Terminal Service Process Spawn

 Original Source: [Sigma source]
Title: Terminal Service Process Spawn
Status: test
Description:Detects a process spawned by the terminal service server process (this could be an indicator for an exploitation of CVE-2019-0708)
References:
  -https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/rdp-stands-for-really-do-patch-understanding-the-wormable-rdp-vulnerability-cve-2019-0708/
Author: Florian Roth (Nextron Systems)
Date: 2019-05-22
modified:2023-01-25
Tags:
  • -'attack.initial-access'
  • -'attack.t1190'
  • -'attack.lateral-movement'
  • -'attack.t1210'
  • -'car.2013-07-002'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection:
    ParentCommandLine|contains|all:
      -'\svchost.exe'
      -'termsvcs'

  filter_img:
    Image|endswith:
      -'\rdpclip.exe'
      -':\Windows\System32\csrss.exe'
      -':\Windows\System32\wininit.exe'
      -':\Windows\System32\winlogon.exe'

  filter_null:
    Image: 'None'
  condition:selection and not 1 of filter_*
Falsepositives:
  -Unknown
Level: high