Remote Management Access Launch After MSI Install
Description
Identifies an MSI installer execution followed by commonly abused pre-configured Remote Management software. This may indicate abuse where an attacker triggers an MSI install then connects via a guest link with a known session key.
Query · eql
sequence with maxspan=1m
[process where event.action == "start" and process.name : "msiexec.exe" and process.args : ("/i*", "-i*") and
process.parent.executable != null and
process.command_line : ("*\\Users\\*\\Downloads\\*", "*\\SystemTemp\\ScreenConnect*") and
not process.args : ("C:\\Program Files (x86)\\*.msi", "C:\\Program Files\\*.msi") and
not (process.parent.name : ("cmd.exe", "powershell.exe") and user.id == "S-1-5-18" and
process.parent.args : ("C:\\Program Files (x86)\\ITSPlatform\\*.bat", "C:\\Windows\\LTSvc\\*", "\\\\*")) and
not process.parent.executable : ("C:\\Windows\\SystemTemp\\ScreenConnect\\*\\ScreenConnect.ClientSetup.exe",
"C:\\Windows\\System32\\MDMAppInstaller.exe",
"C:\\Program Files (x86)\\Microsoft Intune Management Extension\\Microsoft.Management.Services.IntuneWindowsAgent.exe")]
[process where event.action == "start" and process.Ext.relative_file_name_modify_time <= 100 and
(
(process.name : "ScreenConnect.ClientService.exe" and process.command_line : "*?e=Access&y=Guest&h*&k=*" and
not process.command_line like "*-relay.screenconnect.com&p=443*&c=&c=&c=&c=&c=&c=&c=&c=\"") or
(process.name : "Syncro.Installer.exe" and process.args : "--config-json" and process.args : "--key")
)]