← Back to Explore
sigmamediumHunting
TeamViewer Remote Session
Detects the creation of log files during a TeamViewer remote session
Detection Query
selection1:
TargetFilename|endswith:
- \TeamViewer\RemotePrinting\tvprint.db
- \TeamViewer\TVNetwork.log
selection2:
TargetFilename|contains|all:
- \TeamViewer
- _Logfile.log
condition: 1 of selection*
Author
Florian Roth (Nextron Systems)
Created
2022-01-30
Data Sources
windowsFile Events
Platforms
windows
References
Tags
attack.command-and-controlattack.t1219.002
Raw Content
title: TeamViewer Remote Session
id: 162ab1e4-6874-4564-853c-53ec3ab8be01
status: test
description: Detects the creation of log files during a TeamViewer remote session
references:
- https://www.teamviewer.com/en-us/
author: Florian Roth (Nextron Systems)
date: 2022-01-30
tags:
- attack.command-and-control
- attack.t1219.002
logsource:
product: windows
category: file_event
detection:
selection1:
TargetFilename|endswith:
- '\TeamViewer\RemotePrinting\tvprint.db'
- '\TeamViewer\TVNetwork.log'
selection2:
TargetFilename|contains|all:
- '\TeamViewer'
- '_Logfile.log'
condition: 1 of selection*
falsepositives:
- Legitimate uses of TeamViewer in an organisation
level: medium