← Back to Explore
sigmahighHunting
RDP Over Reverse SSH Tunnel
Detects svchost hosting RDP termsvcs communicating with the loopback address and on TCP port 3389
Detection Query
selection_img:
Image|endswith: \svchost.exe
Initiated: "true"
SourcePort: 3389
selection_destination:
DestinationIp|cidr:
- 127.0.0.0/8
- ::1/128
condition: all of selection_*
Author
Samir Bousseaden
Created
2019-02-16
Data Sources
windowsNetwork Connection Events
Platforms
windows
Tags
attack.command-and-controlattack.t1572attack.lateral-movementattack.t1021.001car.2013-07-002
Raw Content
title: RDP Over Reverse SSH Tunnel
id: 5f699bc5-5446-4a4a-a0b7-5ef2885a3eb4
status: test
description: Detects svchost hosting RDP termsvcs communicating with the loopback address and on TCP port 3389
references:
- https://twitter.com/cyb3rops/status/1096842275437625346
author: Samir Bousseaden
date: 2019-02-16
modified: 2024-03-12
tags:
- attack.command-and-control
- attack.t1572
- attack.lateral-movement
- attack.t1021.001
- car.2013-07-002
logsource:
category: network_connection
product: windows
detection:
selection_img:
Image|endswith: '\svchost.exe'
Initiated: 'true'
SourcePort: 3389
selection_destination:
DestinationIp|cidr:
- '127.0.0.0/8'
- '::1/128'
condition: all of selection_*
falsepositives:
- Unknown
level: high