RDP over Reverse SSH Tunnel WFP

 Original Source: [Sigma source]
Title: RDP over Reverse SSH Tunnel WFP
Status: test
Description:Detects svchost hosting RDP termsvcs communicating with the loopback address
References:
  -https://twitter.com/SBousseaden/status/1096148422984384514
  -https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES/blob/44fbe85f72ee91582876b49678f9a26292a155fb/Command%20and%20Control/DE_RDP_Tunnel_5156.evtx
Author: Samir Bousseaden
Date: 2019-02-16
modified:2022-09-02
Tags:
  • -'attack.command-and-control'
  • -'attack.lateral-movement'
  • -'attack.t1090.001'
  • -'attack.t1090.002'
  • -'attack.t1021.001'
  • -'car.2013-07-002'
Logsource:
  • product: windows
  • service: security
Detection:
  selection:
    EventID: '5156'
  sourceRDP:
    SourcePort: '3389'
    DestAddress:
      -'127.*'
      -'::1'

  destinationRDP:
    DestPort: '3389'
    SourceAddress:
      -'127.*'
      -'::1'

  filter_app_container:
    FilterOrigin: 'AppContainer Loopback'
  filter_thor:
    Application|endswith:
      -'\thor.exe'
      -'\thor64.exe'

  condition:selection and ( sourceRDP or destinationRDP ) and not 1 of filter*
Falsepositives:
  -Programs that connect locally to the RDP port
Level: high