This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Remote Access Tool - AnyDesk Incoming Connection
Original Source:
[Sigma source]
Title:
Remote Access Tool - AnyDesk Incoming Connection
Status:
experimental
Description:
Detects incoming connections to AnyDesk. This could indicate a potential remote attacker trying to connect to a listening instance of AnyDesk and use it as potential command and control channel.
References:
-https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1219/T1219.md#atomic-test-2---anydesk-files-detected-test-on-windows
-https://asec.ahnlab.com/en/40263/
Author:
@d4ns4n_ (Wuerth-Phoenix)
Date:
2024-09-02
modified:
2025-02-24
Tags:
-'attack.persistence'
-'attack.command-and-control'
-'attack.t1219.002'
Logsource:
category: network_connection
product: windows
Detection:
selection:
Image|endswith
:
-'\AnyDesk.exe'
-'\AnyDeskMSI.exe'
Initiated
:
'false'
condition
:
selection
Falsepositives:
-Legitimate incoming connections (e.g. sysadmin activity). Most of the time I would expect outgoing connections (initiated locally).
Level:
medium