Detection rules › Sigma

RDP Over Reverse SSH Tunnel

Severity
high
Author
Samir Bousseaden
Source
upstream

Detects svchost hosting RDP termsvcs communicating with the loopback address and on TCP port 3389

MITRE ATT&CK coverage

TacticTechniques
Lateral MovementT1021.001 Remote Services: Remote Desktop Protocol
Command & ControlT1572 Protocol Tunneling

Event coverage

ProviderEvent IDTitle
Sysmon3Network connection

Stages and Predicates

Stage 1: all of selection_img

Image|endswith: '\svchost.exe'
Initiated: true
SourcePort: 3389

Stage 2: all of selection_destination

or:
DestinationIp|cidr: '127.0.0.0/8'
DestinationIp|cidr: '::1/128'

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
DestinationIpcidr_match
  • 127.0.0.0/8 corpus 13 (sigma 13)
  • ::1/128 corpus 13 (sigma 13)
Imageends_with
  • \svchost.exe corpus 20 (sigma 20)
Initiatedeq
  • true corpus 40 (sigma 40)
SourcePorteq
  • 3389 corpus 3 (sigma 3)

Neighbors

Stricter alternatives (narrower than this rule)

The rules below may be useful if you find the current rule is too noisy / lacks specificity.