Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0588 — Detection of Remote Service Session Hijacking for RDP.
DET0588

Detection of Remote Service Session Hijacking for RDP.

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1620 Analytic 1620
Windows

Detection of suspicious use of `tscon.exe` or equivalent methods to hijack legitimate RDP sessions. Defenders can observe anomalies such as session reassignments without corresponding authentication, processes spawned in the context of hijacked sessions, or unusual RDP network traffic flows that deviate from expected baselines.

WinEventLog:Security EventCode=4624, 4648 WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=3, 22 WinEventLog:System EventCode=7045
[ExpectedRDPHosts] Whitelist of systems and accounts authorized to use RDP; deviations indicate possible hijacking.
[TimeWindow] Time threshold for correlating logon events with session reassignment and process execution.
[SessionIDMapping] Environment-specific mapping of user accounts to session IDs; inconsistencies may reveal hijacking.

Detected Techniques

1

Lateral Movement (1)

Details

MITRE ID
DET0588
STIX ID
x-mitre-detection-strategy--2729a43c-3f8d-4fee-b2bd-f773436d051b
Analytics
1
Techniques Detected
1
By Tactic
Lateral Movement
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.