This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
RDP over Reverse SSH Tunnel WFP
Original Source:
[Sigma source]
Title:
RDP over Reverse SSH Tunnel WFP
Status:
test
Description:
Detects svchost hosting RDP termsvcs communicating with the loopback address
References:
-https://twitter.com/SBousseaden/status/1096148422984384514
-https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES/blob/44fbe85f72ee91582876b49678f9a26292a155fb/Command%20and%20Control/DE_RDP_Tunnel_5156.evtx
Author:
Samir Bousseaden
Date:
2019-02-16
modified:
2022-09-02
Tags:
-'attack.command-and-control'
-'attack.lateral-movement'
-'attack.t1090.001'
-'attack.t1090.002'
-'attack.t1021.001'
-'car.2013-07-002'
Logsource:
product: windows
service: security
Detection:
selection:
EventID
:
'5156'
sourceRDP:
SourcePort
:
'3389'
DestAddress
:
-'127.*'
-'::1'
destinationRDP:
DestPort
:
'3389'
SourceAddress
:
-'127.*'
-'::1'
filter_app_container:
FilterOrigin
:
'AppContainer Loopback'
filter_thor:
Application|endswith
:
-'\thor.exe'
-'\thor64.exe'
condition
:
selection and ( sourceRDP or destinationRDP ) and not 1 of filter*
Falsepositives:
-Programs that connect locally to the RDP port
Level:
high