Hijack Legit RDP Session to Move Laterally
Description
Detects the usage of tsclient share to place a backdoor on the RDP source machine's startup folder
Query · sigma
selection: Image|endswith: \mstsc.exe TargetFilename|contains: \Microsoft\Windows\Start Menu\Programs\Startup\ condition: selection
Known false positives
- Unlikely