Apache Guacamole Linux: Two-User Session Presence Anomaly

Flags Guacamole sessions on Linux when telemetry indicates two users are present, suggesting anomalous or suspicious session activity.

FreeReviewedSigma · High · v3
Product
linux
Service
guacamole
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2020-07-03
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags a suspicious Guacamole session state where the system indicates two users are now present. Such behavior can be consistent with unauthorized access or session takeover, since an attacker may cause additional user presence within an active session. It relies on Guacamole service telemetry that reports the '(2 users now present)' session anomaly indicator on Linux.

Related detections4 linkedT1212 — drag to rearrange
Windows Rundll32 Calls DavSetCookie for NTLM Coercion via Spoolss/Srvsvc
Windows Process Creation alerts on GALLIUM-associated hash IOCs
Windows Audit-CVE: User Applications Writing CveEventWrite Events (Event ID 1)
Windows Kerberos TGT Issue Operations Failures (Event IDs 675/4768/4769/4771)
Apache Guacamole Linux: Two-User Session Presence Anomaly
Pivot detection · T1212 · 4 related

Changelog

v3
  1. v3
    Candidate ingested via manual entry.2026-07-31
  2. v2
    Candidate ingested via manual entry.2026-07-31
  3. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.