{"id":"T1563.002","name":"RDP Hijacking","url":"https://attack.mitre.org/techniques/T1563/002","tactics":["lateral-movement"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0588","stix_id":"x-mitre-detection-strategy--2729a43c-3f8d-4fee-b2bd-f773436d051b","name":"Detection of Remote Service Session Hijacking for RDP.","url":"https://attack.mitre.org/detectionstrategies/DET0588","analytics":[{"id":"AN1620","stix_id":"x-mitre-analytic--be773ad4-9e5f-4063-910a-99a3cab90582","name":"Analytic 1620","description":"Detection of suspicious use of `tscon.exe` or equivalent methods to hijack legitimate RDP sessions. Defenders can observe anomalies such as session reassignments without corresponding authentication, processes spawned in the context of hijacked sessions, or unusual RDP network traffic flows that deviate from expected baselines.","url":"https://attack.mitre.org/detectionstrategies/DET0588#AN1620","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4624, 4648","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:System","channel":"EventCode=7045","data_component":"DC0060","data_component_name":"Service Creation","log_source_slug":"wineventlog-system"}],"mutable_elements":[{"field":"ExpectedRDPHosts","description":"Whitelist of systems and accounts authorized to use RDP; deviations indicate possible hijacking."},{"field":"TimeWindow","description":"Time threshold for correlating logon events with session reassignment and process execution."},{"field":"SessionIDMapping","description":"Environment-specific mapping of user accounts to session IDs; inconsistencies may reveal hijacking."}],"live":true,"detection_strategies":["DET0588"],"techniques":["T1563.002"]}],"live":true,"version":"1.0","techniques":["T1563.002"]}],"sigma_rules":[{"id":"6ba5a05f-b095-4f0a-8654-b825f4f16334","title":"Potential MSTSC Shadowing Activity","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2020-01-24","modified":"2023-02-05","description":"Detects RDP session hijacking by using MSTSC shadowing","references":["https://twitter.com/kmkz_security/status/1220694202301976576","https://github.com/kmkz/Pentesting/blob/47592e5e160d3b86c2024f09ef04ceb87d204995/Post-Exploitation-Cheat-Sheet"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.lateral-movement","attack.t1563.002"],"path":"rules/windows/process_creation/proc_creation_win_mstsc_rdp_hijack_shadowing.yml","techniques":["T1563.002"],"cves":[]},{"id":"f72aa3e8-49f9-4c7d-bd74-f8ab84ff9bbb","title":"Suspicious RDP Redirect Using TSCON","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2018-03-17","modified":"2023-05-16","description":"Detects a suspicious RDP session redirect using tscon.exe","references":["http://www.korznikov.com/2017/03/0-day-or-feature-privilege-escalation.html","https://medium.com/@networksecurity/rdp-hijacking-how-to-hijack-rds-and-remoteapp-sessions-transparently-to-move-through-an-da2a1e73a5f6","https://www.hackingarticles.in/rdp-session-hijacking-with-tscon/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.lateral-movement","attack.t1563.002","attack.t1021.001","car.2013-07-002"],"path":"rules/windows/process_creation/proc_creation_win_tscon_rdp_redirect.yml","techniques":["T1563.002","T1021.001"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}