New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
ScreenConnect rules #4467
ScreenConnect rules #4467
Conversation
events generated due to remote tool and command execution
ScreenConnect has a feature to remotely execute commands on target machine
ScreenConnect RMM has feature to remotely execute binaries on a target machine. The binaries will be dropped to C:\Users\User\Documents\ConnectWiseControl\Temp\ before execution.
Hi, Mitre tags are lowcase. |
fixing condition and log source
fixing condition and log source
Hello frack113 Thank you for checking the rules |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hi @alwashali thanks for the contribution. Just have a couple of questions before we can merge these if you may :)
rules/windows/file/file_event/file_event_win_screenconnect_remote_tool_execution.yaml
Outdated
Show resolved
Hide resolved
rules/windows/process_creation/proc_creation_win_screenconnect_remote_command_execution.yaml
Outdated
Show resolved
Hide resolved
rules/windows/process_creation/proc_creation_win_screenconnect_remote_command_execution.yaml
Outdated
Show resolved
Hide resolved
rules/windows/builtin/application/screenconnect/win_app_remote_command_execution.yaml
Outdated
Show resolved
Hide resolved
rules/windows/builtin/application/screenconnect/win_app_remote_binary_execution.yaml
Outdated
Show resolved
Hide resolved
@alwashali for the rules using the application logs. Can you post the log or screenshot of the details view. The General view has text that is often generated and not part of the log itself. |
Summary of the Pull Request
Rules to detect ScreenConnect RMM tools activity
Changelog
new: Remote Access Tool - ScreenConnect Command Execution
new: Remote Access Tool - ScreenConnect File Transfer
new: Remote Access Tool - ScreenConnect Temporary File
new: Remote Access Tool - ScreenConnect Remote Command Execution
Example Log Event
Fixed Issues
N/A
SigmaHQ Rule Creation Conventions