  • -'attack.t1219.002'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains|all:
      -'/c '
      -'echo '
      -'.exe --set-password'

  condition:selection
Falsepositives:
  -Legitimate piping of the password to anydesk
  -Some FP could occur with similar tools that uses the same command line '--set-password'
Level: medium