{"id":"b19146a3-25d4-41b4-928b-1e2a92641b1b","title":"Remote Access Tool - ScreenConnect Server Web Shell Execution","description":"Detects potential web shell execution from the ScreenConnect server process.","author":"Jason Rathbun (Blackpoint Cyber)","status":"test","level":"high","date":"2024-02-26","modified":"","tags":["attack.initial-access","attack.t1190"],"technique_ids":["T1190"],"logsource":{"product":"windows","category":"process_creation"},"falsepositives":["Unlikely"],"references":["https://blackpointcyber.com/resources/blog/breaking-through-the-screen/","https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8"],"source_path":"rules/windows/process_creation/proc_creation_win_remote_access_tools_screenconnect_webshell.yml","source_sha256":"3d9c714d5fc4af2e7900a680645ea06eb127bdca003644e986219fc3c6ee29d1","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_remote_access_tools_screenconnect_webshell.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Remote Access Tool - ScreenConnect Server Web Shell Execution\nid: b19146a3-25d4-41b4-928b-1e2a92641b1b\nstatus: test\ndescription: Detects potential web shell execution from the ScreenConnect server process.\nreferences:\n    - https://blackpointcyber.com/resources/blog/breaking-through-the-screen/\n    - https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8\nauthor: Jason Rathbun (Blackpoint Cyber)\ndate: 2024-02-26\ntags:\n    - attack.initial-access\n    - attack.t1190\nlogsource:\n    product: windows\n    category: process_creation\ndetection:\n    selection:\n        ParentImage|endswith: '\\ScreenConnect.Service.exe'\n        Image|endswith:\n            - '\\cmd.exe'\n            - '\\csc.exe'\n    condition: selection\nfalsepositives:\n    - Unlikely\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1190","id":"T1190","name":"Exploit Public-Facing Application","page":"techniques/enterprise/T1190/"}],"data_path":"data/detection-rules/b19146a3-25d4-41b4-928b-1e2a92641b1b.json","kind":"sigma"}
