Detection rules › Sigma
RDP over Reverse SSH Tunnel WFP
Detects svchost hosting RDP termsvcs communicating with the loopback address
Known false positives
- Programs that connect locally to the RDP port
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Lateral Movement | |
| Command & Control |
Telemetry coverage
| Provider | Record / event type |
|---|---|
| Security-Auditing | Event ID 5156: The Windows Filtering Platform has permitted a connection. |
Rule body
title: RDP over Reverse SSH Tunnel WFP
id: 5bed80b6-b3e8-428e-a3ae-d3c757589e41
status: test
description: Detects svchost hosting RDP termsvcs communicating with the loopback address
references:
- https://twitter.com/SBousseaden/status/1096148422984384514
- https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES/blob/44fbe85f72ee91582876b49678f9a26292a155fb/Command%20and%20Control/DE_RDP_Tunnel_5156.evtx
author: Samir Bousseaden
date: 2019-02-16
modified: 2022-09-02
tags:
- attack.command-and-control
- attack.lateral-movement
- attack.t1090.001
- attack.t1090.002
- attack.t1021.001
- car.2013-07-002
logsource:
product: windows
service: security
detection:
selection:
EventID: 5156
sourceRDP:
SourcePort: 3389
DestAddress:
- '127.*'
- '::1'
destinationRDP:
DestPort: 3389
SourceAddress:
- '127.*'
- '::1'
filter_app_container:
FilterOrigin: 'AppContainer Loopback'
filter_thor: # checking BlueKeep vulnerability
Application|endswith:
- '\thor.exe'
- '\thor64.exe'
condition: selection and ( sourceRDP or destinationRDP ) and not 1 of filter*
falsepositives:
- Programs that connect locally to the RDP port
level: high
Stages and Predicates
Stage 0: condition
selection and ( sourceRDP or destinationRDP ) and not 1 of filter*Stage 1: selection
selection:
EventID: 5156
Stage 2: sourceRDP
sourceRDP:
SourcePort: 3389
DestAddress:
- '127.*'
- '::1'
Stage 3: destinationRDP
destinationRDP:
DestPort: 3389
SourceAddress:
- '127.*'
- '::1'
Stage 4: not filter*
filter_app_container:
FilterOrigin: 'AppContainer Loopback'
filter_thor:
Application|endswith:
- '\thor.exe'
- '\thor64.exe'
Exclusions
The rule actively suppresses these predicates.
| Field | Kind | Excluded values | Search |
|---|---|---|---|
Application | ends_with | \thor.exe | excludes:Application field:"Application" value:"\thor.exe" |
Application | ends_with | \thor64.exe | excludes:Application field:"Application" value:"\thor64.exe" |
FilterOrigin | eq | AppContainer Loopback | excludes:FilterOrigin field:"FilterOrigin" value:"AppContainer Loopback" |
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
DestAddress | wildcard |
| field:"dest_ip" kind:wildcard |
DestPort | eq |
| field:"DestinationPort" kind:eq value:"3389" |
SourceAddress | wildcard |
| field:"src_ip" kind:wildcard |
SourcePort | eq |
| field:"SourcePort" kind:eq value:"3389" |