Potential RDP Tunneling Via SSH (f7d7ebd5-a016-46e2-9c54-f9932f2d386d)
Execution of ssh.exe to perform data exfiltration and tunneling through RDP
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Potential RDP Tunneling Via SSH (f7d7ebd5-a016-46e2-9c54-f9932f2d386d) | Sigma-Rules | Protocol Tunneling - T1572 (4fe28b27-b13c-453e-a386-c2ef362a573b) | Attack Pattern | 1 |