Suspicious TSCON Start as SYSTEM

 Original Source: [Sigma source]
Title: Suspicious TSCON Start as SYSTEM
Status: test
Description:Detects a tscon.exe start as LOCAL SYSTEM
References:
  -http://www.korznikov.com/2017/03/0-day-or-feature-privilege-escalation.html
  -https://medium.com/@networksecurity/rdp-hijacking-how-to-hijack-rds-and-remoteapp-sessions-transparently-to-move-through-an-da2a1e73a5f6
  -https://www.ired.team/offensive-security/lateral-movement/t1076-rdp-hijacking-for-lateral-movement
Author: Florian Roth (Nextron Systems)
Date: 2018-03-17
modified:2022-05-27
Tags:
  • -'attack.command-and-control'
  • -'attack.t1219.002'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    User|contains:
      -'AUTHORI'
      -'AUTORI'

    Image|endswith: '\tscon.exe'
  condition:selection
Falsepositives:
  -Unknown
Level: high