{"id":"T1563","name":"Remote Service Session Hijacking","url":"https://attack.mitre.org/techniques/T1563","tactics":["lateral-movement"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0079","stix_id":"x-mitre-detection-strategy--5d244477-26e2-4b3a-b882-fd74e366e07d","name":"Detection of Remote Service Session Hijacking","url":"https://attack.mitre.org/detectionstrategies/DET0079","analytics":[{"id":"AN0216","stix_id":"x-mitre-analytic--3c320df0-2a99-4bc4-b0f4-7af1675ccdb9","name":"Analytic 0216","description":"Detection of anomalous RDP or remote service session activity where a logon session is hijacked rather than newly created. Indicators include mismatched user credentials vs. active session tokens, service session takeovers without corresponding successful logon events, or RDP shadowing activity without user consent.","url":"https://attack.mitre.org/detectionstrategies/DET0079#AN0216","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4624, 4648","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"ExpectedUserSessionMap","description":"Mapping of users to hosts they are expected to access; deviations indicate possible hijacking."},{"field":"TimeWindow","description":"Threshold for detecting rapid pivoting via hijacked sessions."}],"live":true,"detection_strategies":["DET0079"],"techniques":["T1563"]},{"id":"AN0217","stix_id":"x-mitre-analytic--fba8a3f5-74d0-47d2-a688-1bdcc99dae6b","name":"Analytic 0217","description":"Detection of SSH/Telnet session hijacking via discrepancies between authentication logs and active session tables. Adversary behavior includes reusing or stealing active PTY sessions, attaching to screen/tmux, or issuing commands without corresponding login events.","url":"https://attack.mitre.org/detectionstrategies/DET0079#AN0217","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve: Commands executed within an SSH session where no matching logon/authentication event exists","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"},{"name":"NSM:Connections","channel":"Mismatch between recorded user logon and active sessions (e.g., wtmp/utmp entries without corresponding authentication in auth.log)","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"nsm-connections"},{"name":"NSM:Flow","channel":"Long-lived or hijacked SSH sessions maintained with no active user activity","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"MonitoredServicePorts","description":"Ports for SSH/Telnet/RDP monitored for session hijacking; may vary by environment."}],"live":true,"detection_strategies":["DET0079"],"techniques":["T1563"]},{"id":"AN0218","stix_id":"x-mitre-analytic--81889314-3404-4cfb-a650-52a5898b6f31","name":"Analytic 0218","description":"Detection of hijacked VNC or SSH sessions on macOS where adversaries take over an existing session rather than authenticating directly. Indicators include process execution from active sessions without new logon events, manipulation of TTY sessions, or anomalous network activity tied to dormant sessions.","url":"https://attack.mitre.org/detectionstrategies/DET0079#AN0218","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Authentication inconsistencies where commands are executed without corresponding login events","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Execution of processes linked to hijacked sessions (e.g., anomalous parent-child process lineage)","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"NSM:Flow","channel":"Suspicious long-lived or reattached remote desktop sessions from unexpected IPs","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"SessionIdleThreshold","description":"Time threshold for inactive sessions flagged as suspicious when commands suddenly resume."}],"live":true,"detection_strategies":["DET0079"],"techniques":["T1563"]}],"live":true,"version":"1.0","techniques":["T1563"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}