{"id":"T1021.005","name":"VNC","url":"https://attack.mitre.org/techniques/T1021/005","tactics":["lateral-movement"],"platforms":["Linux","Windows","macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0178","stix_id":"x-mitre-detection-strategy--bb431f45-c3fe-4b98-8dd7-70346b56c880","name":"Behavioral Detection of Unauthorized VNC Remote Control Sessions","url":"https://attack.mitre.org/detectionstrategies/DET0178","analytics":[{"id":"AN0504","stix_id":"x-mitre-analytic--7c91d6c7-4591-41b1-9c08-0c0660b07d24","name":"Analytic 0504","description":"Detection of VNC service or executable starting unexpectedly, followed by user session creation and interactive desktop activity (mouse/keyboard simulation).","url":"https://attack.mitre.org/detectionstrategies/DET0178#AN0504","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4624, 4648","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"wineventlog-security"},{"name":"NSM:Flow","channel":"port 5900 inbound","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"TimeWindow","description":"Correlate VNC process with user logon activity within defined time span"},{"field":"VNCBinaryList","description":"Trackable VNC executable names (e.g., vncserver.exe, winvnc.exe)"},{"field":"LogonType","description":"Limit detection to interactive logons (type 10)"}],"live":true,"detection_strategies":["DET0178"],"techniques":["T1021.005"]},{"id":"AN0505","stix_id":"x-mitre-analytic--9032a591-de05-44c2-b1f6-3d711f417cce","name":"Analytic 0505","description":"Spawning of VNC-related processes (e.g., `x11vnc`, `vncserver`) coupled with authentication logs and port listening behavior on TCP 5900.","url":"https://attack.mitre.org/detectionstrategies/DET0178#AN0505","platforms":["Linux"],"log_source_references":[{"name":"auditd:EXECVE","channel":"None","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-execve"},{"name":"linux:syslog","channel":"None","data_component":"DC0088","data_component_name":"Logon Session Metadata","log_source_slug":"linux-syslog"},{"name":"NSM:Flow","channel":"TCP port 5900 open","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"ListeningPort","description":"Default VNC port (5900) but may vary in config"},{"field":"ProcessNameFilter","description":"Filter specific VNC binaries in process execution logs"},{"field":"UserContext","description":"Scope detection to non-service or high-privilege accounts"}],"live":true,"detection_strategies":["DET0178"],"techniques":["T1021.005"]},{"id":"AN0506","stix_id":"x-mitre-analytic--b88251d3-6406-4512-a55f-a6bc3493e2ad","name":"Analytic 0506","description":"Detection of VNC-based remote control via `screensharingd` activity in Unified Logs along with concurrent remote login activity or suspicious user interaction.","url":"https://attack.mitre.org/detectionstrategies/DET0178#AN0506","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"authentication","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"process_events","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"},{"name":"NSM:firewall","channel":"inbound connection to port 5900","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-firewall"}],"mutable_elements":[{"field":"AuthenticationPredicate","description":"Unified log predicate to refine suspicious screensharing access"},{"field":"TimeWindow","description":"Time between VNC connection and follow-on activity (e.g., 30s)"},{"field":"UserActivitySpike","description":"Mouse/keyboard interaction spike immediately post-VNC login"}],"live":true,"detection_strategies":["DET0178"],"techniques":["T1021.005"]}],"live":true,"version":"1.0","techniques":["T1021.005"]}],"sigma_rules":[{"id":"871b9555-69ca-4993-99d3-35a59f9f3599","title":"Suspicious UltraVNC Execution","author":"Bhabesh Raj","status":"test","level":"high","date":"2022-03-04","modified":"2022-03-09","description":"Detects suspicious UltraVNC command line flag combination that indicate a auto reconnect upon execution, e.g. startup (as seen being used by Gamaredon threat group)","references":["https://web.archive.org/web/20220224045756/https://www.ria.ee/sites/default/files/content-editors/kuberturve/tale_of_gamaredon_infection.pdf","https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/shuckworm-gamaredon-espionage-ukraine","https://unit42.paloaltonetworks.com/unit-42-title-gamaredon-group-toolset-evolution","https://uvnc.com/docs/uvnc-viewer/52-ultravnc-viewer-commandline-parameters.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.lateral-movement","attack.g0047","attack.t1021.005"],"path":"rules/windows/process_creation/proc_creation_win_ultravnc_susp_execution.yml","techniques":["T1021.005"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}