Title:
Remote Access Tool - AnyDesk Piped Password Via CLI
Status:
test
Description:Detects piping the password to an anydesk instance via CMD and the '--set-password' flag.
References:
-https://redcanary.com/blog/misbehaving-rats/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-09-28
modified:2023-03-05
Tags:
- -'attack.command-and-control'
- -'attack.t1219.002'
Logsource:
- category: process_creation
- product: windows
Detection:
selection:
CommandLine|contains|all:
-'/c '
-'echo '
-'.exe --set-password'
condition:
selection
Falsepositives:
-Legitimate piping of the password to anydesk
-Some FP could occur with similar tools that uses the same command line '--set-password'
Level:
medium