Hijack Legit RDP Session to Move Laterally

 Original Source: [Sigma source]
Title: Hijack Legit RDP Session to Move Laterally
Status: test
Description:Detects the usage of tsclient share to place a backdoor on the RDP source machine's startup folder
References:
  -Internal Research
Author: Samir Bousseaden
Date: 2019-02-21
modified:2021-11-27
Tags:
  • -'attack.command-and-control'
  • -'attack.t1219.002'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    Image|endswith: '\mstsc.exe'
    TargetFilename|contains: '\Microsoft\Windows\Start Menu\Programs\Startup\'
  condition:selection
Falsepositives:
  -Unlikely
Level: high