Remote Service Session Hijacking

T1563

Technique with 2 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may take control of preexisting sessions with remote services to move laterally in an environment. Users may use valid credentials to log into a service specifically designed to accept remote connections, such as telnet, SSH, and RDP. When a user logs into a service, a session will be established that will allow them to maintain a continuous interaction with that service.

Adversaries may commandeer these sessions to carry out actions on remote systems. Remote Service Session Hijacking differs from use of Remote Services because it hijacks an existing session rather than creating a new session using Valid Accounts.

Detection rules4

Rules on DetectionCode tagged with T1563 or one of its sub-techniques.

Sigma2

RuleLevelLog sourceTechnique
Potential MSTSC Shadowing Activityhighwindows / process_creationT1563.002
Suspicious RDP Redirect Using TSCONhighwindows / process_creationT1563.002

Splunk2

RuleTypeRiskData sourceTechnique
Windows RDP Connection SuccessfulHuntingNULLWindows Event Log RemoteConnectionManager 1149T1563.002
Windows Service Create with TsconTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1563.002

Sub-techniques2

IDNameExamples
T1563.001SSH Hijacking1
T1563.002RDP Hijacking2

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples0

No procedure examples are recorded for this technique.

References2

  1. Breach Post-mortem SSH Hijack Open source
    Hodgson, M. (2019, May 8). Post-mortem and remediations for Apr 11 security incident. Retrieved November 17, 2024.
  2. RDP Hijacking Medium Open source
    Beaumont, K. (2017, March 19). RDP hijacking — how to hijack RDS and RemoteApp sessions transparently to move through an organisation. Retrieved December 11, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.