Suspicious RDP Redirect Using TSCON

 Original Source: [Sigma source]
Title: Suspicious RDP Redirect Using TSCON
Status: test
Description:Detects a suspicious RDP session redirect using tscon.exe
References:
  -http://www.korznikov.com/2017/03/0-day-or-feature-privilege-escalation.html
  -https://medium.com/@networksecurity/rdp-hijacking-how-to-hijack-rds-and-remoteapp-sessions-transparently-to-move-through-an-da2a1e73a5f6
  -https://www.hackingarticles.in/rdp-session-hijacking-with-tscon/
Author: Florian Roth (Nextron Systems)
Date: 2018-03-17
modified:2023-05-16
Tags:
  • -'attack.lateral-movement'
  • -'attack.t1563.002'
  • -'attack.t1021.001'
  • -'car.2013-07-002'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains: ' /dest:rdp-tcp#'
  condition:selection
Falsepositives:
  -Unknown
Level: high