Remote Service Session Hijacking T1563

Tactic: Lateral Movement

Adversaries may take control of preexisting sessions with remote services to move laterally in an environment. Users may use valid credentials to log into a service specifically designed to accept remote connections, such as telnet, SSH, and RDP. When a user logs into a service, a session will be established that will allow them to maintain a continuous interaction with that service.

Events covered

7 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 20 rules share fields, values, and exclusions.

Fields filtered most (28 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
event.type10eq 8, in 2start, change, creation
EventType9eq 6, in 3exec, ProcessRollup2, connection_attempted, creation, end
host.os.type8eq 8
process_name8eq 3, in 3, is_not_null 1, regex_match 1, wildcard 1curl, wget, (?i)rdpclip.exe, (?i)tstheme.exe, *.elf
CommandLine6contains 5, eq 1 /dest:rdp-tcp#, /dest:rdp-tcp, /usr/sbin/sshd -D -R, dest:rdp-, github.com/hackerschoice/
Image4ends_with 1, eq 1, starts_with 1, wildcard 1./, ./*, /boot/, /boot/*, /dev/shm/
event.category4eq 4file, process, registry
parent_process_name4eq 3, in 1sshd, ssh, svchost.exe
file.name3in 2, eq 1authorized_keys, authorized_keys2, libkeyutils.so
process.args3starts_with 2, eq 1-c, /shadow:, http://nossl.segfault.net/, https://github.com/hackerschoice/, https://gsocket.io/
EventID2eq 21149, 4688, 4778, 4779
TargetFilename2in 1, wildcard 1/etc/ssh/*, /home/*/.ssh/*, /root/.ssh/*, /usr/bin/scp, /usr/bin/sftp
esf.event_type2eq 2135, 136, 9
process.args_count2eq 21, 2
Details1eq 10x00000001, 0x00000002, 0x00000003

Top indicator values (152 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
71078
event.typeeq
change
294
EventTypeeq
exec
5576
EventTypein
exec
2201
event.categoryeq
file
243
event.categoryeq
process
2142
event.typein
change
220
event.typein
creation
219
file.namein
authorized_keys
23
file.namein
authorized_keys2
23
parent_process_nameeq
sshd
23
process_namein
curl
289
process_namein
wget
246
CommandLinecontains
/dest:rdp-tcp#
1
CommandLinecontains
/dest:rdp-tcp
1
CommandLinecontains
dest:rdp-
1
CommandLinecontains
github.com/hackerschoice/
1
CommandLinecontains
gsocket.io/
1
CommandLinecontains
noconsentprompt
1
CommandLinecontains
nossl.segfault.net/
1
CommandLinecontains
shadow:
1
CommandLinecontains
thc.org/
1
CommandLinecontains
tscon
1
CommandLineeq
/usr/sbin/sshd -D -R
1
Detailseq
0x00000001
161
Detailseq
0x00000002
14
Detailseq
0x00000003
1
Detailseq
0x00000004
14
Detailseq
1
120
Detailseq
2
14

Exclusions (143 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
CommandLinecontains
ansible
1
CommandLinecontains
become-success
1
CommandLinein
-bash
1
CommandLinein
-sh
1
CommandLinein
-zsh
1
CommandLinewildcard
*BECOME-SUCCESS*
1
CommandLinewildcard
*ansible*
1
CommandLinewildcard
sh -c -- /usr/bin/env -i PATH=*
1
CommandLinewildcard
sh -c /usr/bin/env -i PATH=*
1
Imageeq
/home/sa-ansible
1
Imageeq
/library/developer/commandlinetools/usr/bin/git
1
Imageeq
/opt/jc/bin/jumpcloud-agent
1
Imageeq
/opt/puppetlabs/puppet/bin/puppet
1
Imageeq
/usr/bin/bsdtar
1
Imageeq
/usr/bin/chef-client
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 6 rules

Elastic 11 rules

Splunk 3 rules