Hijack Legit RDP Session to Move Laterally (52753ea4-b3a0-4365-910d-36cff487b789)
Detects the usage of tsclient share to place a backdoor on the RDP source machine's startup folder
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Hijack Legit RDP Session to Move Laterally (52753ea4-b3a0-4365-910d-36cff487b789) | Sigma-Rules | Remote Access Software - T1219 (4061e78c-1284-44b4-9116-73e4ac3912f7) | Attack Pattern | 1 |